chore(sonar): exclude eng tooling from analysis - #210
Conversation
|
Navigate logical layers of code changes, visualize relationships, and explore their blast radius. No actionable comments were generated in the recent review. 🎉 ℹ️ Recent review info⚙️ Run configurationConfiguration used: Repository: rodri-oliveira-dev/Dapper-FluentMap/https://raw.githubusercontent.com/rodri-oliveira-dev/.github/main/coderabbit-templates/dotnet-library.yaml (via .coderabbit.yaml) Review profile: ASSERTIVE Plan: Advanced Run ID: 📒 Files selected for processing (1)
Included review availability: This review used your included allowance. Your plan provides up to 10 included reviews per hour; 8 remain after this review. 📜 Recent review details⏰ Context from checks skipped due to timeout. (7)
🧰 Additional context used📓 Path-based instructions (1)Verifique permissões mínimas, exposição de secrets, pinning seguro de actions, supply chain, condições de execução e confiabilidade do pipeline.⚙️ CodeRabbit configuration file Files:
🔇 Additional comments (1)
📝 WalkthroughWalkthroughO workflow do CI remove ChangesExclusões do SonarQube
Priority: ⬇️ Low Estimated code review effort: 1 (Trivial) | ~3 minutes Change: Other Merge Risk: ⚪ Minimal · up to Engineering tooling remains excluded from Sonar analysis and coverage. No material merge risk is evident. Architecture SummaryArchitecture risk: 🔵 Low · up to The changed surface does not map to a changed system, dependency edge, entrypoint, or external dependency. Changed systems: None identified. Architecture concerns Review detailsBefore / after behavior
🚥 Pre-merge checks | ✅ 5✅ Passed checks (5 passed)
✨ Finishing Touches🧪 Generate unit tests (beta)
Comment |
SonarQube Cloud successThe SonarQube Cloud Quality Gate passed for this PR. Quality Gate status: OK
|
Summary
eng/consumer-smoke/**exclusion witheng/**insonar.exclusionseng/**exclusion tosonar.coverage.exclusionscheck-jsonschema==0.38.0installation fromfix/sonar-pip-only-binary, including the YAML quoting correction from PR fix(ci): require binary package installation #209 reviewRationale
The
eng/**tree contains internal build, release, validation, and repository tooling. Removing the complete directory from SonarQube Cloud static analysis and coverage metrics keeps those measurements focused on the library production code.The incorporated pip change prevents fallback to source distributions while keeping the workflow valid by quoting the
runscalar that contains:.Validation
actionlint 1.7.12check-jsonschema==0.38.0and thevendor.github-workflowsschemaeng/consumer-smoke/**no longer remains in either parametereng/test-release-governance.ps1for the Sonar exclusion change.github/workflows/ci.ymlis includedSummary by CodeRabbit