Commit Graph
168 Commits
Author SHA1 Message Date
Alban Auzeill e0c4e7abeb uses winget instead of Chocolatey 2026-08-03 12:15:40 +02:00
Alban Auzeill 280d6fc5b8 Try --install-arguments "/S" 2026-08-03 12:05:14 +02:00
Alban Auzeill 154f7918a7 Try --params "/S" 2026-08-03 12:03:28 +02:00
Alban Auzeill 2448e3394c Retry to install gnupg 3 times 2026-08-03 11:33:19 +02:00
Alban Auzeill 62d06e46aa Try github-windows-latest-s 2026-08-03 11:26:48 +02:00
Alban Auzeill f8132da3be Use powershell 2026-08-03 11:22:56 +02:00
Alban Auzeill f9b74a459a Try another runner 2026-08-03 11:14:25 +02:00
Alban Auzeill bf5bc7ceac Revert "Harden reproducer: install native GnuPG via multiple strategies"
This reverts commit 8b19b74547.
2026-08-03 11:13:53 +02:00
Alban AuzeillandClaude Opus 4.8 8b19b74547 Harden reproducer: install native GnuPG via multiple strategies
The choco community feed can return transient 503s (as it did on the first
run), which left gpg.exe missing and failed the step. Install Gpg4win via a
feed-independent direct download first, then winget, then choco with retries;
succeed if any strategy yields gpg.exe.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
2026-08-03 11:03:28 +02:00
Alban AuzeillandClaude Opus 4.8 78aa5797b9 Investigate Windows GPG path bug (#186785) + CI reproducer
convertToUnixPath() rewrites drive letters to MSYS form (R:\ -> /r/),
which native GnuPG (Gpg4win) cannot resolve. Add investigation.md and a
windows-latest reproducer workflow that installs native GnuPG and expects
the action to fail at GPG signature verification.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
2026-08-03 10:44:46 +02:00
dependabot[bot] ad8210318a SQSCANGHA-158 NO-JIRA Bump actions/checkout from 7.0.0 to 7.0.1 (#260)
Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-07-22 15:37:07 +02:00
dependabot[bot] 7451daf950 SQSCANGHA-157 NO-JIRA Bump actions/setup-node from 6.4.0 to 7.0.0 (#259) 2026-07-20 17:50:30 +02:00
Alban Auzeill 22918119ff SQSCANGHA-156 GPG signature verification fails when temporary directory path is too long (#258) v8.2.1 2026-07-13 17:36:59 +02:00
dependabot[bot] 7cdc154593 SQSCANGHA-153 NO-JIRA Bump actions/checkout from 6.0.2 to 7.0.0 (#255)
Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-07-06 11:52:45 +02:00
Antoine Vinot 45f27363d4 SQSCANGHA-151 Change Code Owners (#254) 2026-06-16 09:15:26 +02:00
Julien HENRYandClaude Sonnet 4.6 713881670b SQSCANGHA-127 Rename downloaded file to .zip before extraction on Windows (#251)
Co-authored-by: Claude Sonnet 4.6 <noreply@anthropic.com>
v8.2.0
2026-06-08 14:51:37 +02:00
Julien HENRYandClaude Sonnet 4.6 3581139216 SQSCANGHA-135 Fix scanner binaries always re-downloaded due to incompatible 4-part version (#250)
Co-authored-by: Claude Sonnet 4.6 <noreply@anthropic.com>
2026-06-08 10:53:34 +02:00
Julien HENRYandClaude Sonnet 4.6 c9d327c024 SQSCANGHA-84 Remove outdated wget/curl references
The action was refactored to use Node.js (@actions/tool-cache) for
downloads, which doesn't rely on wget or curl. Update the README and
QA workflow to reflect this.

Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
2026-06-04 17:25:27 +02:00
Julien HENRYandClaude Sonnet 4.6 b243e5198f SQSCANGHA-88 Deprecate the SONARCLOUD_URL env variable support
Emit a warning when SONARCLOUD_URL is set, directing users to either
pass nothing, use SONAR_REGION=us for the US region, or pass
-Dsonar.scanner.sonarcloudUrl and -Dsonar.scanner.apiBaseUrl via args
for advanced needs. Backward compatibility is preserved.

Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
2026-06-04 16:34:28 +02:00
Julien HENRYandClaude Sonnet 4.6 375c3f5c03 SQSCANGHA-149 Add scannerBinariesAuthHeader input for authenticated binary downloads
Organisations using private Artifactory mirrors require authentication to
download the SonarScanner CLI. This adds an optional scannerBinariesAuthHeader
input whose value is forwarded as the Authorization HTTP header to both the
binary and GPG signature downloads via tc.downloadTool's built-in auth
parameter. No new dependencies are introduced.

Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
2026-06-04 14:19:55 +02:00
Julien HENRYandClaude Sonnet 4.6 9c783232fe SQSCANGHA-144 Add gate jobs to QA workflows for branch protection
Add a non-matrix gate job to qa-main, qa-deprecated-c-cpp, and
qa-install-build-wrapper workflows. Each gate job depends on all
other jobs in its workflow and provides a single stable check context
that can be used in GitHub branch protection required status checks.

Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
2026-06-04 09:32:35 +02:00
SonarTech 7006c4492b Update SonarScanner CLI to 8.1.0.6389 v8.1 v8.1.0 2026-05-19 09:24:23 +02:00
dependabot[bot] edd319f284 NO-JIRA Bump actions/setup-node from 6.3.0 to 6.4.0 (#234)
Signed-off-by: dependabot[bot] <support@github.com>
2026-05-19 09:23:47 +02:00
dependabot[bot] e050aa9e69 NO-JIRA Bump actions/cache from 5.0.4 to 5.0.5 (#231)
Signed-off-by: dependabot[bot] <support@github.com>
2026-05-19 09:23:25 +02:00
dependabot[bot] 6cd3d8f2ae NO-JIRA Bump madhead/semver-utils from 4.3.0 to 5.0.0
Bumps [madhead/semver-utils](https://github.com/madhead/semver-utils) from 4.3.0 to 5.0.0.
- [Release notes](https://github.com/madhead/semver-utils/releases)
- [Commits](https://github.com/madhead/semver-utils/compare/36d1e0ed361bd7b4b77665de8093092eaeabe6ba...4cf918affe9106ea59f86c6250e5ec4570ac4389)

---
updated-dependencies:
- dependency-name: madhead/semver-utils
  dependency-version: 5.0.0
  dependency-type: direct:production
  update-type: version-update:semver-major
...

Signed-off-by: dependabot[bot] <support@github.com>
2026-05-19 09:20:24 +02:00
56568530ed SQSCANGHA-146 Add proxy support for GPG keyserver access (#244)
Co-authored-by: Marius Boden <marius.boden@xebia.com>
Co-authored-by: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
2026-05-19 09:11:36 +02:00
Claire Villard c444753899 SQSCANGHA-140 Add the missing requirements in README.md (#243) 2026-05-11 12:13:30 +02:00
Antoine Vinot 59db25f34e SQSCANGHA-145 Set skipSignatureVerification default value to false (#241) v8.0 v8.0.0 2026-04-29 14:23:12 +02:00
Pavel Mikula ca30b65f4e SQSCANGHA-143 SubmitReview: Use Vault token (#238) 2026-04-29 11:16:25 +02:00
Antoine VinotandGustavo Cunha c7ee0f9df9 SQSCANGHA-140 Set skipSignatureVerification default value to true to avoid breaking change (#240)
Co-authored-by: Gustavo Cunha <dev@gustavocunha.dev>
v7 v7.2 v7.2.1
2026-04-29 10:13:05 +02:00
Claire Villard 55e44800a8 SQSCANGHA-140 Add OpenPGP signature verification for scanner downloads (#235) v7.2.0 2026-04-28 15:49:48 +02:00
Antoine VinotandJarek Potiuk 30dbe5c9ee SQSCANGHA-138 Update dist and add ci test (#233)
Co-authored-by: Jarek Potiuk <jarek@potiuk.com>
2026-04-23 14:20:12 +02:00
Claire VillardandJulien Carsique c8357220fa SQSCANGHA-134 Upgrade the libraries to latest version (#227)
Co-authored-by: Julien Carsique <julien.carsique@sonarsource.com>
2026-04-14 15:21:19 +02:00
Claire Villard f00de44f57 SC-45750 Migrate to dateless license headers (#229) 2026-04-10 13:57:27 +02:00
Claire Villard f099b44166 SQSCANGHA-133 Upgrade the Node version used in UTs + contribution guide (#226) 2026-04-03 10:34:00 +02:00
tomverin d899ed2996 BUILD-10861 Dependabot 5-day cooldown + internal excludes (#225) 2026-04-02 15:07:08 +02:00
Claire Villard 299e4b793a SQSCANGHA-132 Upgrade Node to 24 (#224) v7.1 v7.1.0 2026-04-01 11:14:54 +02:00
dependabot[bot] 3988e54db2 SQSCANGHA-131 Bump picomatch from 4.0.3 to 4.0.4 (#223)
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-03-31 08:58:59 +02:00
dependabot[bot] 9598b8a83f SQSCANGHA-130 Bump rollup from 4.50.1 to 4.59.0 (#221)
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-03-06 10:07:15 +01:00
dependabot[bot] dcc5211de5 SQSCANGHA-128 NO-JIRA Bump actions/cache from 4 to 5 (#219)
Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-02-16 20:53:44 +01:00
Claire VillardandClaude Sonnet 4.5 b9f37f9de0 SQSCANGHA-129 Fix the Analysis Processing team name in CODEOWNERS (#220)
Co-authored-by: Claude Sonnet 4.5 <noreply@anthropic.com>
2026-02-11 11:37:16 +01:00
github-actions[bot] a31c9398be SQSCANGHA-126 Update SonarScanner CLI to 8.0.1.6346 (#218) v7.0 v7.0.0 2025-12-09 09:53:51 +01:00
dependabot[bot] 40f5b61913 SQSCANGHA-123 NO-JIRA Bump actions/setup-node from 5 to 6 (#214) 2025-10-15 15:09:18 +02:00
Brandon Davis 9bf7c126a1 SQSCANGHA-122 Include caveats for running SCA (#213) 2025-10-09 06:21:35 -05:00
github-actions[bot] ba6563cca7 Update SonarScanner CLI to 7.3.0.5189 (#212) 2025-10-06 09:29:17 +02:00
dependabot[bot] 5ffbad4454 SQSCANGHA-120 Bump actions/setup-node from 4 to 5 (#211) 2025-09-22 07:47:48 +02:00
Joan Biel fd88b7d7cc SQSCANGHA-119 New Readme structure
Add quick start section

Increase visibility of special cases and alternatives

Prioritize SQC examples over SQS
v6 v6.0 v6.0.0
2025-09-18 10:38:53 +02:00
Julien HENRY 27a157d234 SQSCANGHA-118 Update the README to document the breaking change for args parsing 2025-09-18 10:38:53 +02:00
Jeremy Davis e327da8e78 NO-JIRA Add documentation for contribution 2025-09-18 10:38:53 +02:00
Jeremy Davis ff001fd600 SQSCANGHA-107 Migrate install-build-wrapper 2025-09-18 10:38:53 +02:00