Skip to content

chore(sonar): exclude eng tooling from analysis - #210

Merged
rodri-oliveira-dev merged 4 commits into
mainfrom
chore/sonar-exclude-eng
Sep 29, 2026
Merged

rodri-oliveira-dev merged 4 commits into
mainfrom
chore/sonar-exclude-eng

Conversation

@rodri-oliveira-dev

@rodri-oliveira-dev rodri-oliveira-dev commented Sep 29, 2026 •

Copy link
Copy Markdown
Owner

Summary

  • replace the partial eng/consumer-smoke/** exclusion with eng/** in sonar.exclusions
  • apply the same eng/** exclusion to sonar.coverage.exclusions
  • preserve all other scanner parameters and existing exclusions
  • incorporate the binary-only check-jsonschema==0.38.0 installation from fix/sonar-pip-only-binary, including the YAML quoting correction from PR fix(ci): require binary package installation #209 review

Rationale

The eng/** tree contains internal build, release, validation, and repository tooling. Removing the complete directory from SonarQube Cloud static analysis and coverage metrics keeps those measurements focused on the library production code.

The incorporated pip change prevents fallback to source distributions while keeping the workflow valid by quoting the run scalar that contains : .

Validation

  • validated all six GitHub workflow files with verified actionlint 1.7.12
  • validated all six workflows with check-jsonschema==0.38.0 and the vendor.github-workflows schema
  • confirmed both Sonar scanner arguments are present exactly once and remain correctly formatted
  • confirmed eng/consumer-smoke/** no longer remains in either parameter
  • passed eng/test-release-governance.ps1 for the Sonar exclusion change
  • reviewed the combined diff; only .github/workflows/ci.yml is included

Summary by CodeRabbit

  • Manutenção
    • Os relatórios internos de qualidade e cobertura passam a excluir de forma mais ampla os diretórios de engenharia, incluindo os testes de fumaça do consumidor.
    • A instalação da ferramenta de validação de configuração passa a aceitar apenas distribuições binárias.
    • Essas alterações afetam os processos internos de análise e validação; não alteram a funcionalidade disponível no aplicativo.

@coderabbitai

coderabbitai Bot commented Sep 29, 2026 •

Copy link
Copy Markdown

Review in Change Stack →

Navigate logical layers of code changes, visualize relationships, and explore their blast radius.

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration

Configuration used: Repository: rodri-oliveira-dev/Dapper-FluentMap/https://raw.githubusercontent.com/rodri-oliveira-dev/.github/main/coderabbit-templates/dotnet-library.yaml (via .coderabbit.yaml)

Review profile: ASSERTIVE

Plan: Advanced

Run ID: 71aa19a8-e771-4f31-b7af-e161099f28db

📥 Commits

Reviewing files that changed from the base of the PR and between d873f74 and 0d7a2df.

📒 Files selected for processing (1)
  • .github/workflows/ci.yml

Included review availability: This review used your included allowance. Your plan provides up to 10 included reviews per hour; 8 remain after this review.

📜 Recent review details
⏰ Context from checks skipped due to timeout. (7)
  • GitHub Check: Repository configuration
  • GitHub Check: Compatibility (minimum, Dapper 2.1.79)
  • GitHub Check: Native AOT strict generated smoke (SQLite, win-x64)
  • GitHub Check: Analyzer and generator compatibility
  • GitHub Check: Compatibility (latest-stable, Dapper 2.1.89)
  • GitHub Check: Provider compatibility (SQL Server, PostgreSQL, MySQL, MariaDB)
  • GitHub Check: Analyze C# with CodeQL
🧰 Additional context used
📓 Path-based instructions (1)
Verifique permissões mínimas, exposição de secrets, pinning seguro de actions, supply chain, condições de execução e confiabilidade do pipeline.

⚙️ CodeRabbit configuration file

Files:

  • .github/workflows/ci.yml
🔇 Additional comments (1)
.github/workflows/ci.yml (1)

516-517: LGTM!


📝 Walkthrough

Walkthrough

O workflow do CI remove eng/consumer-smoke/** das exclusões do SonarQube para análise e cobertura. O padrão geral eng/** permanece em ambas as configurações.

Changes

Exclusões do SonarQube

Layer / File(s) Summary
Atualização dos padrões de exclusão
.github/workflows/ci.yml
As configurações de análise e cobertura deixam de listar eng/consumer-smoke/** separadamente e mantêm eng/**.

Priority: ⬇️ Low

Estimated code review effort: 1 (Trivial) | ~3 minutes

Change: Other

Merge Risk: ⚪ Minimal · up to 0d7a2

Engineering tooling remains excluded from Sonar analysis and coverage. No material merge risk is evident.

Architecture Summary

Architecture risk: 🔵 Low · up to 0d7a2

The changed surface does not map to a changed system, dependency edge, entrypoint, or external dependency.

Changed systems: None identified.

Architecture concerns
No architecture-level concerns identified.

Review details

Before / after behavior

  • observed — Modified behavior in .github/workflows/ci.yml: As exclusões do SonarQube removem eng/consumer-smoke/** e mantêm eng/**, junto às demais exclusões, para análise e cobertura.
🚥 Pre-merge checks | ✅ 5
✅ Passed checks (5 passed)
Check name Status Explanation
Docstring Coverage ✅ Passed No functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check. Docstring coverage is scoped to functions touched by this diff. Analyzed 0 functions across 0…
Linked Issues check ✅ Passed Check skipped because no linked issues were found for this pull request.
Out of Scope Changes check ✅ Passed Check skipped because no linked issues were found for this pull request.
Description Check ✅ Passed Check skipped - CodeRabbit’s high-level summary is enabled.
Title check ✅ Passed O título resume de forma clara e concisa a alteração principal: excluir ferramentas de engenharia da análise do SonarQube. Ele corresponde às mudanças em .github/workflows/ci.yml e ao objetivo do pu…
✨ Finishing Touches
🧪 Generate unit tests (beta)
  • Commit to this branch
  • Create a new PR

Comment @coderabbitai help to get the list of available commands.

@github-actions

github-actions Bot commented Sep 29, 2026 •

Copy link
Copy Markdown
Contributor

SonarQube Cloud success

The SonarQube Cloud Quality Gate passed for this PR.

Quality Gate status: OK

Metric Status Actual Threshold
new_reliability_rating OK 1 1
new_security_rating OK 1 1
new_maintainability_rating OK 1 1
new_duplicated_lines_density OK 0.0 3
new_security_hotspots_reviewed OK 100.0 100

@rodri-oliveira-dev
rodri-oliveira-dev merged commit 05b2a25 into main Sep 29, 2026
12 of 13 checks passed
@rodri-oliveira-dev
rodri-oliveira-dev deleted the chore/sonar-exclude-eng branch September 29, 2026 18:58
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant