mirror of
https://github.com/NVIDIA/Model-Optimizer.git
synced 2026-10-02 03:14:52 +08:00
Enable SonarQube Static Application Security Testing (SAST) (#1349)
Enable SonarQube as a Nvidia recommended and more comprehensive code scanning tools compared to Bandit we currently use in pre-commit hook (still left for now) Tested pipeline in internal gitlab and it works and results are uploaded in internal SonarQube website <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **Chores** * Added CI jobs to run SonarQube analysis and generate a vulnerability report, with scheduled and branch-triggered runs. * Configured scans to preserve full git history, use caching, and auto-cancel interruptible runs. * Added an ignore rule to exclude generated analysis artifacts from version control. <!-- end of auto-generated comment: release notes by coderabbit.ai --> --------- Signed-off-by: Keval Morabia <28916987+kevalmorabia97@users.noreply.github.com>
This commit is contained in:
@@ -61,3 +61,6 @@ venv/
|
||||
|
||||
# Ignore claude local settings
|
||||
.claude/settings.local.json
|
||||
|
||||
# Ignore SonarQube analysis
|
||||
.sonar/
|
||||
|
||||
@@ -0,0 +1,54 @@
|
||||
workflow:
|
||||
auto_cancel:
|
||||
on_new_commit: interruptible
|
||||
|
||||
stages:
|
||||
- build-sonar
|
||||
- sonarqube-vulnerability-report
|
||||
|
||||
default:
|
||||
tags:
|
||||
- type/docker
|
||||
- os/linux
|
||||
- cpu
|
||||
|
||||
image:
|
||||
name: sonarsource/sonar-scanner-cli:11
|
||||
entrypoint: [""]
|
||||
|
||||
variables:
|
||||
SONAR_USER_HOME: "${CI_PROJECT_DIR}/.sonar"
|
||||
GIT_DEPTH: "0" # Shallow clones should be disabled for a better relevancy of analysis
|
||||
|
||||
build-sonar:
|
||||
stage: build-sonar
|
||||
interruptible: true
|
||||
cache:
|
||||
policy: pull-push
|
||||
key: "sonar-cache-${CI_COMMIT_REF_SLUG}"
|
||||
paths:
|
||||
- "${SONAR_USER_HOME}/cache"
|
||||
- sonar-scanner/
|
||||
script:
|
||||
- sonar-scanner -Dsonar.projectKey=EngHW_ModelOpt_ModelOpt_modelopt -Dsonar.sources=modelopt,modelopt_recipes,examples -Dsonar.host.url="${SONAR_HOST_URL}"
|
||||
-Dsonar.token="${SONAR_TOKEN}"
|
||||
rules:
|
||||
- if: $CI_PIPELINE_SOURCE == "schedule"
|
||||
- if: $CI_PIPELINE_SOURCE == "web"
|
||||
- if: $CI_COMMIT_BRANCH =~ /^(main|release\/.*)$/ && $CI_PIPELINE_SOURCE == "push"
|
||||
|
||||
sonarqube-vulnerability-report:
|
||||
stage: sonarqube-vulnerability-report
|
||||
interruptible: true
|
||||
script:
|
||||
- 'curl --fail --silent --show-error -u "${SONAR_TOKEN}:" "${SONAR_HOST_URL}/api/issues/gitlab_sast_export?projectKey=EngHW_ModelOpt_ModelOpt_modelopt&branch=${CI_COMMIT_BRANCH}&pullRequest=${CI_MERGE_REQUEST_IID}"
|
||||
-o gl-sast-sonar-report.json'
|
||||
- 'test -s gl-sast-sonar-report.json'
|
||||
rules:
|
||||
- if: $CI_PIPELINE_SOURCE == "schedule"
|
||||
- if: $CI_PIPELINE_SOURCE == "web"
|
||||
- if: $CI_COMMIT_BRANCH =~ /^(main|release\/.*)$/ && $CI_PIPELINE_SOURCE == "push"
|
||||
artifacts:
|
||||
expire_in: 1 day
|
||||
reports:
|
||||
sast: gl-sast-sonar-report.json
|
||||
Reference in New Issue
Block a user