Skip to content

CLP-1147 Use DEV version of SQ in its - #6300

Open
BartLucien wants to merge 1 commit into
masterfrom
lb/CLP915-use-DEV-in-its
Open

BartLucien wants to merge 1 commit into
masterfrom
lb/CLP915-use-DEV-in-its

Conversation

@BartLucien

@BartLucien BartLucien commented Oct 5, 2026 •

Copy link
Copy Markdown
Contributor

Part of CLP-915


Summary by Gitar

  • CI / Tests:
    • Updated GitHub Actions workflows and integration tests to use the DEV version of SonarQube instead of LATEST_RELEASE
  • Documentation:
    • Updated README.md to reference DEV for sonar.runtimeVersion

This will update automatically on new commits.

@BartLucien BartLucien changed the title CLP-915 use DEV in its CLP-915 Use DEV version of SQ in its Oct 5, 2026
@hashicorp-vault-sonar-prod

hashicorp-vault-sonar-prod Bot commented Oct 5, 2026 •

Copy link
Copy Markdown
Contributor

CLP-1147

@sonarqube-next

sonarqube-next Bot commented Oct 5, 2026

Copy link
Copy Markdown
Contributor

Comment on lines 108 to +111
- name: Orchestrator Cache
uses: ./.github/actions/orchestrator-cache
with:
sq-version: ${{ matrix.item.sq_version }}
sq-version: DEV

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Performance: Orchestrator cache now always skipped, so every PR job re-downloads SQ

.github/actions/orchestrator-cache/action.yml skips the cache step when inputs.sq-version == 'DEV' (line 21). This PR hardcodes sq-version: DEV for all four Ruling QA jobs (two of them on Windows) and for Plugin QA. Before, only the nightly Plugin QA run used DEV; now every PR and push run downloads the SonarQube Enterprise distribution again in five jobs. CI gets slower and pulls more from the artifact store. A fix: allow DEV caching with a short-lived key (e.g. include the date or resolved DEV build number in the key), or confirm this cost is acceptable.

Was this helpful? React with 👍 / 👎

@BartLucien BartLucien changed the title CLP-915 Use DEV version of SQ in its CLP-1147 Use DEV version of SQ in its Oct 8, 2026
@BartLucien
BartLucien force-pushed the lb/CLP915-use-DEV-in-its branch from d63c05d to 2e8194a Compare October 8, 2026 15:38
@datadog-sonarsource

datadog-sonarsource Bot commented Oct 8, 2026 •

Copy link
Copy Markdown

Pipelines

❌ Errors

Your PR has failed checks. Please review the issues below and take necessary action before merging.

🚦 3 Pipeline jobs failed

Build | Build

View more details · View in GitHub Actions

Build | Build and Unit Test on Windows

View more details · View in GitHub Actions

Build | Ruling Update and Notify

View more details · View in GitHub Actions

Useful? React with 👍 / 👎

This comment will be updated automatically if new data arrives.
🔗 Commit SHA: 2e8194a | Docs | View more details | Give us feedback!

@gitar-bot

gitar-bot Bot commented Oct 8, 2026

Copy link
Copy Markdown
CI failed: CI workflow failures occurred due to a 403 error when getting the build number because of insufficient token permissions, and ruling update jobs failing because upstream artifacts were missing after being skipped.

Overview

Analysis of 3 logs across CI jobs reveals two distinct configuration issues: a 403 Forbidden error when attempting to fetch the build number due to missing write permissions, and a failure in downloading ruling QA artifacts because the upstream ruling job was skipped and its results treated as failures.

Failures

Build Number Action HTTP 403 Error (confidence: high)

  • Type: configuration
  • Affected jobs: 113397647491, 113397647861
  • Related to change: unclear
  • Root cause: The build-number action attempted to create a Git reference, but the workflow token only has contents: read permissions, whereas GitHub requires contents: write for reference creation.
  • Suggested fix: Grant contents: write permission to the calling workflow, or update the action to avoid creating git references.

