Commit a5e232bfe9

a5e232bfe9ec9b6757952fbc9403b47917f9438e

parent: f84bca7807

Verified · cmc ci/build: success ci/sonar: success ci/test: success ci/vuln: success

cmc <hello@cleberg.net> · 2026-09-05 01:06 UTC

ci: analyse each branch as itself, not as main

The scanner ran with no branch name, so every analysis was recorded
against the project's main branch whatever branch produced it — and the
job runs on every push, so a feature branch replaced main's results.

Not theoretical: while dismissing the first scan's false positives the
dashboard was showing an unmerged branch's head, and two findings open on
main read as FIXED on the strength of a commit main does not contain.

Wrong in both directions. A branch that removes findings makes main look
clean before the fix is merged; one that adds findings makes main look
broken when it is not. Once the gate is binding rather than reporting, it
would follow whichever branch built last.

A branch other than main now passes -Dsonar.branch.name and keeps its own
history. main passes nothing and stays the project's default analysis.
The step still ends in `|| true`, so an instance whose plan does not
offer branch analysis loses the branch scans rather than the build — and
main stops being overwritten either way, which is the part that matters.

Closes #154

Layout: unified · split

.gitbay/ci.yml +12 −1
@@ -53,5 +53,16 @@ jobs:
5353 unzip -q -o "$HOME_DIR/.sonar/sonar-scanner.zip" -d "$HOME_DIR/.sonar/"
5454 rm -f "$HOME_DIR/.sonar/sonar-scanner.zip"
5555 fi
56 # Analyse each branch as itself. Without this every branch is
57 # recorded against the project's main branch, so a feature branch
58 # replaces main's results — a branch that removes findings makes
59 # main look clean before its fix is merged, and one that adds
60 # findings makes main look broken when it is not (#154).
61 BRANCH="${GITBAY_REF:-}"
62 BRANCH="${BRANCH#refs/heads/}"
63 BRANCH_ARG=""
64 if [ -n "$BRANCH" ] && [ "$BRANCH" != "main" ]; then
65 BRANCH_ARG="-Dsonar.branch.name=$BRANCH"
66 fi
5667 SONAR_HOST_URL=https://sonarcloud.io \
57 "$SCANNER/bin/sonar-scanner" -Dsonar.scm.revision="${GITBAY_SHA:-}" || true
68 "$SCANNER/bin/sonar-scanner" -Dsonar.scm.revision="${GITBAY_SHA:-}" $BRANCH_ARG || true