ci: SonarCloud static analysis, report-only !248

merged merged by cmc on 2026-09-04 19:43 UTC · krz/gitbay:sonar-scan into main

Discussion

cmc

A second static-analysis pass alongside vuln, from the security sweep (#149). Report-only: the scan ends in || true, so a first run against an existing codebase does not turn every build red before it has been read. Dropping the || true makes the quality gate binding.

Before this merges you need to set the token, or the job skips on every build:

gitbay repo secret set krz/gitbay SONAR_TOKEN

Value on stdin. Generate it at SonarCloud (My Account → Security, or a project analysis token) — I can't mint one.

Three things the vendor snippet doesn't survive here, each of which would have bitten on the first run:

  • Each step is its own sh -c, so the snippet's three exports never reach the scanner. It's one step.
  • Fork merge requests build without secrets by design (BuildSecrets is read only when b.Trusted). Without a guard, every outside contribution fails on a missing credential. The step says why it is skipping and exits 0 — verified by running it with the variable unset.
  • The snippet re-downloads ~50 MB per run. Cached under the runner's home, fetched only when the binary isn't already there.

Coverage is deliberately absent: most of this repo's coverage comes from the e2e suite, and re-running it under -coverprofile doubles CI time, while unit-only coverage would report misleadingly low numbers for packages e2e exercises heavily.

What is not verified: the install-and-scan path itself. Without a token the job skips, so until the secret exists CI proves only that the skip works. I checked the scanner URL resolves (HTTP 200) and the step parses and is syntactically valid, but the first real scan will be the first time that branch runs.

Ref #149