From 19328d3ccf1fc04842bfbe19b295846408869fea Mon Sep 17 00:00:00 2001 From: Adam Setch Date: Sat, 3 Oct 2026 16:14:50 -0400 Subject: [PATCH 1/2] build: add SonarQube Cloud analysis --- .github/workflows/sonarcloud.yml | 38 ++++++++++++++++++++++++++++++++ sonar-project.properties | 25 +++++++++++++++++++++ 2 files changed, 63 insertions(+) create mode 100644 .github/workflows/sonarcloud.yml create mode 100644 sonar-project.properties diff --git a/.github/workflows/sonarcloud.yml b/.github/workflows/sonarcloud.yml new file mode 100644 index 0000000..04dd0c9 --- /dev/null +++ b/.github/workflows/sonarcloud.yml @@ -0,0 +1,38 @@ +name: SonarQube Cloud + +on: + push: + branches: + - main + pull_request: + +permissions: {} + +jobs: + sonarqube: + name: SonarQube Cloud Analysis + runs-on: ubuntu-latest + permissions: + contents: read + # Only analyze PRs from the same repository. Limitation of SonarQube Cloud + if: github.event.pull_request.head.repo.fork == false + + steps: + - name: Checkout + uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 + with: + fetch-depth: 0 # Shallow clones should be disabled for a better relevancy of analysis + persist-credentials: false + + - name: Setup pnpm + uses: pnpm/setup@fbda4c85fc2e1e08721cd8763afea8f48d60f024 # v3.0.0 + with: + node-version-file: ".nvmrc" + cache: true + require-lockfile: true + + - name: SonarQube Cloud Scan + uses: SonarSource/sonarqube-scan-action@d209202bc7d53ff1cc128f7f907dac145c9d6ae9 # v8.3.0 + env: + GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }} # Needed to get PR information, if any + SONAR_TOKEN: ${{ secrets.SONAR_TOKEN }} diff --git a/sonar-project.properties b/sonar-project.properties new file mode 100644 index 0000000..376604d --- /dev/null +++ b/sonar-project.properties @@ -0,0 +1,25 @@ +# ===================================================== +# SonarCloud +# https://docs.sonarsource.com/sonarcloud/advanced-setup/ci-based-analysis/github-actions-for-sonarcloud/ +# ===================================================== +sonar.projectKey=gitify-app_website +sonar.organization=gitify-app +sonar.projectDescription=The source code of gitify.io. + + +# ===================================================== +# Source Configuration +# https://docs.sonarsource.com/sonarcloud/advanced-setup/analysis-scope/ +# ===================================================== +sonar.sources=./src +sonar.typescript.tsconfigPaths=./tsconfig.json + + +# ===================================================== +# Project Metadata +# https://docs.sonarsource.com/sonarcloud/advanced-setup/ci-based-analysis/sonarscanner-for-npm/configuring/ +# ===================================================== +sonar.links.homepage=https://gitify.io +sonar.links.ci=https://github.com/gitify-app/website/actions +sonar.links.scm=https://github.com/gitify-app/website +sonar.links.issue=https://github.com/gitify-app/website/issues From 283cfbe53e1b104ed9e5fc8e45c41e9f5f32f24b Mon Sep 17 00:00:00 2001 From: Adam Setch Date: Sat, 3 Oct 2026 16:28:13 -0400 Subject: [PATCH 2/2] docs: add SonarQube Cloud quality gate badge --- README.md | 4 +++- 1 file changed, 3 insertions(+), 1 deletion(-) diff --git a/README.md b/README.md index ce925b2..026ca5d 100644 --- a/README.md +++ b/README.md @@ -1,6 +1,6 @@ # gitify.io -[![Netlify Status][netlify-badge]][netlify-deploys] [![Renovate enabled][renovate-badge]][renovate] [![Contributors][contributors-badge]][github] [![OSS License][license-badge]][license] +[![Netlify Status][netlify-badge]][netlify-deploys] [![Renovate enabled][renovate-badge]][renovate] [![Contributors][contributors-badge]][github] [![OSS License][license-badge]][license] [![Quality Gate Status][quality-badge]][quality] > The source code for our gitify.io website @@ -52,3 +52,5 @@ All commands are run from the root of the project, from a terminal: [license-badge]: https://img.shields.io/github/license/gitify-app/gitify?logo=github [renovate]: https://github.com/gitify-app/website/issues/15 [renovate-badge]: https://img.shields.io/badge/renovate-enabled-brightgreen.svg?logo=renovate&logoColor=white +[quality]: https://sonarcloud.io/summary/new_code?id=gitify-app_website +[quality-badge]: https://img.shields.io/sonar/quality_gate/gitify-app_website?server=https%3A%2F%2Fsonarcloud.io&logo=sonarqubecloud