Skip to content

ci(sonarcloud): add SonarCloud analysis with Quality Gate on PRs - #22

Merged
santidev21 merged 2 commits into
mainfrom
chore/sonarcloud
Oct 1, 2026
Merged

santidev21 merged 2 commits into
mainfrom
chore/sonarcloud

Conversation

@santidev21

Copy link
Copy Markdown
Owner

Summary

  • New .github/workflows/sonarcloud.yml: SonarScanner for .NET (begin → build → test with coverage → end) on push to main, pull_request and workflow_dispatch.
  • Quality Gate: sonar.qualitygate.wait=true on PR events only — the Sonar way gate evaluates new code (Clean as You Code), so a red check here means this PR introduced issues. The first push to main is the baseline (everything counts as new) and must not block CI on pre-existing debt.
  • Zero-warnings preserved: the analysis build alone passes -p:TreatWarningsAsErrors=false because SonarScanner injects its own Roslyn analyzers for that build. The gate in ci.yml (build-and-test job) is untouched, and the solution still has no SonarAnalyzer package — SonarCloud is the only analyzer, as decided in the plan.
  • coverlet.runsettings now emits opencover alongside cobertura so SonarCloud imports coverage; check-coverage.mjs (85% gate) still reads cobertura only and is unchanged.
  • PR parameters are passed explicitly (the scanner does not auto-detect GitHub Actions) and fetch-depth: 0 gives SonarCloud the blame data needed for new-code detection.
  • Job is skipped for Dependabot and fork PRs (repository secrets are unavailable there).
  • .sonarqube/ (scanner working dir) added to .gitignore.

Setup already done

  • Org santidev21 imported/bound to GitHub; project santidev21_MyBudgetBot created.
  • SONAR_TOKEN repository secret configured.

Not touched

  • Existing ci.yml gates (build with zero warnings, dotnet format, 85% coverage) remain the source of truth.

… PRs

- New .github/workflows/sonarcloud.yml: dotnet-sonarscanner begin/build/
  test/end on push to main, pull requests and manual dispatch.
- sonar.qualitygate.wait=true on pull_request events only: the Sonar way
  gate evaluates new code, so a red build means the PR introduced issues.
  The first push to main is the baseline (everything counts as new) and
  must not block CI on pre-existing debt.
- The analysis build passes TreatWarningsAsErrors=false: SonarScanner
  injects its own Roslyn analyzers for that build only. The zero-warnings
  gate is unchanged in ci.yml, and the solution still has no SonarAnalyzer
  package reference by design.
- PR parameters are passed explicitly because the scanner does not
  auto-detect GitHub Actions.
- Job is skipped for Dependabot and fork PRs (no repository secrets).
- coverlet.runsettings: emit opencover alongside cobertura so SonarCloud
  imports coverage (check-coverage.mjs still reads cobertura only).
- .sonarqube/ added to .gitignore (scanner working directory).
github.event.pullrequest.number does not exist (the pull_request payload
key uses an underscore); the empty value made the scanner reject
sonar.pullrequest.key and abort the analysis.
@sonarqubecloud

sonarqubecloud Bot commented Oct 1, 2026

Copy link
Copy Markdown

@santidev21
santidev21 merged commit aaa5698 into main Oct 1, 2026
10 checks passed
@santidev21
santidev21 deleted the chore/sonarcloud branch October 1, 2026 02:49
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant