CLP-996 Split build from analysis for sonar-xml - #588
guillaume-dequenne wants to merge 1 commit into
Conversation
|
|
This PR is stale because it has been open 7 days with no activity. If there is no activity in the next 7 days it will be closed automatically |
| with: | ||
| name: build-output-${{ steps.build.outputs.BUILD_NUMBER }} | ||
| path: '**/target' | ||
| retention-days: 3 |
There was a problem hiding this comment.
why 3? It's fairly cheap - I'd add at least 7. Sometimes we leave PRs in the side then rerun them. Better if the artifact is cached.
| sonar-platform: none | ||
| maven-args: -Pcoverage | ||
|
|
||
| - name: Upload build output for scanning |
There was a problem hiding this comment.
| - name: Upload build output for scanning | |
| - name: Upload plugin build as pipeline artifact |
| with: | ||
| build-version: ${{ steps.build.outputs.project-version }} | ||
|
|
||
| scan: |
| build-version: ${{ steps.build.outputs.project-version }} | ||
|
|
||
| scan: | ||
| name: Scan |
There was a problem hiding this comment.
| name: Scan | |
| name: Analysis |
Maybe can also be renamed as "NEXT analysis" or "SonarQube Cloud analysis" based on what the repo is using. WDYT?
| skip-build: true | ||
| sonar-platform: next | ||
| artifactory-reader-role: private-reader | ||
| artifactory-deployer-role: qa-deployer |
There was a problem hiding this comment.
this has no effect I think.
We can remove it.
82efc48 to
c1f9b96
Compare
Keep build, tests, coverage, and deployment in the producer job. Upload the target directories for a scanner-only analysis job that can be rerun independently, and gate promotion on its result.
7b6bc36 to
d2678d8
Compare
|
Code Review ✅ Approved 2 closed / 2 findings🟡 Medium risk · Splitting Maven build and NEXT analysis changes CI artifact flow and promotion gating. Splits Maven build from NEXT analysis into separate CI jobs, with build outputs uploaded as seven-day artifacts for restoration during analysis. Addressed the analysis job's outdated mise version pin and resolved the action version mismatch between producer ( ✅ 2 closed✅ Quality: Analysis job pins older mise version (2026.9.11) than other jobs
✅ Cross-PR: Analysis pin's re-pin note targets @v1 while #598 moves repo to @v2
Review coverage🧪 Functional validation 3 of 3 objectives covered 📋 Rules No rules evaluated 🤖 Auto-approval Not enabled · Set up Implementation Status ✅ 3 of 3 objectives covered✅ CLP-897 - 3 of 3 objectives coveredThis PR covers splitting the build and analysis jobs by creating a producer job that uploads the build artifact and a consumer analysis job that downloads it. ✅ 3 covered here
OptionsAuto-apply is off → Gitar will not commit updates to this branch. Comment with these commands to change the behavior for this request:
Was this helpful? React with 👍 / 👎 | Gitar |





Part of CLP-897
Summary
Dependency
2.3.0. The analysis job usesbuild-maven@v2.@v1on this branch. Reconcile the open v2 migration PR before merging so producer and consumer use the same major version.Validation
v2and release2.3.0point to the mergedskip-buildaction commit.git diff --checkafter replacing the action pin.