A second static-analysis pass alongside vuln, from the security sweep
(#149). Report-only: the scan ends in || true, so a first run against
an existing codebase does not turn every build red before it has been
read. Dropping the || true makes the quality gate binding.
Before this merges you need to set the token, or the job skips on every build:
gitbay repo secret set krz/gitbay SONAR_TOKEN
Value on stdin. Generate it at SonarCloud (My Account → Security, or a project analysis token) — I can't mint one.
Three things the vendor snippet doesn't survive here, each of which would have bitten on the first run:
- Each step is its own
sh -c, so the snippet's threeexports never reach the scanner. It's one step. - Fork merge requests build without secrets by design (
BuildSecretsis read only whenb.Trusted). Without a guard, every outside contribution fails on a missing credential. The step says why it is skipping and exits 0 — verified by running it with the variable unset. - The snippet re-downloads ~50 MB per run. Cached under the runner's home, fetched only when the binary isn't already there.
Coverage is deliberately absent: most of this repo's coverage comes from
the e2e suite, and re-running it under -coverprofile doubles CI time,
while unit-only coverage would report misleadingly low numbers for
packages e2e exercises heavily.
What is not verified: the install-and-scan path itself. Without a token the job skips, so until the secret exists CI proves only that the skip works. I checked the scanner URL resolves (HTTP 200) and the step parses and is syntactically valid, but the first real scan will be the first time that branch runs.
Ref #149