Repository navigation
refactor(forge): share pagination as a function and keep RestClient f… #1511
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
| name: SonarQube | |
| # Static analysis on the self-hosted SonarQube (https://sonar.ferrlabs.com), | |
| # via the org-wide reusable workflow. Every run pins sonar.projectVersion to | |
| # the latest release tag so each analysis is attributed to the version it | |
| # belongs to (and SonarQube's new-code period lines up with releases). | |
| # | |
| # Runs on a GitHub-hosted runner: this repo is public and the self-hosted | |
| # `ferrlabs-k8s` group has allows_public_repositories=false. | |
| on: | |
| push: | |
| branches: [main] | |
| pull_request: | |
| concurrency: | |
| group: ${{ github.workflow }}-${{ github.ref }} | |
| cancel-in-progress: ${{ github.event_name == 'pull_request' }} | |
| permissions: | |
| contents: read | |
| jobs: | |
| version: | |
| name: Resolve latest release tag | |
| runs-on: ubuntu-latest | |
| outputs: | |
| version: ${{ steps.tag.outputs.version }} | |
| steps: | |
| - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7 | |
| with: | |
| fetch-depth: 0 | |
| - id: tag | |
| # Highest semver release tag (vX.Y.Z), independent of branch | |
| # reachability — `git describe` would return the nearest ancestor | |
| # tag, which goes stale on feature branches and PRs. The floating | |
| # major tag (v5) is excluded by requiring the two dots. | |
| run: | | |
| TAG=$(git tag -l 'v[0-9]*.[0-9]*.[0-9]*' --sort=-v:refname | head -n1) | |
| VERSION="${TAG#v}" | |
| echo "version=${VERSION:-0.0.0}" >> "$GITHUB_OUTPUT" | |
| echo "Latest release tag: ${TAG:-<none>} -> projectVersion=${VERSION:-0.0.0}" | |
| # Coverage lives here rather than in ci.yml because the reusable scan | |
| # downloads the report from an artifact in the same run, and artifacts do | |
| # not cross workflow runs. Tarpaulin is slow, so it runs once and feeds | |
| # both Sonar and Codecov instead of once per workflow. | |
| coverage: | |
| name: Coverage | |
| runs-on: ubuntu-latest | |
| steps: | |
| - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7 | |
| - uses: dtolnay/rust-toolchain@6bed0761d98439e5a578e2877258200ad565ba87 # stable | |
| - uses: Swatinem/rust-cache@6323deb102c322ba6fcbdcafc7e3dddab59af2b6 # v2 | |
| - uses: taiki-e/install-action@67729d5c413db75907f0ad1e39bb04b9c868ff60 # v2 | |
| with: | |
| tool: cargo-tarpaulin | |
| - name: Generate coverage | |
| run: cargo tarpaulin --out xml --skip-clean | |
| - uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7 | |
| with: | |
| name: coverage-cobertura | |
| path: cobertura.xml | |
| retention-days: 1 | |
| - uses: codecov/codecov-action@303a32d7a59b442fa8d48b6a1cc6825c09c847a5 # v7 | |
| with: | |
| files: cobertura.xml | |
| token: ${{ secrets.CODECOV_TOKEN }} | |
| fail_ci_if_error: false | |
| scan: | |
| needs: [version, coverage] | |
| # The reusable workflow declares `pull-requests: write` (it posts the diff | |
| # against the base project). The job would otherwise inherit the read-only | |
| # workflow-level block above, and GitHub rejects the run before it starts. | |
| permissions: | |
| contents: read | |
| pull-requests: write | |
| uses: FerrLabs/.github/.github/workflows/reusable-sonarqube-scan.yml@dc37316d0b31cb7a47455f2933202533f9c909bd # main | |
| with: | |
| runner: ubuntu-latest | |
| project-key: ferrflow | |
| coverage-artifact: coverage-cobertura | |
| args: >- | |
| -Dsonar.projectVersion=${{ needs.version.outputs.version }} | |
| -Dsonar.rust.cobertura.reportPaths=.sonarcov/cobertura.xml | |
| secrets: inherit |