From 993beab80d1dcf956a70dcf0e91f31838c9b9488 Mon Sep 17 00:00:00 2001 From: Jeppe B <2jepp9350@gmail.com> Date: Thu, 16 Jul 2026 13:33:00 +0200 Subject: [PATCH] Configure advisory Qodana analysis --- .github/workflows/code_quality.yml | 91 +++++++++++++++--------------- qodana.yaml | 56 ++++++------------ 2 files changed, 62 insertions(+), 85 deletions(-) diff --git a/.github/workflows/code_quality.yml b/.github/workflows/code_quality.yml index 3ec1fc1e..fdb66584 100644 --- a/.github/workflows/code_quality.yml +++ b/.github/workflows/code_quality.yml @@ -1,65 +1,66 @@ -name: Qodana Configuration Upload +name: Qodana on: - push: - branches: [master, beta, canary, internal] + workflow_dispatch: pull_request: branches: [master, beta, canary, internal] - workflow_dispatch: + types: [opened, synchronize, reopened, ready_for_review] + push: + branches: [master, beta, canary, internal] permissions: contents: read + checks: write + pull-requests: write + +concurrency: + group: qodana-${{ github.event_name == 'pull_request' && format('pr-{0}', github.event.pull_request.number) || github.ref }} + cancel-in-progress: true jobs: - upload-qodana-config: - runs-on: [self-hosted, Linux, X64, default] - timeout-minutes: 10 + qodana: + name: Qodana + if: >- + github.event_name != 'pull_request' || + ( + github.event.pull_request.draft == false && + github.event.pull_request.head.repo.full_name == github.repository && + github.event.pull_request.user.login != 'dependabot[bot]' + ) + runs-on: ubuntu-24.04 + timeout-minutes: 60 steps: - name: Checkout repository - uses: actions/checkout@v5 + # v5.0.1 + uses: actions/checkout@93cb6efe18208431cddfb8368fd83d5badbf9bfd + with: + ref: ${{ github.event_name == 'pull_request' && github.event.pull_request.head.sha || github.sha }} + fetch-depth: 0 + persist-credentials: false - - name: Detect Qodana upload prerequisites - id: qodana-upload-prerequisites + - name: Require Qodana project token shell: bash env: - QODANA_CONFIGURATIONS_TOKEN: ${{ secrets.QODANA_CONFIGURATIONS_TOKEN }} + QODANA_TOKEN: ${{ secrets.QODANA_TOKEN }} run: | set -euo pipefail - config_present=false - token_present=false - [[ -f qodana-global-configurations.yaml ]] && config_present=true - [[ -n "${QODANA_CONFIGURATIONS_TOKEN:-}" ]] && token_present=true - - if [[ "$config_present" == true && "$token_present" == true ]]; then - echo "ready=true" >> "$GITHUB_OUTPUT" - echo "reason=all prerequisites are configured" >> "$GITHUB_OUTPUT" - elif [[ "$config_present" != true && "$token_present" != true ]]; then - echo "ready=false" >> "$GITHUB_OUTPUT" - echo "reason=qodana-global-configurations.yaml and QODANA_CONFIGURATIONS_TOKEN are missing" >> "$GITHUB_OUTPUT" - elif [[ "$config_present" != true ]]; then - echo "ready=false" >> "$GITHUB_OUTPUT" - echo "reason=qodana-global-configurations.yaml is missing" >> "$GITHUB_OUTPUT" - else - echo "ready=false" >> "$GITHUB_OUTPUT" - echo "reason=QODANA_CONFIGURATIONS_TOKEN is missing" >> "$GITHUB_OUTPUT" + if [[ -z "${QODANA_TOKEN:-}" ]]; then + echo "::error::QODANA_TOKEN is not configured for this repository." + exit 1 fi - - name: Run Qodana Configuration Uploader - if: ${{ steps.qodana-upload-prerequisites.outputs.ready == 'true' }} + - name: Qodana + # v2026.1.3 + uses: JetBrains/qodana-action@4861e015da555e86a72b862892aba6c2b93e6891 + with: + use-caches: true + cache-default-branch-only: true + upload-result: false + use-annotations: true + pr-mode: ${{ github.event_name == 'pull_request' }} + post-pr-comment: true + github-token: ${{ github.token }} + push-fixes: none env: - QODANA_CONFIGURATIONS_TOKEN: ${{ secrets.QODANA_CONFIGURATIONS_TOKEN }} - run: | - docker run --rm \ - -v "$(pwd):/workspace" \ - -w /workspace \ - -e QODANA_CONFIGURATIONS_TOKEN \ - jetbrains/qodana-configuration-uploader@sha256:f4786ceea616048c3401cf0b0345d2220d22a2ec7b046fd48cbbfc522e6efe30 \ - --global-configs-file qodana-global-configurations.yaml \ - --qodana-host https://qodana.cloud - - - name: Skip Qodana Configuration Upload - if: ${{ steps.qodana-upload-prerequisites.outputs.ready != 'true' }} - env: - QODANA_SKIP_REASON: ${{ steps.qodana-upload-prerequisites.outputs.reason }} - run: echo "Skipping Qodana configuration upload because ${QODANA_SKIP_REASON}." + QODANA_TOKEN: ${{ secrets.QODANA_TOKEN }} diff --git a/qodana.yaml b/qodana.yaml index 722ccd51..7f534e82 100644 --- a/qodana.yaml +++ b/qodana.yaml @@ -1,46 +1,22 @@ -#-------------------------------------------------------------------------------# -# Qodana analysis is configured by qodana.yaml file # -# https://www.jetbrains.com/help/qodana/qodana-yaml.html # -#-------------------------------------------------------------------------------# - -################################################################################# -# WARNING: Do not store sensitive information in this file, # -# as its contents will be included in the Qodana report. # -################################################################################# version: "1.0" +linter: jetbrains/qodana-js:2026.1 -#Specify inspection profile for code analysis profile: - name: qodana.starter + name: qodana.recommended -#Enable inspections -#include: -# - name: +bootstrap: npm ci --legacy-peer-deps -#Disable inspections -#exclude: -# - name: -# paths: -# - +include: + - name: Eslint -#Execute shell command before Qodana execution (Applied in CI/CD pipeline) -#bootstrap: sh ./prepare-qodana.sh - -#Install IDE plugins before Qodana execution (Applied in CI/CD pipeline) -#plugins: -# - id: #(plugin id can be found at https://plugins.jetbrains.com) - -# Quality gate. Will fail the CI/CD pipeline if any condition is not met -# severityThresholds - configures maximum thresholds for different problem severities -# testCoverageThresholds - configures minimum code coverage on a whole project and newly added code -# Code Coverage is available in Ultimate and Ultimate Plus plans -#failureConditions: -# severityThresholds: -# any: 15 -# critical: 5 -# testCoverageThresholds: -# fresh: 70 -# total: 50 - -#Specify Qodana linter for analysis (Applied in CI/CD pipeline) -linter: jetbrains/qodana-js:2025.3 +exclude: + - name: All + paths: + - src/i18n/generated + - node_modules.codex-backup + - output + - .gradle + - playwright/.cache + - android + - ios + - app