Add Sonar analysis to repository#90
Conversation
c88f850 to
a789054
Compare
gradle-modules/src/main/kotlin/org.sonarsource.cloud-native.publishing-configuration.gradle.kts
Fixed
Show fixed
Hide fixed
a789054 to
36010c5
Compare
0c37dee to
f10f947
Compare
f10f947 to
25fa5ce
Compare
mstachniuk
left a comment
There was a problem hiding this comment.
|
SonarQube reviewer guideImportant We are currently testing different models for AI Summary. Model A:Summary: Add GitHub Actions caching, SonarQube integration, and shadow scan workflow Review Focus: The custom Gradle cache key generation using md5sum of multiple files; the new shadow-scan workflow configuration with IRIS analysis; migration from direct Gradle command to SonarSource's build-gradle action with disabled caching. Start review at: Model B:Summary: Refactor CI/CD pipelines to use standardized SonarSource build actions with Gradle caching, add shadow scan workflow, and configure root build.gradle with SonarQube plugin. Review Focus:
Start review at:
|
SonarQube reviewer guideImportant We are currently testing different models for AI Summary. Model A:Summary: Add SonarQube analysis with shadow scans and improve Gradle caching in CI workflows. Review Focus: The custom Gradle cache key generation logic using MD5 hashing of build files is duplicated across workflows and could be error-prone. Verify the shadow scan configuration correctly targets the three different SonarQube platforms (Next, SQC-EU, SQC-US). Ensure the Start review at: Model B:Summary: Refactor CI/CD build process with Gradle caching optimization and add new shadow scan workflow for security analysis. Review Focus:
Start review at:
|
|
@mstachniuk It's not always this slow, the last run took 2m. I don't know why it happens, seems to be flaky / sleeping github runners... |








No description provided.