From c64b7de9f8be0692e6e796d62f874d74ff61d847 Mon Sep 17 00:00:00 2001 From: Romain Birling Date: Fri, 2 Oct 2026 09:01:57 +0200 Subject: [PATCH 1/3] SONARJAVA-6899 Publish the built plugin version for PVF Record the deployed sonar-java version as the candidate-version artifact so a later /pvf comment can resolve which build to benchmark. --- .github/workflows/build.yml | 7 +++++++ 1 file changed, 7 insertions(+) diff --git a/.github/workflows/build.yml b/.github/workflows/build.yml index 65eccc2971e..80f4e6f0242 100644 --- a/.github/workflows/build.yml +++ b/.github/workflows/build.yml @@ -52,6 +52,13 @@ jobs: --define sonar.skip=true --projects !java-checks-test-sources/aws,!java-checks-test-sources/default,!java-checks-test-sources/java-17,!java-checks-test-sources/spring-3.2,!java-checks-test-sources/spring-web-4.0 + # PVF: publish the concrete deployed plugin version so pvf-comment.yml can dispatch a performance-validation run into peachee-java-kotlin. + - name: Prepare PVF candidate version + if: ${{ steps.build-maven.outputs.deployed }} + uses: SonarSource/core-languages-tooling-public/prepare-pvf@master + with: + build-version: ${{ steps.build-maven.outputs.project-version }} + ruling-qa: strategy: fail-fast: false From 33c4b916190a692814faf02dd2a54c2ae9390434 Mon Sep 17 00:00:00 2001 From: Romain Birling Date: Fri, 2 Oct 2026 09:02:09 +0200 Subject: [PATCH 2/3] SONARJAVA-6899 Trigger performance validation from a /pvf comment A `/pvf` comment on a PR dispatches performance-validation-java.yml in peachee-java-kotlin, which runs the benchmark and comments the dashboard link back here. The dashboard is hosted there because this repository is public and the report has to stay private. --- .github/workflows/pvf-comment.yml | 41 +++++++++++++++++++++++++++++++ 1 file changed, 41 insertions(+) create mode 100644 .github/workflows/pvf-comment.yml diff --git a/.github/workflows/pvf-comment.yml b/.github/workflows/pvf-comment.yml new file mode 100644 index 00000000000..f25fff132a6 --- /dev/null +++ b/.github/workflows/pvf-comment.yml @@ -0,0 +1,41 @@ +name: PVF /pvf comment + +on: + issue_comment: + types: [created] + +permissions: + actions: read + contents: read + pull-requests: read + id-token: write + +concurrency: + group: pvf-comment-${{ github.event.issue.number }} + cancel-in-progress: false + queue: max + +jobs: + trigger: + if: > + github.event.issue.pull_request && + contains(fromJSON('["OWNER","MEMBER","COLLABORATOR"]'), github.event.comment.author_association) && + contains(github.event.comment.body, '/pvf') + runs-on: sonar-xs + steps: + - name: Get cross-repo dispatch token from Vault + id: secrets + uses: SonarSource/vault-action-wrapper@v3 + with: + secrets: | + development/github/token/{REPO_OWNER_NAME_DASH}-pvf-dispatch token | DISPATCH_TOKEN; + + - name: Trigger performance validation in peachee-java-kotlin + uses: SonarSource/core-languages-tooling-public/pvf-trigger@master + with: + comment: ${{ github.event.comment.body }} + pr-number: ${{ github.event.issue.number }} + target-repo: SonarSource/peachee-java-kotlin + target-ref: master + target-workflow: performance-validation-java.yml + dispatch-token: ${{ fromJSON(steps.secrets.outputs.vault).DISPATCH_TOKEN }} From f1281ffaabe5971535a815fb06820af279eb88e1 Mon Sep 17 00:00:00 2001 From: rombirli <56340680+rombirli@users.noreply.github.com> Date: Thu, 8 Oct 2026 10:49:17 +0200 Subject: [PATCH 3/3] Apply Alex's suggestion: hange the pull-request to write so we dont have to do it later Co-authored-by: Alex Meseldzija --- .github/workflows/pvf-comment.yml | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/.github/workflows/pvf-comment.yml b/.github/workflows/pvf-comment.yml index f25fff132a6..11df33f4093 100644 --- a/.github/workflows/pvf-comment.yml +++ b/.github/workflows/pvf-comment.yml @@ -7,7 +7,7 @@ on: permissions: actions: read contents: read - pull-requests: read + pull-requests: write id-token: write concurrency: