Files
Model-Optimizer/.gitlab/.gitlab-ci.yml
T
Keval Morabia 1306841989 Enable SonarQube Static Application Security Testing (SAST) (#1349)
Enable SonarQube as a Nvidia recommended and more comprehensive code
scanning tools compared to Bandit we currently use in pre-commit hook
(still left for now)

Tested pipeline in internal gitlab and it works and results are uploaded
in internal SonarQube website

<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->
## Summary by CodeRabbit

* **Chores**
* Added CI jobs to run SonarQube analysis and generate a vulnerability
report, with scheduled and branch-triggered runs.
* Configured scans to preserve full git history, use caching, and
auto-cancel interruptible runs.
* Added an ignore rule to exclude generated analysis artifacts from
version control.
<!-- end of auto-generated comment: release notes by coderabbit.ai -->

---------

Signed-off-by: Keval Morabia <28916987+kevalmorabia97@users.noreply.github.com>
2026-04-28 00:34:27 +05:30

55 lines
1.6 KiB
YAML

workflow:
auto_cancel:
on_new_commit: interruptible
stages:
- build-sonar
- sonarqube-vulnerability-report
default:
tags:
- type/docker
- os/linux
- cpu
image:
name: sonarsource/sonar-scanner-cli:11
entrypoint: [""]
variables:
SONAR_USER_HOME: "${CI_PROJECT_DIR}/.sonar"
GIT_DEPTH: "0" # Shallow clones should be disabled for a better relevancy of analysis
build-sonar:
stage: build-sonar
interruptible: true
cache:
policy: pull-push
key: "sonar-cache-${CI_COMMIT_REF_SLUG}"
paths:
- "${SONAR_USER_HOME}/cache"
- sonar-scanner/
script:
- sonar-scanner -Dsonar.projectKey=EngHW_ModelOpt_ModelOpt_modelopt -Dsonar.sources=modelopt,modelopt_recipes,examples -Dsonar.host.url="${SONAR_HOST_URL}"
-Dsonar.token="${SONAR_TOKEN}"
rules:
- if: $CI_PIPELINE_SOURCE == "schedule"
- if: $CI_PIPELINE_SOURCE == "web"
- if: $CI_COMMIT_BRANCH =~ /^(main|release\/.*)$/ && $CI_PIPELINE_SOURCE == "push"
sonarqube-vulnerability-report:
stage: sonarqube-vulnerability-report
interruptible: true
script:
- 'curl --fail --silent --show-error -u "${SONAR_TOKEN}:" "${SONAR_HOST_URL}/api/issues/gitlab_sast_export?projectKey=EngHW_ModelOpt_ModelOpt_modelopt&branch=${CI_COMMIT_BRANCH}&pullRequest=${CI_MERGE_REQUEST_IID}"
-o gl-sast-sonar-report.json'
- 'test -s gl-sast-sonar-report.json'
rules:
- if: $CI_PIPELINE_SOURCE == "schedule"
- if: $CI_PIPELINE_SOURCE == "web"
- if: $CI_COMMIT_BRANCH =~ /^(main|release\/.*)$/ && $CI_PIPELINE_SOURCE == "push"
artifacts:
expire_in: 1 day
reports:
sast: gl-sast-sonar-report.json