Missing Ruling QA Artifacts (confidence: medium)

  • Type: configuration
  • Affected jobs: 113398027617
  • Related to change: unclear
  • Root cause: The ruling-qa job was skipped, causing the downstream notifier to evaluate the skipped status as a failure, attempt to download missing artifacts, and fail since no artifacts were uploaded.
  • Suggested fix: Ensure the ruling-qa job runs successfully and uploads the required artifacts, or update the notification workflow to skip gracefully when upstream jobs are omitted.

Summary

  • Change-related failures: 0 failures explicitly tied to the PR changes
  • Infrastructure/flaky failures: 0 failures
  • Recommended action: Verify workflow file permissions for token access and check why ruling QA jobs are being skipped in the CI pipeline.
Code Review 👍 Approved with suggestions 0 closed / 1 findings

🟡 Medium risk · Switching CI and integration tests from LATEST_RELEASE to DEV could leave release-specific regressions undetected or make builds depend on DEV availability.

Switches integration tests and GitHub Actions workflows to use the DEV version of SonarQube instead of LATEST_RELEASE. The orchestrator cache is now skipped for all PR and push runs in five jobs, causing SonarQube to be re-downloaded on each CI execution. Consider implementing short-lived DEV caching (e.g., with a date-based or build-number-based cache key) to avoid the performance cost, or confirm this is acceptable.

💡 Performance: Orchestrator cache now always skipped, so every PR job re-downloads SQ

📄 .github/workflows/build.yml:108-111 📄 .github/workflows/build.yml:219-222

.github/actions/orchestrator-cache/action.yml skips the cache step when inputs.sq-version == 'DEV' (line 21). This PR hardcodes sq-version: DEV for all four Ruling QA jobs (two of them on Windows) and for Plugin QA. Before, only the nightly Plugin QA run used DEV; now every PR and push run downloads the SonarQube Enterprise distribution again in five jobs. CI gets slower and pulls more from the artifact store. A fix: allow DEV caching with a short-lived key (e.g. include the date or resolved DEV build number in the key), or confirm this cost is acceptable.

🤖 Prompt for agents
Code Review: Switches integration tests and GitHub Actions workflows to use the `DEV` version of SonarQube instead of `LATEST_RELEASE`. The orchestrator cache is now skipped for all PR and push runs in five jobs, causing SonarQube to be re-downloaded on each CI execution. Consider implementing short-lived DEV caching (e.g., with a date-based or build-number-based cache key) to avoid the performance cost, or confirm this is acceptable.

1. 💡 Performance: Orchestrator cache now always skipped, so every PR job re-downloads SQ
   Files: .github/workflows/build.yml:108-111, .github/workflows/build.yml:219-222

   `.github/actions/orchestrator-cache/action.yml` skips the cache step when `inputs.sq-version == 'DEV'` (line 21). This PR hardcodes `sq-version: DEV` for all four Ruling QA jobs (two of them on Windows) and for Plugin QA. Before, only the nightly Plugin QA run used DEV; now every PR and push run downloads the SonarQube Enterprise distribution again in five jobs. CI gets slower and pulls more from the artifact store. A fix: allow DEV caching with a short-lived key (e.g. include the date or resolved DEV build number in the key), or confirm this cost is acceptable.

Review coverage

🧪 Functional validation No results

📋 Rules No rules evaluated

🤖 Auto-approval Not enabled · Set up

Tip

Comment Gitar fix CI or enable auto-apply: gitar auto-apply:on

Options

Auto-apply is off → Gitar will not commit updates to this branch.
Display: compact → Counting what did not apply, without listing it.

Comment with these commands to change the behavior for this request:

Auto-apply Compact
gitar auto-apply:on         
gitar display:verbose         

Was this helpful? React with 👍 / 👎 | Gitar

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant