[ 
https://issues.apache.org/jira/browse/NUTCH-3205?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=18105129#comment-18105129
 ] 

ASF GitHub Bot commented on NUTCH-3205:
---------------------------------------

lewismc merged PR #953:
URL: https://github.com/apache/nutch/pull/953




>  Improve SonarCloud analysis classpath, launcher coverage, version metadata, 
> and scan workflow reliability
> ----------------------------------------------------------------------------------------------------------
>
>                 Key: NUTCH-3205
>                 URL: https://issues.apache.org/jira/browse/NUTCH-3205
>             Project: Nutch
>          Issue Type: Improvement
>          Components: build, ci/cd
>    Affects Versions: 1.23
>            Reporter: Lewis John McGibbney
>            Assignee: Lewis John McGibbney
>            Priority: Major
>             Fix For: 1.24
>
>
> SonarCloud master analysis for apache_nutch succeeds and the quality gate
> "Nutch Way" is correctly assigned, but the scanner log shows analysis-quality
> gaps that we should fix in-repo.
> Observed (e.g. Actions run 31868074956 / job 94972171475):
> - WARN: Unresolved imports/types during Java main and test analysis
> - WARN: Preview features detected (despite sonar.java.enablePreview=false;
>   often accompanies unresolved types)
> - Project version reported as "not provided"
> - Incorrect property name sonar.source.encoding (should be 
> sonar.sourceEncoding)
> - sonar.java.libraries only includes build/lib/*.jar, while plugin 
> dependencies
>   live under build/*/lib/*.jar (~200 jars in CI artifacts)
> - sonar.sources omits src/bin, so the nutch and crawl bash launchers are not
>   analyzed under the shell quality profile
> - sonarcloud.yml download/flatten steps use continue-on-error: true, so a
>   missing JaCoCo/JUnit/binary artifact can still produce a "successful" scan
> Note: "Nutch Way" is the quality GATE (already applied on SonarCloud). There 
> is
> no "Nutch Way" quality PROFILE; profiles remain Sonar way. This issue does not
> change gate/profile association.
> Proposed changes:
> 1. Update sonar-project.properties: encoding key, version, tags, broader Java
>    libraries/test libraries, coverage exclusions for package-info.java, and
>    include src/bin in sonar.sources so nutch/crawl launchers are analyzed
> 2. Update .github/workflows/sonarcloud.yml: pass -Dsonar.projectVersion from
>    default.properties; remove continue-on-error from artifact steps; add a
>    preflight check that required inputs exist before scanning



--
This message was sent by Atlassian Jira
(v8.20.10#820010)

Reply via email to