Commit a5e232bfe9
a5e232bfe9ec9b6757952fbc9403b47917f9438e
parent: f84bca7807
Verified · cmc ci/build: success ci/sonar: success ci/test: success ci/vuln: success
cmc <hello@cleberg.net> · 2026-09-05 01:06 UTC
ci: analyse each branch as itself, not as main
The scanner ran with no branch name, so every analysis was recorded
against the project's main branch whatever branch produced it — and the
job runs on every push, so a feature branch replaced main's results.
Not theoretical: while dismissing the first scan's false positives the
dashboard was showing an unmerged branch's head, and two findings open on
main read as FIXED on the strength of a commit main does not contain.
Wrong in both directions. A branch that removes findings makes main look
clean before the fix is merged; one that adds findings makes main look
broken when it is not. Once the gate is binding rather than reporting, it
would follow whichever branch built last.
A branch other than main now passes -Dsonar.branch.name and keeps its own
history. main passes nothing and stays the project's default analysis.
The step still ends in `|| true`, so an instance whose plan does not
offer branch analysis loses the branch scans rather than the build — and
main stops being overwritten either way, which is the part that matters.
Closes #154
Layout: unified · split
.gitbay/ci.yml
+12 −1
| @@ -53,5 +53,16 @@ jobs: |
| 53 | 53 | unzip -q -o "$HOME_DIR/.sonar/sonar-scanner.zip" -d "$HOME_DIR/.sonar/" |
| 54 | 54 | rm -f "$HOME_DIR/.sonar/sonar-scanner.zip" |
| 55 | 55 | fi |
| 56 | # Analyse each branch as itself. Without this every branch is |
| 57 | # recorded against the project's main branch, so a feature branch |
| 58 | # replaces main's results — a branch that removes findings makes |
| 59 | # main look clean before its fix is merged, and one that adds |
| 60 | # findings makes main look broken when it is not (#154). |
| 61 | BRANCH="${GITBAY_REF:-}" |
| 62 | BRANCH="${BRANCH#refs/heads/}" |
| 63 | BRANCH_ARG="" |
| 64 | if [ -n "$BRANCH" ] && [ "$BRANCH" != "main" ]; then |
| 65 | BRANCH_ARG="-Dsonar.branch.name=$BRANCH" |
| 66 | fi |
| 56 | 67 | SONAR_HOST_URL=https://sonarcloud.io \ |
| 57 | | "$SCANNER/bin/sonar-scanner" -Dsonar.scm.revision="${GITBAY_SHA:-}" || true |
| 68 | "$SCANNER/bin/sonar-scanner" -Dsonar.scm.revision="${GITBAY_SHA:-}" $BRANCH_ARG || true |