Skip to content

chore(ci): replace SonarCloud with Qodana - #3478

Closed
atagisow-alokai wants to merge 2 commits into
v2-developfrom
chore/replace-sonarcloud-with-qodana
Closed

atagisow-alokai wants to merge 2 commits into
v2-developfrom
chore/replace-sonarcloud-with-qodana

Conversation

@atagisow-alokai

Copy link
Copy Markdown

What

Replaces SonarCloud with JetBrains Qodana, mirroring the setup in the enterprise repo.

  • Removes both SonarCloud Scan steps (SonarSource/sonarqube-scan-action@v6) from ci.yml, along with the now-unused workflow-level SONAR_TOKEN_REACT / SONAR_TOKEN_VUE env block.
  • Deletes the two dead sonar-project.properties files (packages/sfui/frameworks/{vue,react}) that those steps consumed.
  • Adds qodana.yaml — copied from enterprise, security-scoped on the qodana-js linter: VulnerableLibrariesLocal, NpmVulnerableApiCode, HardcodedPasswords, HttpUrlsUsage, plus CheckDependencyLicenses.
  • Adds .github/workflows/qodana_code_quality.yml as a standalone workflow (JetBrains' recommended layout, and what enterprise does), running on v2 / v2-develop and PRs.

Before this can merge

A Qodana Cloud project and a QODANA_TOKEN repository secret are needed. QODANA_TOKEN is a per-project token created in the Qodana Cloud UI; this repo currently has only SONAR_TOKEN_REACT and SONAR_TOKEN_VUE.

The scan step is gated on if: ${{ env.QODANA_TOKEN }} — the same idiom the Sonar steps already used — so CI stays green until that secret exists, and the scan starts working the moment it's added. No coordination required between merging this and provisioning the token.

Two things worth a decision

  1. Coverage reporting is dropped, not ported. The Sonar steps uploaded Cypress lcov coverage for the Vue and React frameworks separately. Qodana is a static analyser and does not consume lcov, so per-framework coverage and the quality gate go away. Fine if this is Sonar decommissioning; not fine if anyone depends on those dashboards.
  2. The Post-Cypress (generate coverage) steps and CYPRESS_COVERAGE: true are left in place. Sonar looked like their only consumer, so they may now be dead CI time — but that is a separate change and I did not want to assume nothing else reads coverage/lcov.info.

Note that Qodana's config here is a security scope, not a like-for-like replacement for Sonar's code-quality gate.

🤖 Generated with Claude Code

SonarCloud is being decommissioned. Mirror the Qodana setup from the
enterprise repo: a standalone Qodana workflow plus a security-scoped
qodana.yaml (dependency vulnerabilities, licences, hardcoded passwords,
HTTP URLs) on the qodana-js linter.

The two SonarCloud Scan steps in ci.yml consumed Cypress lcov coverage;
Qodana does not, so coverage reporting is dropped rather than ported.
The Post-Cypress coverage steps are left in place deliberately - removing
them is a separate call once it is confirmed nothing else reads them.

The scan is gated on QODANA_TOKEN being present, matching how the Sonar
steps were gated, so CI stays green until a Qodana Cloud project and its
token secret exist for this repo.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
@changeset-bot

changeset-bot Bot commented Sep 4, 2026 •

Copy link
Copy Markdown

⚠️ No Changeset found

Latest commit: a204dcb

Merging this PR will not cause a version bump for any packages. If these changes should not result in a new version, you're good to go. If these changes should result in a version bump, you need to add a changeset.

This PR includes no changesets

When changesets are added to this PR, you'll see the packages that this PR includes changesets for and the associated semver types

Click here to learn what changesets are, and how to add one.

Click here if you're a maintainer who wants to add a changeset to this PR

The initial copy came from a working tree that was behind enterprise's dev
branch, so it missed the `ignore:` refinements added there for
HardcodedPasswords and HttpUrlsUsage. Enterprise's own ignore paths are not
portable, so this carries over the note about which inspections need them
instead of the literal paths.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
@github-actions

github-actions Bot commented Sep 4, 2026

Copy link
Copy Markdown
Contributor

Qodana for JS

It seems all right 👌

No new problems were found according to the checks applied

☁️ View the detailed Qodana report

Contact Qodana team

Contact us at qodana-support@jetbrains.com

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant