Dominik Fuchß 4 лет назад
Родитель
Сommit
0454bdd3fa
2 измененных файлов с 45 добавлено и 13 удалено
  1. 44 0
      .github/workflows/sonarcloud-branch.yml
  2. 1 13
      .github/workflows/sonarcloud-pr.yml

+ 44 - 0
.github/workflows/sonarcloud-branch.yml

@@ -0,0 +1,44 @@
+name: SonarCloud Scan (triggered by maven.yml)
+
+on:
+  push:
+    branches:
+      - master
+
+  # Allows you to run this workflow manually from the Actions tab
+  workflow_dispatch:
+
+jobs:
+  sonar:
+    name: SonarCloud Scan
+    runs-on: ubuntu-latest
+    if: ${{ github.actor != 'dependabot[bot]' }}
+
+    steps:
+      - uses: actions/checkout@v3
+        with:
+          fetch-depth: 0  # Shallow clones should be disabled for a better relevancy of analysis
+      - name: Set up JDK
+        uses: actions/setup-java@v3
+        with:
+          distribution: 'temurin'
+          java-version: 17
+
+      - name: Cache SonarCloud packages
+        uses: actions/cache@v3
+        with:
+          path: ~/.sonar/cache
+          key: ${{ runner.os }}-sonar
+          restore-keys: ${{ runner.os }}-sonar
+      - name: Cache Maven packages
+        uses: actions/cache@v3
+        with:
+          path: ~/.m2
+          key: ${{ runner.os }}-m2-${{ hashFiles('**/pom.xml') }}
+          restore-keys: ${{ runner.os }}-m2
+          
+      - name: Build and analyze
+        env:
+          GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }}
+          SONAR_TOKEN: ${{ secrets.SONAR_TOKEN }}
+        run: mvn -U -B verify org.sonarsource.scanner.maven:sonar-maven-plugin:sonar

+ 1 - 13
.github/workflows/sonarcloud.yml → .github/workflows/sonarcloud-pr.yml

@@ -38,7 +38,7 @@ jobs:
   sonar:
     name: SonarCloud Scan
     runs-on: ubuntu-latest
-    if: ${{ github.actor != 'dependabot[bot]' && github.event.workflow_run.conclusion == 'success' }}
+    if: ${{ needs.get-info.outputs.sourceEvent == 'pull_request' && github.actor != 'dependabot[bot]' && github.event.workflow_run.conclusion == 'success' }}
     needs: get-info
 
     steps:
@@ -67,7 +67,6 @@ jobs:
           restore-keys: ${{ runner.os }}-m2
           
       - name: Build and analyze (PR)
-        if: ${{ needs.get-info.outputs.sourceEvent == 'pull_request' }}
         env:
           GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }}
           SONAR_TOKEN: ${{ secrets.SONAR_TOKEN }}
@@ -78,14 +77,3 @@ jobs:
           -Dsonar.pullrequest.branch=${{ needs.get-info.outputs.sourceHeadBranch }} 
           -Dsonar.pullrequest.base=${{ needs.get-info.outputs.pullRequestNumber }} 
           -U -B verify org.sonarsource.scanner.maven:sonar-maven-plugin:sonar
-          
-      - name: Build and analyze (Branch)
-        if: ${{ needs.get-info.outputs.sourceEvent != 'pull_request' }}
-        env:
-          GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }}
-          SONAR_TOKEN: ${{ secrets.SONAR_TOKEN }}
-        run: >
-          mvn 
-          -Dsonar.scm.revision=${{ github.event.workflow_run.head_sha }} 
-          -U -B verify org.sonarsource.scanner.maven:sonar-maven-plugin:sonar
-