Configure advisory Qodana analysis (#173)

This commit is contained in:
Jeppe B
2026-07-16 14:21:02 +02:00
committed by GitHub
parent 18302723e8
commit 39cc3a780a
2 changed files with 62 additions and 85 deletions
+46 -45
View File
@@ -1,65 +1,66 @@
name: Qodana Configuration Upload
name: Qodana
on:
push:
branches: [master, beta, canary, internal]
workflow_dispatch:
pull_request:
branches: [master, beta, canary, internal]
workflow_dispatch:
types: [opened, synchronize, reopened, ready_for_review]
push:
branches: [master, beta, canary, internal]
permissions:
contents: read
checks: write
pull-requests: write
concurrency:
group: qodana-${{ github.event_name == 'pull_request' && format('pr-{0}', github.event.pull_request.number) || github.ref }}
cancel-in-progress: true
jobs:
upload-qodana-config:
runs-on: [self-hosted, Linux, X64, default]
timeout-minutes: 10
qodana:
name: Qodana
if: >-
github.event_name != 'pull_request' ||
(
github.event.pull_request.draft == false &&
github.event.pull_request.head.repo.full_name == github.repository &&
github.event.pull_request.user.login != 'dependabot[bot]'
)
runs-on: ubuntu-24.04
timeout-minutes: 60
steps:
- name: Checkout repository
uses: actions/checkout@v5
# v5.0.1
uses: actions/checkout@93cb6efe18208431cddfb8368fd83d5badbf9bfd
with:
ref: ${{ github.event_name == 'pull_request' && github.event.pull_request.head.sha || github.sha }}
fetch-depth: 0
persist-credentials: false
- name: Detect Qodana upload prerequisites
id: qodana-upload-prerequisites
- name: Require Qodana project token
shell: bash
env:
QODANA_CONFIGURATIONS_TOKEN: ${{ secrets.QODANA_CONFIGURATIONS_TOKEN }}
QODANA_TOKEN: ${{ secrets.QODANA_TOKEN }}
run: |
set -euo pipefail
config_present=false
token_present=false
[[ -f qodana-global-configurations.yaml ]] && config_present=true
[[ -n "${QODANA_CONFIGURATIONS_TOKEN:-}" ]] && token_present=true
if [[ "$config_present" == true && "$token_present" == true ]]; then
echo "ready=true" >> "$GITHUB_OUTPUT"
echo "reason=all prerequisites are configured" >> "$GITHUB_OUTPUT"
elif [[ "$config_present" != true && "$token_present" != true ]]; then
echo "ready=false" >> "$GITHUB_OUTPUT"
echo "reason=qodana-global-configurations.yaml and QODANA_CONFIGURATIONS_TOKEN are missing" >> "$GITHUB_OUTPUT"
elif [[ "$config_present" != true ]]; then
echo "ready=false" >> "$GITHUB_OUTPUT"
echo "reason=qodana-global-configurations.yaml is missing" >> "$GITHUB_OUTPUT"
else
echo "ready=false" >> "$GITHUB_OUTPUT"
echo "reason=QODANA_CONFIGURATIONS_TOKEN is missing" >> "$GITHUB_OUTPUT"
if [[ -z "${QODANA_TOKEN:-}" ]]; then
echo "::error::QODANA_TOKEN is not configured for this repository."
exit 1
fi
- name: Run Qodana Configuration Uploader
if: ${{ steps.qodana-upload-prerequisites.outputs.ready == 'true' }}
- name: Qodana
# v2026.1.3
uses: JetBrains/qodana-action@4861e015da555e86a72b862892aba6c2b93e6891
with:
use-caches: true
cache-default-branch-only: true
upload-result: false
use-annotations: true
pr-mode: ${{ github.event_name == 'pull_request' }}
post-pr-comment: true
github-token: ${{ github.token }}
push-fixes: none
env:
QODANA_CONFIGURATIONS_TOKEN: ${{ secrets.QODANA_CONFIGURATIONS_TOKEN }}
run: |
docker run --rm \
-v "$(pwd):/workspace" \
-w /workspace \
-e QODANA_CONFIGURATIONS_TOKEN \
jetbrains/qodana-configuration-uploader@sha256:f4786ceea616048c3401cf0b0345d2220d22a2ec7b046fd48cbbfc522e6efe30 \
--global-configs-file qodana-global-configurations.yaml \
--qodana-host https://qodana.cloud
- name: Skip Qodana Configuration Upload
if: ${{ steps.qodana-upload-prerequisites.outputs.ready != 'true' }}
env:
QODANA_SKIP_REASON: ${{ steps.qodana-upload-prerequisites.outputs.reason }}
run: echo "Skipping Qodana configuration upload because ${QODANA_SKIP_REASON}."
QODANA_TOKEN: ${{ secrets.QODANA_TOKEN }}