Alban Auzeill
e0c4e7abeb
uses winget instead of Chocolatey
2026-08-03 12:15:40 +02:00
Alban Auzeill
280d6fc5b8
Try --install-arguments "/S"
2026-08-03 12:05:14 +02:00
Alban Auzeill
154f7918a7
Try --params "/S"
2026-08-03 12:03:28 +02:00
Alban Auzeill
2448e3394c
Retry to install gnupg 3 times
2026-08-03 11:33:19 +02:00
Alban Auzeill
62d06e46aa
Try github-windows-latest-s
2026-08-03 11:26:48 +02:00
Alban Auzeill
f8132da3be
Use powershell
2026-08-03 11:22:56 +02:00
Alban Auzeill
f9b74a459a
Try another runner
2026-08-03 11:14:25 +02:00
Alban Auzeill
bf5bc7ceac
Revert "Harden reproducer: install native GnuPG via multiple strategies"
...
This reverts commit 8b19b74547 .
2026-08-03 11:13:53 +02:00
Alban Auzeill and Claude Opus 4.8
8b19b74547
Harden reproducer: install native GnuPG via multiple strategies
...
The choco community feed can return transient 503s (as it did on the first
run), which left gpg.exe missing and failed the step. Install Gpg4win via a
feed-independent direct download first, then winget, then choco with retries;
succeed if any strategy yields gpg.exe.
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com >
2026-08-03 11:03:28 +02:00
Alban Auzeill and Claude Opus 4.8
78aa5797b9
Investigate Windows GPG path bug ( #186785 ) + CI reproducer
...
convertToUnixPath() rewrites drive letters to MSYS form (R:\ -> /r/),
which native GnuPG (Gpg4win) cannot resolve. Add investigation.md and a
windows-latest reproducer workflow that installs native GnuPG and expects
the action to fail at GPG signature verification.
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com >
2026-08-03 10:44:46 +02:00
dependabot[bot]
ad8210318a
SQSCANGHA-158 NO-JIRA Bump actions/checkout from 7.0.0 to 7.0.1 ( #260 )
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-07-22 15:37:07 +02:00
dependabot[bot]
7451daf950
SQSCANGHA-157 NO-JIRA Bump actions/setup-node from 6.4.0 to 7.0.0 ( #259 )
2026-07-20 17:50:30 +02:00
dependabot[bot]
7cdc154593
SQSCANGHA-153 NO-JIRA Bump actions/checkout from 6.0.2 to 7.0.0 ( #255 )
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-07-06 11:52:45 +02:00
Julien HENRY and Claude Sonnet 4.6
c9d327c024
SQSCANGHA-84 Remove outdated wget/curl references
...
The action was refactored to use Node.js (@actions/tool-cache) for
downloads, which doesn't rely on wget or curl. Update the README and
QA workflow to reflect this.
Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com >
2026-06-04 17:25:27 +02:00
Julien HENRY and Claude Sonnet 4.6
b243e5198f
SQSCANGHA-88 Deprecate the SONARCLOUD_URL env variable support
...
Emit a warning when SONARCLOUD_URL is set, directing users to either
pass nothing, use SONAR_REGION=us for the US region, or pass
-Dsonar.scanner.sonarcloudUrl and -Dsonar.scanner.apiBaseUrl via args
for advanced needs. Backward compatibility is preserved.
Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com >
2026-06-04 16:34:28 +02:00
Julien HENRY and Claude Sonnet 4.6
9c783232fe
SQSCANGHA-144 Add gate jobs to QA workflows for branch protection
...
Add a non-matrix gate job to qa-main, qa-deprecated-c-cpp, and
qa-install-build-wrapper workflows. Each gate job depends on all
other jobs in its workflow and provides a single stable check context
that can be used in GitHub branch protection required status checks.
Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com >
2026-06-04 09:32:35 +02:00
dependabot[bot]
edd319f284
NO-JIRA Bump actions/setup-node from 6.3.0 to 6.4.0 ( #234 )
...
Signed-off-by: dependabot[bot] <support@github.com >
2026-05-19 09:23:47 +02:00
dependabot[bot]
e050aa9e69
NO-JIRA Bump actions/cache from 5.0.4 to 5.0.5 ( #231 )
...
Signed-off-by: dependabot[bot] <support@github.com >
2026-05-19 09:23:25 +02:00
dependabot[bot]
6cd3d8f2ae
NO-JIRA Bump madhead/semver-utils from 4.3.0 to 5.0.0
...
Bumps [madhead/semver-utils](https://github.com/madhead/semver-utils ) from 4.3.0 to 5.0.0.
- [Release notes](https://github.com/madhead/semver-utils/releases )
- [Commits](https://github.com/madhead/semver-utils/compare/36d1e0ed361bd7b4b77665de8093092eaeabe6ba...4cf918affe9106ea59f86c6250e5ec4570ac4389 )
---
updated-dependencies:
- dependency-name: madhead/semver-utils
dependency-version: 5.0.0
dependency-type: direct:production
update-type: version-update:semver-major
...
Signed-off-by: dependabot[bot] <support@github.com >
2026-05-19 09:20:24 +02:00
Pavel Mikula
ca30b65f4e
SQSCANGHA-143 SubmitReview: Use Vault token ( #238 )
2026-04-29 11:16:25 +02:00
Antoine Vinot and Jarek Potiuk
30dbe5c9ee
SQSCANGHA-138 Update dist and add ci test ( #233 )
...
Co-authored-by: Jarek Potiuk <jarek@potiuk.com >
2026-04-23 14:20:12 +02:00
Claire Villard and Julien Carsique
c8357220fa
SQSCANGHA-134 Upgrade the libraries to latest version ( #227 )
...
