diff --git a/.gitea/workflows/ci.yml b/.gitea/workflows/ci.yml new file mode 100644 index 00000000..27edcb06 --- /dev/null +++ b/.gitea/workflows/ci.yml @@ -0,0 +1,39 @@ +name: ci + +on: + push: + branches: ["main"] + workflow_dispatch: + +concurrency: + group: ${{ github.workflow }}-${{ github.head_ref || github.ref }} + cancel-in-progress: true + +jobs: + sonar: + # SonarQube Community Build har inget separat PR-analysläge (en enda "main"-gren + # per projekt) — en analys från en PR-branch eller en tagg-push som inte pekar på + # main skulle skriva över kvalitetshistoriken. Kör därför bara + # vid push till main. + if: github.event_name == 'push' && github.ref == 'refs/heads/main' + runs-on: ubuntu-latest + timeout-minutes: 20 + steps: + - uses: https://git.siax.io/actions/checkout@34e114876b0b11c390a56381ad16ebd13914f8d5 # mirrored, immutable + with: + fetch-depth: 0 + - name: SonarQube analysis (self-hosted sonar.siax.io) + env: + SONAR_HOST_URL: https://sonar.siax.io + SONAR_TOKEN: ${{ secrets.SONAR_TOKEN }} + run: | + set -euo pipefail + test -n "$SONAR_TOKEN" || { echo "::error::SONAR_TOKEN repo secret missing"; exit 1; } + # Jobbet kör i en container på act_runner; "docker run -v \"$PWD:...\"" + # skulle montera VÄRDENS (tomma) sökväg. Kopiera in källträdet istället. + cid=$(docker create -e SONAR_HOST_URL -e SONAR_TOKEN -w /usr/src \ + sonarsource/sonar-scanner-cli:latest \ + sonar-scanner -Dsonar.projectKey=accounted -Dsonar.host.url="$SONAR_HOST_URL") + trap 'docker rm -f "$cid" >/dev/null 2>&1 || true' EXIT + docker cp . "$cid":/usr/src + docker start -a "$cid" diff --git a/sonar-project.properties b/sonar-project.properties new file mode 100644 index 00000000..bc062285 --- /dev/null +++ b/sonar-project.properties @@ -0,0 +1,3 @@ +sonar.projectKey=accounted +sonar.host.url=https://sonar.siax.io +sonar.exclusions=**/node_modules/**,**/dist/**,**/build/**,**/.next/**,**/out/**,**/coverage/**,**/__pycache__/**,**/*.min.js