SonarCloud
Setting up the SonarCloud analysis.
Adding SonarCloud analysis for src_method takes two steps.
First, ask a software engineer to enable the SonarCloud app for the repository in Algorithmiq's GitHub organization settings:
- Go to Algorithmiq's GitHub organization settings.
- Click on "GitHub Apps" in the left-hand bar.
- Click "Configure" for SonarCloud.
- In the "Repository Access" menu, add
src-methodto the list. - Click "Save".
Then, on the SonarCloud dashboard:
- Go to the Algorithmiq organization.
- Click on the + in the top right corner and choose Analyze new project.
- Add the
src-methodrepository from the list.
We run SonarCloud through CI: the analysis method (Administration > Analysis method) must not be set to Automatic Analysis.
Finally, set the SONAR_TOKEN secret for the repository:
- Copy the token from the project's GitHub Actions configuration.
- Go to the Secrets and variables menu for Actions.
- Click on New repository secret, name it
SONAR_TOKENand paste the value. - Repeat the same steps in the Secrets and variables menu for Dependabot.
The Publish Tests Results job of the test workflow then uploads coverage and
reports, which show up on the SonarCloud dashboard. Without the token, the scan
is skipped rather than failing.