From 1306841989dae454b25c8f705a9646949e5c9ae6 Mon Sep 17 00:00:00 2001 From: Keval Morabia <28916987+kevalmorabia97@users.noreply.github.com> Date: Tue, 28 Apr 2026 00:34:27 +0530 Subject: [PATCH] Enable SonarQube Static Application Security Testing (SAST) (#1349) Enable SonarQube as a Nvidia recommended and more comprehensive code scanning tools compared to Bandit we currently use in pre-commit hook (still left for now) Tested pipeline in internal gitlab and it works and results are uploaded in internal SonarQube website ## Summary by CodeRabbit * **Chores** * Added CI jobs to run SonarQube analysis and generate a vulnerability report, with scheduled and branch-triggered runs. * Configured scans to preserve full git history, use caching, and auto-cancel interruptible runs. * Added an ignore rule to exclude generated analysis artifacts from version control. --------- Signed-off-by: Keval Morabia <28916987+kevalmorabia97@users.noreply.github.com> --- .gitignore | 3 +++ .gitlab/.gitlab-ci.yml | 54 ++++++++++++++++++++++++++++++++++++++++++ 2 files changed, 57 insertions(+) create mode 100644 .gitlab/.gitlab-ci.yml diff --git a/.gitignore b/.gitignore index 6e8491465..09a61233b 100644 --- a/.gitignore +++ b/.gitignore @@ -61,3 +61,6 @@ venv/ # Ignore claude local settings .claude/settings.local.json + +# Ignore SonarQube analysis +.sonar/ diff --git a/.gitlab/.gitlab-ci.yml b/.gitlab/.gitlab-ci.yml new file mode 100644 index 000000000..937938272 --- /dev/null +++ b/.gitlab/.gitlab-ci.yml @@ -0,0 +1,54 @@ +workflow: + auto_cancel: + on_new_commit: interruptible + +stages: + - build-sonar + - sonarqube-vulnerability-report + +default: + tags: + - type/docker + - os/linux + - cpu + +image: + name: sonarsource/sonar-scanner-cli:11 + entrypoint: [""] + +variables: + SONAR_USER_HOME: "${CI_PROJECT_DIR}/.sonar" + GIT_DEPTH: "0" # Shallow clones should be disabled for a better relevancy of analysis + +build-sonar: + stage: build-sonar + interruptible: true + cache: + policy: pull-push + key: "sonar-cache-${CI_COMMIT_REF_SLUG}" + paths: + - "${SONAR_USER_HOME}/cache" + - sonar-scanner/ + script: + - sonar-scanner -Dsonar.projectKey=EngHW_ModelOpt_ModelOpt_modelopt -Dsonar.sources=modelopt,modelopt_recipes,examples -Dsonar.host.url="${SONAR_HOST_URL}" + -Dsonar.token="${SONAR_TOKEN}" + rules: + - if: $CI_PIPELINE_SOURCE == "schedule" + - if: $CI_PIPELINE_SOURCE == "web" + - if: $CI_COMMIT_BRANCH =~ /^(main|release\/.*)$/ && $CI_PIPELINE_SOURCE == "push" + +sonarqube-vulnerability-report: + stage: sonarqube-vulnerability-report + interruptible: true + script: + - 'curl --fail --silent --show-error -u "${SONAR_TOKEN}:" "${SONAR_HOST_URL}/api/issues/gitlab_sast_export?projectKey=EngHW_ModelOpt_ModelOpt_modelopt&branch=${CI_COMMIT_BRANCH}&pullRequest=${CI_MERGE_REQUEST_IID}" + -o gl-sast-sonar-report.json' + - 'test -s gl-sast-sonar-report.json' + rules: + - if: $CI_PIPELINE_SOURCE == "schedule" + - if: $CI_PIPELINE_SOURCE == "web" + - if: $CI_COMMIT_BRANCH =~ /^(main|release\/.*)$/ && $CI_PIPELINE_SOURCE == "push" + artifacts: + expire_in: 1 day + reports: + sast: gl-sast-sonar-report.json