From e103e7e41bc61df548565f8f34e5385d4f67bc82 Mon Sep 17 00:00:00 2001 From: Bruno Domingues Date: Wed, 14 May 2025 15:17:59 -0300 Subject: [PATCH] Add quality gate workflow 12. --- .github/workflows/quality-gate.yml | 68 +++++++++++++++++++++++------- 1 file changed, 53 insertions(+), 15 deletions(-) diff --git a/.github/workflows/quality-gate.yml b/.github/workflows/quality-gate.yml index 9164b3d..111fd10 100644 --- a/.github/workflows/quality-gate.yml +++ b/.github/workflows/quality-gate.yml @@ -13,28 +13,65 @@ jobs: sonar: name: SonarQube Analysis runs-on: ubuntu-latest - permissions: write-all + permissions: + contents: read # Necessário para checkout + # Adicione outras permissões se o token do app precisar delas, + # mas 'write-all' é muito amplo e geralmente não necessário para o token do workflow em si. + # As permissões para o token do app são definidas na configuração do GitHub App. steps: - name: ⬇️ Checkout Code uses: actions/checkout@v4 with: - fetch-depth: 0 - - - name: Generate token - id: generate-token + fetch-depth: 0 # Necessário para SonarQube analysis + persist-credentials: false # Importante: Evita que o token padrão do checkout interfira + + - name: Generate App Token + id: generate-app-token uses: actions/create-github-app-token@v1 with: app-id: ${{ secrets.APP_ID }} private-key: ${{ secrets.APP_PRIVATE_KEY }} - owner: 'Aignosi' - repositories: 'sientia-dataops-library,sientia-mlops-library' + owner: 'Aignosi' # O proprietário (usuário ou organização) dos repositórios + repositories: 'sientia-dataops-library,sientia-mlops-library' # Repositórios que o token do app precisa acessar - - name: Create temporary requirements file - env: - GITHUB_TOKEN: ${{ steps.generate-token.outputs.token }} + - name: Prepare requirements.txt + id: prepare-requirements run: | - sed "s|git+ssh://git@github.com|git+https://${GITHUB_TOKEN}@github.com|g" requirements.txt > requirements_https.txt + if [ ! -f requirements.txt ]; then + echo "requirements.txt not found!" + # Decide how to handle: exit 1, or create an empty one, or use a default + # For now, let's assume it might be optional or created elsewhere if not present. + # If it's mandatory, uncomment the line below: + exit 1 + echo "PROCESSED_REQUIREMENTS_FILE=requirements.txt" >> $GITHUB_OUTPUT # Fallback or handle error + else + # Converte URLs SSH (git@github.com: ou git+ssh://git@github.com/) para HTTPS genéricas + # Exemplo: git+ssh://git@github.com/Aignosi/repo.git -> git+https://github.com/Aignosi/repo.git + # Exemplo: git@github.com:Aignosi/repo.git -> git+https://github.com/Aignosi/repo.git + sed -e "s|git+ssh://git@github.com/|git+https://github.com/|g" \ + -e "s|git@github.com:|git+https://github.com/|g" \ + requirements.txt > requirements_prepared.txt + echo "PROCESSED_REQUIREMENTS_FILE=requirements_prepared.txt" >> $GITHUB_OUTPUT + echo "--- Original requirements.txt ---" + cat requirements.txt + echo "--- Prepared requirements_prepared.txt ---" + cat requirements_prepared.txt + fi + + - name: Configure Git to use App Token + env: + # Este é o token gerado pelo GitHub App, com permissões para os repositórios de dependência + GH_APP_TOKEN: ${{ steps.generate-app-token.outputs.token }} + run: | + # Configura o Git para usar o token do app para todas as URLs HTTPS do github.com + # Isso garante que o pip, ao clonar dependências, usará este token. + git config --global url."https://oauth2:${GH_APP_TOKEN}@github.com/".insteadOf "https://github.com/" + echo "Git authentication configured to use the App Token for github.com" + + # (Opcional) Para depuração: Verifique se o token pode listar o repositório remoto + GIT_TERMINAL_PROMPT=0 git ls-remote https://github.com/Aignosi/sientia-dataops-library.git HEAD || echo "Failed to ls-remote sientia-dataops-library" + GIT_TERMINAL_PROMPT=0 git ls-remote https://github.com/Aignosi/sientia-mlops-library.git HEAD || echo "Failed to ls-remote sientia-mlops-library" - name: 🔧 Setup Python uses: actions/setup-python@v4 @@ -45,14 +82,15 @@ jobs: uses: actions/cache@v3 with: path: ~/.cache/pip - key: ${{ runner.os }}-pip-${{ hashFiles('requirements_https.txt') }} + key: ${{ runner.os }}-pip-${{ hashFiles(steps.prepare-requirements.outputs.PROCESSED_REQUIREMENTS_FILE) }} restore-keys: | ${{ runner.os }}-pip- - name: 📦 Install Dependencies run: | python -m pip install --upgrade pip - pip install -r requirements_https.txt + echo "Installing dependencies from ${{ steps.prepare-requirements.outputs.PROCESSED_REQUIREMENTS_FILE }}" + pip install -r ${{ steps.prepare-requirements.outputs.PROCESSED_REQUIREMENTS_FILE }} pip install pytest pytest-cov - name: ⬇️ Setup Node.js 18 @@ -65,13 +103,13 @@ jobs: - name: 🧪 Run Tests with Pytest run: | - pytest tests --junitxml=pytest.xml --cov=scouter requirements--cov-report=xml --cov-report=term + pytest tests --junitxml=pytest.xml --cov=scouter --cov-report=xml --cov-report=term - name: 📊 Run SonarQube Analysis env: SONAR_PROJECT_KEY: ${{ secrets.SONAR_PROJECT_KEY }} SONAR_HOST_URL: ${{ secrets.SONAR_HOST_URL }} - SONAR_TOKEN: ${{ secrets.SONAR_TOKEN }} + SONAR_TOKEN: ${{ secrets.SONAR_TOKEN }} # Este é o token do SonarQube run: | sonar-scanner \ -Dsonar.projectKey=$SONAR_PROJECT_KEY \