Skip to content

SONARJAVA-6899 Onboard SonarJava onto the PVF - #6288

Merged
rombirli merged 3 commits into
masterfrom
rombirli/sonarjava-6899-onboard-pvf
Oct 8, 2026
Merged

rombirli merged 3 commits into
masterfrom
rombirli/sonarjava-6899-onboard-pvf

Conversation

@rombirli

@rombirli rombirli commented Oct 2, 2026 •

Copy link
Copy Markdown
Contributor

Part of SONARJAVA-6899. Companion PR: SonarSource/peachee-java-kotlin#327

Onboards SonarJava onto the Performance Validation Framework, the same way SonarJS#7913 did for SonarJS.

Because this repository is public and the PVF report must stay private, the benchmark and the dashboard are hosted in peachee-java-kotlin (as SonarJS hosts its in peachee-js). This PR only adds the two ends of the handshake:

  • build.yml records the deployed plugin version as the candidate-version artifact.
  • pvf-comment.yml turns a /pvf comment on a PR into a workflow_dispatch of performance-validation-java.yml in peachee-java-kotlin, which benchmarks that version and comments the dashboard link back here.

Usage once merged

Comment /pvf on a PR to benchmark every rule, or /pvf S1234, S5678 to restrict the run to specific rules.

Prerequisites, all landed

  • Vault token pvf-dispatch for this repository, with actions:write on peachee-java-kotlin — re-terraform-aws-vault#9750
  • The host-side tokens and the GitHub Pages build_type switch, both listed on the companion PR

Testing

The build.yml half is proven by this PR's own Build run: it published candidate-version = 8.45.0.59032.

The host side is proven too. 8.45.0.59032 was benchmarked against a baseline pinned two releases back, over the full 140-project matrix, in peachee-java-kotlin run 37020618474: every project built and prepared, the issue diff reported real rule differences, and the dashboard published to GitHub Pages. That exercises the project matrix, the build delegation, the server context, the report publication and the issue diffing. See peachee-java-kotlin#329 for how that run was triggered.

What remains untestable before merge is only the first hop: GitHub registers an issue_comment workflow and a workflow_dispatch target only once the file sits on the default branch, so /pvf cannot fire from a branch on either side. That hop is the shared pvf-trigger action already in production for SonarJS, so it is not new code.

Merge order

The companion PR has to merge first, because pvf-comment.yml dispatches performance-validation-java.yml against peachee-java-kotlin's master. After both are in, comment /pvf here to confirm the last hop end to end.

@hashicorp-vault-sonar-prod

hashicorp-vault-sonar-prod Bot commented Oct 2, 2026 •

Copy link
Copy Markdown
Contributor

SONARJAVA-6899

Comment thread .github/workflows/pvf-comment.yml
@rombirli
rombirli force-pushed the rombirli/sonarjava-6899-onboard-pvf branch from bd3d709 to adf3cc4 Compare October 2, 2026 07:49
@rombirli

rombirli commented Oct 2, 2026 •

Copy link
Copy Markdown
Contributor Author

Gitar, Valid but conditional on SonarSource/core-languages-tooling-public#70, still open. SonarJS has same permission, keeping parity.

@rombirli

rombirli commented Oct 2, 2026

Copy link
Copy Markdown
Contributor Author

@alex-meseldzija-sonarsource alex-meseldzija-sonarsource left a comment •

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM, just change the pull-request to write so we dont have to do it later.

Comment thread .github/workflows/pvf-comment.yml Outdated
@datadog-sonarsource

This comment has been minimized.

@rombirli
rombirli force-pushed the rombirli/sonarjava-6899-onboard-pvf branch from 4852ee8 to f1281ff Compare October 8, 2026 12:21
@alex-meseldzija-sonarsource
alex-meseldzija-sonarsource force-pushed the rombirli/sonarjava-6899-onboard-pvf branch from f1281ff to 53e92d0 Compare October 8, 2026 14:28
rombirli and others added 3 commits October 8, 2026 16:35
Record the deployed sonar-java version as the candidate-version artifact so a
later /pvf comment can resolve which build to benchmark.
A `/pvf` comment on a PR dispatches performance-validation-java.yml in
peachee-java-kotlin, which runs the benchmark and comments the dashboard link
back here. The dashboard is hosted there because this repository is public and
the report has to stay private.
…ave to do it later

Co-authored-by: Alex Meseldzija <alexander.meseldzija@sonarsource.com>
@rombirli
rombirli force-pushed the rombirli/sonarjava-6899-onboard-pvf branch from 53e92d0 to 9ce947b Compare October 8, 2026 14:36
@gitar-bot

gitar-bot Bot commented Oct 8, 2026

Copy link
Copy Markdown
Code Review ✅ Approved 1 closed / 1 findings

🟡 Medium risk · The /pvf comment workflow dispatches a cross-repository performance run, so matching comments could trigger unintended benchmark runs.

Onboards SonarJava onto the Performance Validation Framework by adding workflow automation to publish the built plugin version and dispatch performance benchmarks via /pvf comments, resolving the pull-requests read permission issue that was blocking the pvf-trigger feedback.

✅ 1 closed
✅ Cross-PR: pull-requests: read blocks pvf-trigger feedback added by tooling PR #70

📄 .github/workflows/pvf-comment.yml:16-20 📄 .github/workflows/pvf-comment.yml:44
This depends on another open PR. This workflow (sonar-java#6288, head bd3d709) calls SonarSource/core-languages-tooling-public/pvf-trigger@master, which is a moving ref, and only grants pull-requests: read. core-languages-tooling-public#70 (head 0e5b127c9ce9b85386289b99f79331aefe9a5e92) changes that action in two ways. It adds a 👀 reaction, which is best-effort. It also adds an if: failure() step that runs gh pr comment to tell the commenter why the dispatch failed. That step is not best-effort, and the PR says callers must raise pull-requests to write to get the feedback. Condition: once #70 is merged to master, any failed /pvf dispatch here (for example, Build has not uploaded candidate-version yet) will have its failure-report step fail with a 403 from gh pr comment. The commenter gets no feedback, the run shows an extra failed step, and the 👀 acknowledgement on successful runs is silently skipped.

Review coverage

🧪 Functional validation No results

📋 Rules No rules evaluated

📖 Knowledge used 1 confirmed expected behavior

Cross-repo coverage 1 repository selected

🤖 Auto-approval Not enabled · Set up

Options

Auto-apply is off → Gitar will not commit updates to this branch.
Display: compact → Counting what did not apply, without listing it.

Comment with these commands to change the behavior for this request:

Auto-apply Compact
gitar auto-apply:on         
gitar display:verbose         

Was this helpful? React with 👍 / 👎 | Gitar

@sonarqube-next

sonarqube-next Bot commented Oct 8, 2026

Copy link
Copy Markdown
Contributor

@rombirli
rombirli merged commit e2ff24d into master Oct 8, 2026
18 checks passed
@rombirli
rombirli deleted the rombirli/sonarjava-6899-onboard-pvf branch October 8, 2026 15:15
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants