Repository navigation
chore(ci): replace SonarCloud with Qodana - #3478
Closed
atagisow-alokai wants to merge 2 commits into
Closed
atagisow-alokai wants to merge 2 commits into
atagisow-alokai wants to merge 2 commits into
Conversation
SonarCloud is being decommissioned. Mirror the Qodana setup from the enterprise repo: a standalone Qodana workflow plus a security-scoped qodana.yaml (dependency vulnerabilities, licences, hardcoded passwords, HTTP URLs) on the qodana-js linter. The two SonarCloud Scan steps in ci.yml consumed Cypress lcov coverage; Qodana does not, so coverage reporting is dropped rather than ported. The Post-Cypress coverage steps are left in place deliberately - removing them is a separate call once it is confirmed nothing else reads them. The scan is gated on QODANA_TOKEN being present, matching how the Sonar steps were gated, so CI stays green until a Qodana Cloud project and its token secret exist for this repo. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
|
The initial copy came from a working tree that was behind enterprise's dev branch, so it missed the `ignore:` refinements added there for HardcodedPasswords and HttpUrlsUsage. Enterprise's own ignore paths are not portable, so this carries over the note about which inspections need them instead of the literal paths. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Contributor
Qodana for JSIt seems all right 👌 No new problems were found according to the checks applied ☁️ View the detailed Qodana report Contact Qodana teamContact us at qodana-support@jetbrains.com
|
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
What
Replaces SonarCloud with JetBrains Qodana, mirroring the setup in the
enterpriserepo.SonarCloud Scansteps (SonarSource/sonarqube-scan-action@v6) fromci.yml, along with the now-unused workflow-levelSONAR_TOKEN_REACT/SONAR_TOKEN_VUEenv block.sonar-project.propertiesfiles (packages/sfui/frameworks/{vue,react}) that those steps consumed.qodana.yaml— copied fromenterprise, security-scoped on theqodana-jslinter:VulnerableLibrariesLocal,NpmVulnerableApiCode,HardcodedPasswords,HttpUrlsUsage, plusCheckDependencyLicenses..github/workflows/qodana_code_quality.ymlas a standalone workflow (JetBrains' recommended layout, and whatenterprisedoes), running onv2/v2-developand PRs.Before this can merge
A Qodana Cloud project and a
QODANA_TOKENrepository secret are needed.QODANA_TOKENis a per-project token created in the Qodana Cloud UI; this repo currently has onlySONAR_TOKEN_REACTandSONAR_TOKEN_VUE.The scan step is gated on
if: ${{ env.QODANA_TOKEN }}— the same idiom the Sonar steps already used — so CI stays green until that secret exists, and the scan starts working the moment it's added. No coordination required between merging this and provisioning the token.Two things worth a decision
Post-Cypress (generate coverage)steps andCYPRESS_COVERAGE: trueare left in place. Sonar looked like their only consumer, so they may now be dead CI time — but that is a separate change and I did not want to assume nothing else readscoverage/lcov.info.Note that Qodana's config here is a security scope, not a like-for-like replacement for Sonar's code-quality gate.
🤖 Generated with Claude Code