Co-authored-by: Julien Carsique <julien.carsique@sonarsource.com >
2026-04-14 15:21:19 +02:00
Claire Villard
f099b44166
SQSCANGHA-133 Upgrade the Node version used in UTs + contribution guide ( #226 )
2026-04-03 10:34:00 +02:00
dependabot[bot]
dcc5211de5
SQSCANGHA-128 NO-JIRA Bump actions/cache from 4 to 5 ( #219 )
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-02-16 20:53:44 +01:00
github-actions[bot]
a31c9398be
SQSCANGHA-126 Update SonarScanner CLI to 8.0.1.6346 ( #218 )
2025-12-09 09:53:51 +01:00
dependabot[bot]
40f5b61913
SQSCANGHA-123 NO-JIRA Bump actions/setup-node from 5 to 6 ( #214 )
2025-10-15 15:09:18 +02:00
dependabot[bot]
5ffbad4454
SQSCANGHA-120 Bump actions/setup-node from 4 to 5 ( #211 )
2025-09-22 07:47:48 +02:00
Julien HENRY
60aee7033b
NO-JIRA Disable fail fast on matrix jobs
2025-09-18 10:38:53 +02:00
Julien HENRY
502204eab4
NO-JIRA Fix test assertion
2025-09-18 10:38:53 +02:00
Jeremy Davis
ee80e84272
SQSCANGHA-112 Fix redirect test to deal with TLS
2025-09-18 10:38:53 +02:00
Jeremy Davis
16df975da5
SQSCANGHA-113 Migrate scanner run step
2025-09-18 10:38:53 +02:00
Jeremy Davis
ed9f3aad50
SQSCANGHA-112 Migrate installation step
2025-09-18 10:38:53 +02:00
SonarTech and Julien HENRY
5837ebfcca
BUILD-8875: Migrate to standardized GitHub runner names
...
Co-authored-by: Julien HENRY <julien.henry@sonarsource.com >
2025-09-02 10:10:38 +02:00
Aleksandra Bozhinoska
016cabf33a
SQSCANGHA-101 Add more command injection tests
2025-08-28 10:57:10 +02:00
dependabot[bot]
786af10ed4
NO-JIRA Bump actions/checkout from 4 to 5
...
Bumps [actions/checkout](https://github.com/actions/checkout ) from 4 to 5.
- [Release notes](https://github.com/actions/checkout/releases )
- [Changelog](https://github.com/actions/checkout/blob/main/CHANGELOG.md )
- [Commits](https://github.com/actions/checkout/compare/v4...v5 )
---
updated-dependencies:
- dependency-name: actions/checkout
dependency-version: '5'
dependency-type: direct:production
update-type: version-update:semver-major
...
Signed-off-by: dependabot[bot] <support@github.com >
2025-08-19 13:34:18 +02:00
Julien HENRY
01850e2590
SQSCANGHA-94 Fix the scanner-update workflow
2025-07-22 11:46:10 +02:00
Samir M
74f62c995b
BUILD-8073 Migrate public repositories workflows to large runners
2025-05-26 14:06:24 +02:00
Aleksandra Bozhinoska
c8aa051cc4
SQSCANGHA-83 Avoid unbound variable error on parameter expansion ( #192 )
2025-05-16 16:57:48 +02:00
csaba-feher-sonarsource and Julien HENRY
2500896589
SQSCANGHA-92 Validate scanner version ( #189 )
...
Co-authored-by: Julien HENRY <julien.henry@sonarsource.com >
2025-05-05 17:48:40 +02:00
csaba-feher-sonarsource
73bc64cb64
SQSCANGHA-94 Update version update logic ( #188 )
2025-05-05 17:48:00 +02:00
csaba-feher-sonarsource and Julien HENRY
7d51dd28ef
SQSCANGHA-93 Fix madhead/semver-utils' version ( #187 )
...
Co-authored-by: Julien HENRY <julien.henry@sonarsource.com >
2025-05-05 17:47:42 +02:00
Julien HENRY
be0a85295f
SQSCANGHA-89 Fix possible command injection
...
It is unlikely to be a real concern, since an attacker having the possibility to edit a pipeline can easily execute any command, but at least our step won't be involved
2025-04-29 12:17:00 +02:00
SonarTech
aa494459d7
SQSCANGHA-85 Update SonarScanner CLI to 7.1.0.4889 to support sonar.region=us
2025-03-24 15:16:27 +01:00
Aleksandra Bozhinoska
1474b34972
SQSCANGHA-87 Fix the new version in version update ( #182 )
2025-03-24 14:38:55 +01:00
Pavel Mikula
961628671d
SQSCANGHA-86 Autoclose issues created by Jira integration ( #179 )
2025-03-10 10:47:13 +01:00
SonarTech
0303d6b62e
Update SonarScanner CLI to 7.0.2.4839
2025-02-14 14:05:04 +01:00
Julien HENRY
3ed7560138
SQSCANGHA-82 Automate the update of the Scanner CLI version
2025-02-14 12:33:25 +01:00
Julien HENRY
73cb22d49a
Fix permission of the version_update workflow
2025-02-10 14:27:00 +01:00
Antonio Aversa
26c51824c8
SQSCANGHA-76 Support self-hosted runners not clearing truststore after run ( #165 )
2024-12-17 09:19:42 +01:00
Antonio Aversa
0ab314b63d
SQSCANGHA-75 Support self-hosted runners not clearing temp after run ( #164 )
2024-12-16 10:45:31 +01:00