Skip to content

fix(release): apply PSR v10.5.3 bug mitigations to reusable workflow #273

fix(release): apply PSR v10.5.3 bug mitigations to reusable workflow

fix(release): apply PSR v10.5.3 bug mitigations to reusable workflow #273

Workflow file for this run

# SonarCloud Analysis for ByronWilliamsCPA/.github
#
# Analyzes shell scripts, YAML workflow templates, and configuration files.
# SonarCloud auto-detects languages; no Python configuration required.
#
name: SonarCloud Analysis
on:
push:
branches:
- main
pull_request:
types: [opened, synchronize, reopened]
workflow_dispatch:
permissions: {}
concurrency:
group: sonarcloud-${{ github.ref }}
cancel-in-progress: true
jobs:
sonarcloud:
name: SonarCloud Scan
runs-on: ubuntu-latest
timeout-minutes: 15
permissions:
contents: read
pull-requests: write
steps:
- name: Harden the runner
uses: step-security/harden-runner@ab7a9404c0f3da075243ca237b5fac12c98deaa5 # v2.19.3
with:
egress-policy: audit
- name: Checkout repository
uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2
with:
fetch-depth: 0
- name: SonarCloud Scan
if: github.event_name != 'pull_request' || github.event.pull_request.head.repo.full_name == github.repository
uses: SonarSource/sonarqube-scan-action@7006c4492b2e0ee0f816d36501671557c97f5995 # v8.1.0 # nosemgrep: detected-sonarqube-docs-api-key # FP -- see #37
env:
GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }}
SONAR_TOKEN: ${{ secrets.SONAR_TOKEN }}
SONAR_HOST_URL: https://sonarcloud.io