Skip to content

refactor(forge): share pagination as a function and keep RestClient f… #1511

refactor(forge): share pagination as a function and keep RestClient f…

refactor(forge): share pagination as a function and keep RestClient f… #1511

Workflow file for this run

name: SonarQube
# Static analysis on the self-hosted SonarQube (https://sonar.ferrlabs.com),
# via the org-wide reusable workflow. Every run pins sonar.projectVersion to
# the latest release tag so each analysis is attributed to the version it
# belongs to (and SonarQube's new-code period lines up with releases).
#
# Runs on a GitHub-hosted runner: this repo is public and the self-hosted
# `ferrlabs-k8s` group has allows_public_repositories=false.
on:
push:
branches: [main]
pull_request:
concurrency:
group: ${{ github.workflow }}-${{ github.ref }}
cancel-in-progress: ${{ github.event_name == 'pull_request' }}
permissions:
contents: read
jobs:
version:
name: Resolve latest release tag
runs-on: ubuntu-latest
outputs:
version: ${{ steps.tag.outputs.version }}
steps:
- uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7
with:
fetch-depth: 0
- id: tag
# Highest semver release tag (vX.Y.Z), independent of branch
# reachability — `git describe` would return the nearest ancestor
# tag, which goes stale on feature branches and PRs. The floating
# major tag (v5) is excluded by requiring the two dots.
run: |
TAG=$(git tag -l 'v[0-9]*.[0-9]*.[0-9]*' --sort=-v:refname | head -n1)
VERSION="${TAG#v}"
echo "version=${VERSION:-0.0.0}" >> "$GITHUB_OUTPUT"
echo "Latest release tag: ${TAG:-<none>} -> projectVersion=${VERSION:-0.0.0}"
# Coverage lives here rather than in ci.yml because the reusable scan
# downloads the report from an artifact in the same run, and artifacts do
# not cross workflow runs. Tarpaulin is slow, so it runs once and feeds
# both Sonar and Codecov instead of once per workflow.
coverage:
name: Coverage
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7
- uses: dtolnay/rust-toolchain@6bed0761d98439e5a578e2877258200ad565ba87 # stable
- uses: Swatinem/rust-cache@6323deb102c322ba6fcbdcafc7e3dddab59af2b6 # v2
- uses: taiki-e/install-action@67729d5c413db75907f0ad1e39bb04b9c868ff60 # v2
with:
tool: cargo-tarpaulin
- name: Generate coverage
run: cargo tarpaulin --out xml --skip-clean
- uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7
with:
name: coverage-cobertura
path: cobertura.xml
retention-days: 1
- uses: codecov/codecov-action@303a32d7a59b442fa8d48b6a1cc6825c09c847a5 # v7
with:
files: cobertura.xml
token: ${{ secrets.CODECOV_TOKEN }}
fail_ci_if_error: false
scan:
needs: [version, coverage]
# The reusable workflow declares `pull-requests: write` (it posts the diff
# against the base project). The job would otherwise inherit the read-only
# workflow-level block above, and GitHub rejects the run before it starts.
permissions:
contents: read
pull-requests: write
uses: FerrLabs/.github/.github/workflows/reusable-sonarqube-scan.yml@dc37316d0b31cb7a47455f2933202533f9c909bd # main
with:
runner: ubuntu-latest
project-key: ferrflow
coverage-artifact: coverage-cobertura
args: >-
-Dsonar.projectVersion=${{ needs.version.outputs.version }}
-Dsonar.rust.cobertura.reportPaths=.sonarcov/cobertura.xml
secrets: inherit