| 123456789101112131415161718192021222324252627282930313233343536373839404142434445 |
- name: SonarCloud Scan (main and develop branch)
- on:
- push:
- branches:
- - main
- - develop
- # Allows you to run this workflow manually from the Actions tab
- workflow_dispatch:
- jobs:
- sonar:
- name: SonarCloud Scan
- runs-on: ubuntu-latest
- if: ${{ github.actor != 'dependabot[bot]' }}
- steps:
- - uses: actions/checkout@v3
- with:
- fetch-depth: 0 # Shallow clones should be disabled for a better relevancy of analysis
- - name: Set up JDK
- uses: actions/setup-java@v3
- with:
- distribution: 'temurin'
- java-version: 17
- - name: Cache SonarCloud packages
- uses: actions/cache@v3
- with:
- path: ~/.sonar/cache
- key: ${{ runner.os }}-sonar
- restore-keys: ${{ runner.os }}-sonar
- - name: Cache Maven packages
- uses: actions/cache@v3
- with:
- path: ~/.m2
- key: ${{ runner.os }}-m2-${{ hashFiles('**/pom.xml') }}
- restore-keys: ${{ runner.os }}-m2
-
- - name: Build and analyze
- env:
- GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }}
- SONAR_TOKEN: ${{ secrets.SONAR_TOKEN }}
- run: mvn -U -B verify org.sonarsource.scanner.maven:sonar-maven-plugin:sonar
|