mirror of
https://github.com/NVIDIA/Model-Optimizer.git
synced 2026-10-02 03:14:52 +08:00
Enable SonarQube as a Nvidia recommended and more comprehensive code scanning tools compared to Bandit we currently use in pre-commit hook (still left for now) Tested pipeline in internal gitlab and it works and results are uploaded in internal SonarQube website <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **Chores** * Added CI jobs to run SonarQube analysis and generate a vulnerability report, with scheduled and branch-triggered runs. * Configured scans to preserve full git history, use caching, and auto-cancel interruptible runs. * Added an ignore rule to exclude generated analysis artifacts from version control. <!-- end of auto-generated comment: release notes by coderabbit.ai --> --------- Signed-off-by: Keval Morabia <28916987+kevalmorabia97@users.noreply.github.com>
55 lines
1.6 KiB
YAML
55 lines
1.6 KiB
YAML
workflow:
|
|
auto_cancel:
|
|
on_new_commit: interruptible
|
|
|
|
stages:
|
|
- build-sonar
|
|
- sonarqube-vulnerability-report
|
|
|
|
default:
|
|
tags:
|
|
- type/docker
|
|
- os/linux
|
|
- cpu
|
|
|
|
image:
|
|
name: sonarsource/sonar-scanner-cli:11
|
|
entrypoint: [""]
|
|
|
|
variables:
|
|
SONAR_USER_HOME: "${CI_PROJECT_DIR}/.sonar"
|
|
GIT_DEPTH: "0" # Shallow clones should be disabled for a better relevancy of analysis
|
|
|
|
build-sonar:
|
|
stage: build-sonar
|
|
interruptible: true
|
|
cache:
|
|
policy: pull-push
|
|
key: "sonar-cache-${CI_COMMIT_REF_SLUG}"
|
|
paths:
|
|
- "${SONAR_USER_HOME}/cache"
|
|
- sonar-scanner/
|
|
script:
|
|
- sonar-scanner -Dsonar.projectKey=EngHW_ModelOpt_ModelOpt_modelopt -Dsonar.sources=modelopt,modelopt_recipes,examples -Dsonar.host.url="${SONAR_HOST_URL}"
|
|
-Dsonar.token="${SONAR_TOKEN}"
|
|
rules:
|
|
- if: $CI_PIPELINE_SOURCE == "schedule"
|
|
- if: $CI_PIPELINE_SOURCE == "web"
|
|
- if: $CI_COMMIT_BRANCH =~ /^(main|release\/.*)$/ && $CI_PIPELINE_SOURCE == "push"
|
|
|
|
sonarqube-vulnerability-report:
|
|
stage: sonarqube-vulnerability-report
|
|
interruptible: true
|
|
script:
|
|
- 'curl --fail --silent --show-error -u "${SONAR_TOKEN}:" "${SONAR_HOST_URL}/api/issues/gitlab_sast_export?projectKey=EngHW_ModelOpt_ModelOpt_modelopt&branch=${CI_COMMIT_BRANCH}&pullRequest=${CI_MERGE_REQUEST_IID}"
|
|
-o gl-sast-sonar-report.json'
|
|
- 'test -s gl-sast-sonar-report.json'
|
|
rules:
|
|
- if: $CI_PIPELINE_SOURCE == "schedule"
|
|
- if: $CI_PIPELINE_SOURCE == "web"
|
|
- if: $CI_COMMIT_BRANCH =~ /^(main|release\/.*)$/ && $CI_PIPELINE_SOURCE == "push"
|
|
artifacts:
|
|
expire_in: 1 day
|
|
reports:
|
|
sast: gl-sast-sonar-report.json
|