Skip to content

SONARJAVA-6899 Onboard SonarJava onto the PVF (2 - TEST) - #6311

Closed
rombirli wants to merge 3 commits into
masterfrom
rombirli/sonarjava-6899-onboard-pvf2
Closed

rombirli wants to merge 3 commits into
masterfrom
rombirli/sonarjava-6899-onboard-pvf2

Conversation

@rombirli

@rombirli rombirli commented Oct 8, 2026 •

Copy link
Copy Markdown
Contributor

Summary by Gitar

  • CI Workflows:
    • Added pvf-comment.yml workflow to trigger performance validation from a /pvf comment.
    • Updated build.yml to prepare and publish the PVF candidate version upon deployment.

This will update automatically on new commits.

rombirli and others added 3 commits October 8, 2026 14:21
Record the deployed sonar-java version as the candidate-version artifact so a
later /pvf comment can resolve which build to benchmark.
A `/pvf` comment on a PR dispatches performance-validation-java.yml in
peachee-java-kotlin, which runs the benchmark and comments the dashboard link
back here. The dashboard is hosted there because this repository is public and
the report has to stay private.
…ave to do it later

Co-authored-by: Alex Meseldzija <alexander.meseldzija@sonarsource.com>
@datadog-sonarsource

datadog-sonarsource Bot commented Oct 8, 2026 •

Copy link
Copy Markdown

Pipelines

❌ Errors

Your PR has failed checks. Please review the issues below and take necessary action before merging.

🚦 3 Pipeline jobs failed

Build | Ruling Update and Notify — 🔄 Retry may pass, looks flaky

View more details · View in GitHub Actions

Build | Build

View more details · View in GitHub Actions

Build | Build and Unit Test on Windows

View more details · View in GitHub Actions

Useful? React with 👍 / 👎

This comment will be updated automatically if new data arrives.
🔗 Commit SHA: f1281ff | Docs | View more details | Give us feedback!

@hashicorp-vault-sonar-prod

Copy link
Copy Markdown
Contributor

SONARJAVA-6899

@gitar-bot

gitar-bot Bot commented Oct 8, 2026 •

Copy link
Copy Markdown
CI failed: Multiple CI jobs failed due to configuration and permission errors: get_build_number failed with HTTP 403 because workflow tokens lacked `contents: write` permissions, and artifact synchronization failed because ruling QA was skipped.

Overview

Three failures occurred across CI jobs, primarily driven by missing workflow write permissions and downstream artifact handling issues when QA jobs are skipped.

Failures

Missing Contents Write Permission for Build Number (confidence: high)

  • Type: configuration
  • Affected jobs: 113361287638, 113361287666
  • Related to change: unclear
  • Root cause: The build-number action received a 403 error while attempting to create a Git ref because the calling workflow token only has contents: read permissions instead of contents: write.
  • Suggested fix: Add permissions: contents: write to the workflow or affected jobs.

Ruling Artifact Sync Failure (confidence: high)

  • Type: configuration
  • Affected jobs: 113361749006
  • Related to change: unclear
  • Root cause: The ruling update and notify job treated a skipped ruling QA job as a failure (ruling-failed=true), and subsequently attempted to download/sync missing artifacts which resulted in an exit code 1.
  • Suggested fix: Ensure ruling artifacts are correctly uploaded when required, or prevent the sync step from executing when ruling QA is skipped.

Summary

  • Change-related failures: 0 (relationship is unclear based on available context)
  • Infrastructure/flaky failures: 0
  • Recommended action: Update workflow permissions to grant contents: write for build number generation, and adjust the ruling QA/artifact sync workflow logic.
Code Review ✅ Approved

🔴 High risk · A comment-gated cross-repository dispatch uses a Vault token, letting eligible commenters initiate external workflows and potentially launch unintended validation runs.

Onboards SonarJava onto the PVF by adding a pvf-comment.yml workflow to trigger performance validation from a /pvf comment and updating build.yml to publish the PVF candidate version on deployment. No issues found.

Review coverage

🧪 Functional validation No results

📋 Rules No rules evaluated

📖 Knowledge used 1 confirmed expected behavior

🤖 Auto-approval Not enabled · Set up

Tip

Comment Gitar fix CI or enable auto-apply: gitar auto-apply:on

Options

Auto-apply is off → Gitar will not commit updates to this branch.
Display: compact → Counting what did not apply, without listing it.

Comment with these commands to change the behavior for this request:

Auto-apply Compact
gitar auto-apply:on         
gitar display:verbose         

Was this helpful? React with 👍 / 👎 | Gitar

@rombirli rombirli closed this Oct 8, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant