commit 388210fd6e209514d1d932ed526b262ed899e9cd Author: Jacek Date: Fri May 14 09:04:32 2021 +0200 SONAR-14825 Provide Quality Gate check GitHub Action diff --git a/.github/workflows/run-unit-tests.yml b/.github/workflows/run-unit-tests.yml new file mode 100644 index 0000000..3780d4e --- /dev/null +++ b/.github/workflows/run-unit-tests.yml @@ -0,0 +1,28 @@ +name: Execute tests +on: + push: + branches: + - master + pull_request: + types: [opened, synchronize, reopened] +jobs: + run-unit-tests: + runs-on: ubuntu-latest + steps: + - name: checkout action + uses: actions/checkout@v2 + with: + path: main + fetch-depth: 0 + - name: checkout bats-core + uses: actions/checkout@v2 + with: + path: bats-core + repository: bats-core/bats-core + fetch-depth: 0 + - name: Install BATS test framework + run: + sudo ./bats-core/install.sh /usr/local + - name: Execute BATS tests + run: + cd main && bats test/check-quality-gate-test.bats diff --git a/.gitignore b/.gitignore new file mode 100644 index 0000000..ed2304e --- /dev/null +++ b/.gitignore @@ -0,0 +1,3 @@ +.idea +.DS_Store + diff --git a/LICENSE.txt b/LICENSE.txt new file mode 100644 index 0000000..65c5ca8 --- /dev/null +++ b/LICENSE.txt @@ -0,0 +1,165 @@ + GNU LESSER GENERAL PUBLIC LICENSE + Version 3, 29 June 2007 + + Copyright (C) 2007 Free Software Foundation, Inc. + Everyone is permitted to copy and distribute verbatim copies + of this license document, but changing it is not allowed. + + + This version of the GNU Lesser General Public License incorporates +the terms and conditions of version 3 of the GNU General Public +License, supplemented by the additional permissions listed below. + + 0. Additional Definitions. + + As used herein, "this License" refers to version 3 of the GNU Lesser +General Public License, and the "GNU GPL" refers to version 3 of the GNU +General Public License. + + "The Library" refers to a covered work governed by this License, +other than an Application or a Combined Work as defined below. + + An "Application" is any work that makes use of an interface provided +by the Library, but which is not otherwise based on the Library. +Defining a subclass of a class defined by the Library is deemed a mode +of using an interface provided by the Library. + + A "Combined Work" is a work produced by combining or linking an +Application with the Library. The particular version of the Library +with which the Combined Work was made is also called the "Linked +Version". + + The "Minimal Corresponding Source" for a Combined Work means the +Corresponding Source for the Combined Work, excluding any source code +for portions of the Combined Work that, considered in isolation, are +based on the Application, and not on the Linked Version. + + The "Corresponding Application Code" for a Combined Work means the +object code and/or source code for the Application, including any data +and utility programs needed for reproducing the Combined Work from the +Application, but excluding the System Libraries of the Combined Work. + + 1. Exception to Section 3 of the GNU GPL. + + You may convey a covered work under sections 3 and 4 of this License +without being bound by section 3 of the GNU GPL. + + 2. Conveying Modified Versions. + + If you modify a copy of the Library, and, in your modifications, a +facility refers to a function or data to be supplied by an Application +that uses the facility (other than as an argument passed when the +facility is invoked), then you may convey a copy of the modified +version: + + a) under this License, provided that you make a good faith effort to + ensure that, in the event an Application does not supply the + function or data, the facility still operates, and performs + whatever part of its purpose remains meaningful, or + + b) under the GNU GPL, with none of the additional permissions of + this License applicable to that copy. + + 3. Object Code Incorporating Material from Library Header Files. + + The object code form of an Application may incorporate material from +a header file that is part of the Library. You may convey such object +code under terms of your choice, provided that, if the incorporated +material is not limited to numerical parameters, data structure +layouts and accessors, or small macros, inline functions and templates +(ten or fewer lines in length), you do both of the following: + + a) Give prominent notice with each copy of the object code that the + Library is used in it and that the Library and its use are + covered by this License. + + b) Accompany the object code with a copy of the GNU GPL and this license + document. + + 4. Combined Works. + + You may convey a Combined Work under terms of your choice that, +taken together, effectively do not restrict modification of the +portions of the Library contained in the Combined Work and reverse +engineering for debugging such modifications, if you also do each of +the following: + + a) Give prominent notice with each copy of the Combined Work that + the Library is used in it and that the Library and its use are + covered by this License. + + b) Accompany the Combined Work with a copy of the GNU GPL and this license + document. + + c) For a Combined Work that displays copyright notices during + execution, include the copyright notice for the Library among + these notices, as well as a reference directing the user to the + copies of the GNU GPL and this license document. + + d) Do one of the following: + + 0) Convey the Minimal Corresponding Source under the terms of this + License, and the Corresponding Application Code in a form + suitable for, and under terms that permit, the user to + recombine or relink the Application with a modified version of + the Linked Version to produce a modified Combined Work, in the + manner specified by section 6 of the GNU GPL for conveying + Corresponding Source. + + 1) Use a suitable shared library mechanism for linking with the + Library. A suitable mechanism is one that (a) uses at run time + a copy of the Library already present on the user's computer + system, and (b) will operate properly with a modified version + of the Library that is interface-compatible with the Linked + Version. + + e) Provide Installation Information, but only if you would otherwise + be required to provide such information under section 6 of the + GNU GPL, and only to the extent that such information is + necessary to install and execute a modified version of the + Combined Work produced by recombining or relinking the + Application with a modified version of the Linked Version. (If + you use option 4d0, the Installation Information must accompany + the Minimal Corresponding Source and Corresponding Application + Code. If you use option 4d1, you must provide the Installation + Information in the manner specified by section 6 of the GNU GPL + for conveying Corresponding Source.) + + 5. Combined Libraries. + + You may place library facilities that are a work based on the +Library side by side in a single library together with other library +facilities that are not Applications and are not covered by this +License, and convey such a combined library under terms of your +choice, if you do both of the following: + + a) Accompany the combined library with a copy of the same work based + on the Library, uncombined with any other library facilities, + conveyed under the terms of this License. + + b) Give prominent notice with the combined library that part of it + is a work based on the Library, and explaining where to find the + accompanying uncombined form of the same work. + + 6. Revised Versions of the GNU Lesser General Public License. + + The Free Software Foundation may publish revised and/or new versions +of the GNU Lesser General Public License from time to time. Such new +versions will be similar in spirit to the present version, but may +differ in detail to address new problems or concerns. + + Each version is given a distinguishing version number. If the +Library as you received it specifies that a certain numbered version +of the GNU Lesser General Public License "or any later version" +applies to it, you have the option of following the terms and +conditions either of that published version or of any later version +published by the Free Software Foundation. If the Library as you +received it does not specify a version number of the GNU Lesser +General Public License, you may choose any version of the GNU Lesser +General Public License ever published by the Free Software Foundation. + + If the Library as you received it specifies that a proxy can decide +whether future versions of the GNU Lesser General Public License shall +apply, that proxy's public statement of acceptance of any version is +permanent authorization for you to choose that version for the +Library. diff --git a/README.md b/README.md new file mode 100644 index 0000000..4e8458b --- /dev/null +++ b/README.md @@ -0,0 +1,75 @@ +# SonarQube Quality Gate check + +Check the Quality Gate of your code with [SonarQube](https://www.sonarqube.org/) to ensure your code meets your own quality standards before you release or deploy new features. + + + +SonarQube is the leading product for Continuous Code Quality & Code Security. It supports most popular programming languages, including Java, JavaScript, TypeScript, C#, Python, C, C++, and many more. + +## Requirements + +Repository with SonarQube analysis results. + +## Usage + +The workflow, usually declared in `.github/workflows/build.yml`, should look like this: + +```yaml +on: + # Trigger analysis when pushing in master or pull requests, and when creating + # a pull request. + push: + branches: + - master + pull_request: + types: [opened, synchronize, reopened] +name: Main Workflow +jobs: + sonarqube: + runs-on: ubuntu-latest + steps: + - uses: actions/checkout@v2 + with: + # Disabling shallow clone is recommended for improving relevancy of reporting + fetch-depth: 0 + #Triggering SonarQube analysis as results of it is required by Quality Gate check + - name: SonarQube Scan + uses: sonarsource/sonarqube-scan-action@master + env: + SONAR_TOKEN: ${{ secrets.SONAR_TOKEN }} + SONAR_HOST_URL: ${{ secrets.SONAR_HOST_URL }} + - name: SonarQube Quality Gate check + uses: sonarsource/sonarqube-quality-gate-action@master + # Force to fail step after specific time + timeout-minutes: 5 + env: + SONAR_TOKEN: ${{ secrets.SONAR_TOKEN }} + +``` + +You can change the location of the report metadata file by using the optional `scanMetadataReportFile` input: + +```yaml +uses: sonarsource/sonarqube-quality-gate-action@master +with: + scanMetadataReportFile: target/sonar/report-task.txt +``` + +### Environment variables + +- `SONAR_TOKEN` – **Required** – this token is used to authenticate access to SonarQube. You can read more about security tokens [here](https://docs.sonarqube.org/latest/user-guide/user-token/). You need to set the `SONAR_TOKEN` environment variable in the "Secrets" settings page of your repository. + +## Do not use this GitHub action if you are in the following situations + +* You want to analyze a .NET solution. Read the documentation about our [Scanner for .NET](https://docs.sonarqube.org/latest/analysis/scan/sonarscanner-for-msbuild/). +* You want to analyze C/C++ code. Read the documentation on [analyzing C/C++ code](https://docs.sonarqube.org/latest/analysis/languages/cfamily/). + +## Have questions or feedback? + +To provide feedback (request a feature or report a bug), please post on the [SonarSource Community Forum](https://community.sonarsource.com/) with the tag `sonarqube`. + +## License + +Scripts and documentation in this project are released under the LGPLv3 License. + +Container images built with this project include third-party materials. diff --git a/action.yml b/action.yml new file mode 100644 index 0000000..7f53109 --- /dev/null +++ b/action.yml @@ -0,0 +1,16 @@ +name: SonarQube Quality Gate Check +description: > + Check if a project / analysis passed the Quality Gate check +branding: + icon: check + color: green +runs: + using: "composite" + steps: + - run: $GITHUB_ACTION_PATH/script/check-quality-gate.sh ${{ inputs.scanMetadataReportFile }} + shell: bash +inputs: + scanMetadataReportFile: + description: Location of the scanner metadata report file + required: false + default: .scannerwork/report-task.txt diff --git a/images/SonarQube-72px.png b/images/SonarQube-72px.png new file mode 100644 index 0000000..ab7712b Binary files /dev/null and b/images/SonarQube-72px.png differ diff --git a/script/check-quality-gate.sh b/script/check-quality-gate.sh new file mode 100755 index 0000000..2b3108f --- /dev/null +++ b/script/check-quality-gate.sh @@ -0,0 +1,48 @@ +#!/usr/bin/env bash + +source "$(dirname "$0")/common.sh" + +if [[ -z "${SONAR_TOKEN}" ]]; then + echo "Set the SONAR_TOKEN env variable." + exit 1 +fi + +metadataFile="$1" + +if [[ ! -f "$metadataFile" ]]; then + echo "$metadataFile does not exist." + exit 1 +fi + +serverUrl="$(sed -n 's/serverUrl=\(.*\)/\1/p' ${metadataFile})" +ceTaskUrl="$(sed -n 's/ceTaskUrl=\(.*\)/\1/p' ${metadataFile})" + +if [ -z "${serverUrl}" ] || [ -z "${ceTaskUrl}" ]; then + echo "Invalid report metadata file." + exit 1 +fi + +task="$(curl --silent --fail --show-error --user ${SONAR_TOKEN}: ${ceTaskUrl})" +status="$(jq -r '.task.status' <<< "$task")" + +until [[ ${status} != "PENDING" && ${status} != "IN_PROGRESS" ]]; do + printf '.' + sleep 5s + task="$(curl --silent --fail --show-error --user ${SONAR_TOKEN}: ${ceTaskUrl})" + status="$(jq -r '.task.status' <<< "$task")" +done + +analysisId="$(jq -r '.task.analysisId' <<< "${task}")" +qualityGateUrl="${serverUrl}/api/qualitygates/project_status?analysisId=${analysisId}" +qualityGateStatus="$(curl --silent --fail --show-error --user ${SONAR_TOKEN}: ${qualityGateUrl} | jq -r '.projectStatus.status')" + +if [[ ${qualityGateStatus} == "OK" ]];then + success "Quality Gate has PASSED." +elif [[ ${qualityGateStatus} == "WARN" ]];then + warn "Warnings on Quality Gate." +elif [[ ${qualityGateStatus} == "ERROR" ]];then + fail "Quality Gate has FAILED." +else + fail "Quality Gate not set for the project. Please configure the Quality Gate in SonarQube or remove sonarqube-quality-gate action from the workflow." +fi + diff --git a/script/common.sh b/script/common.sh new file mode 100755 index 0000000..a347869 --- /dev/null +++ b/script/common.sh @@ -0,0 +1,49 @@ +#!/usr/bin/env bash + +# Begin Standard 'imports' +set -e +set -o pipefail + +gray="\\e[37m" +blue="\\e[36m" +red="\\e[31m" +yellow="\\e[33m" +green="\\e[32m" +reset="\\e[0m" + +info() { echo -e "${blue}INFO: $*${reset}"; } +error() { echo -e "${red}ERROR: $*${reset}"; } +debug() { + if [[ "${DEBUG}" == "true" ]]; then + echo -e "${gray}DEBUG: $*${reset}"; + fi +} + +success() { echo -e "${green}✔ $*${reset}"; } +warn() { echo -e "${yellow}✖ $*${reset}"; exit 1; } +fail() { echo -e "${red}✖ $*${reset}"; exit 1; } + +## Enable debug mode. +enable_debug() { + if [[ "${DEBUG}" == "true" ]]; then + info "Enabling debug mode." + set -x + fi +} + +# Execute a command, saving its output and exit status code, and echoing its output upon completion. +# Globals set: +# status: Exit status of the command that was executed. +# output: Output generated from the command. +# +run() { + echo "$@" + set +e + output=$("$@" 2>&1) + status=$? + set -e + echo "${output}" +} + +# End standard 'imports' + diff --git a/test/check-quality-gate-test.bats b/test/check-quality-gate-test.bats new file mode 100755 index 0000000..f4c5303 --- /dev/null +++ b/test/check-quality-gate-test.bats @@ -0,0 +1,112 @@ +#!/usr/bin/env bats + +setup() { + DIR="$( cd "$( dirname "$BATS_TEST_FILENAME" )" >/dev/null 2>&1 && pwd )" + PATH="$DIR/../src:$PATH" + touch metadata_tmp +} + +teardown() { + rm -f metadata_tmp +} + +@test "fail when SONAR_TOKEN not provided" { + run script/check-quality-gate.sh + [ "$status" -eq 1 ] + [ "$output" = "Set the SONAR_TOKEN env variable." ] +} + +@test "fail when metadata file not exist" { + rm -f metadata_tmp + export SONAR_TOKEN="test" + run script/check-quality-gate.sh + [ "$status" -eq 1 ] + [ "$output" = " does not exist." ] +} + +@test "fail when empty metadata file" { + export SONAR_TOKEN="test" + run script/check-quality-gate.sh metadata_tmp + [ "$status" -eq 1 ] + [ "$output" = "Invalid report metadata file." ] +} + +@test "fail when no Quality Gate status" { + export SONAR_TOKEN="test" + echo "serverUrl=http://localhost:9000" >> metadata_tmp + echo "ceTaskUrl=http://localhost:9000/api/ce/task?id=AXlCe3gsFwOUsY8YKHTn" >> metadata_tmp + + #mock curl + function curl() { + echo '{"task":{"analysisId":"AXlCe3jz9LkwR9Gs0pBY","status":"SUCCESS"}}' + } + export -f curl + + run script/check-quality-gate.sh metadata_tmp + [ "$status" -eq 1 ] + [[ "$output" = *"Quality Gate not set for the project. Please configure the Quality Gate in SonarQube or remove sonarqube-quality-gate action from the workflow."* ]] +} + +@test "fail when Quality Gate status WARN" { + export SONAR_TOKEN="test" + echo "serverUrl=http://localhost:9000" >> metadata_tmp + echo "ceTaskUrl=http://localhost:9000/api/ce/task?id=AXlCe3gsFwOUsY8YKHTn" >> metadata_tmp + + #mock curl + function curl() { + url="${@: -1}" + if [[ $url == *"/api/qualitygates/project_status?analysisId"* ]]; then + echo '{"projectStatus":{"status":"WARN"}}' + else + echo '{"task":{"analysisId":"AXlCe3jz9LkwR9Gs0pBY","status":"SUCCESS"}}' + fi + } + export -f curl + + run script/check-quality-gate.sh metadata_tmp + [ "$status" -eq 1 ] + [[ "$output" = *"Warnings on Quality Gate."* ]] +} + +@test "fail when Quality Gate status ERROR" { + export SONAR_TOKEN="test" + echo "serverUrl=http://localhost:9000" >> metadata_tmp + echo "ceTaskUrl=http://localhost:9000/api/ce/task?id=AXlCe3gsFwOUsY8YKHTn" >> metadata_tmp + + #mock curl + function curl() { + url="${@: -1}" + if [[ $url == *"/api/qualitygates/project_status?analysisId"* ]]; then + echo '{"projectStatus":{"status":"ERROR"}}' + else + echo '{"task":{"analysisId":"AXlCe3jz9LkwR9Gs0pBY","status":"SUCCESS"}}' + fi + } + export -f curl + + run script/check-quality-gate.sh metadata_tmp + [ "$status" -eq 1 ] + [[ "$output" = *"Quality Gate has FAILED."* ]] +} + +@test "pass when Quality Gate status OK" { + export SONAR_TOKEN="test" + echo "serverUrl=http://localhost:9000" >> metadata_tmp + echo "ceTaskUrl=http://localhost:9000/api/ce/task?id=AXlCe3gsFwOUsY8YKHTn" >> metadata_tmp + + #mock curl + function curl() { + url="${@: -1}" + if [[ $url == *"/api/qualitygates/project_status?analysisId"* ]]; then + echo '{"projectStatus":{"status":"OK"}}' + else + echo '{"task":{"analysisId":"AXlCe3jz9LkwR9Gs0pBY","status":"SUCCESS"}}' + fi + } + export -f curl + + run script/check-quality-gate.sh metadata_tmp + [ "$status" -eq 0 ] + [[ "$output" = *"Quality Gate has PASSED."* ]] +} +