Skip to content

Publish tagged releases through crates.io trusted publishing #13

Publish tagged releases through crates.io trusted publishing

Publish tagged releases through crates.io trusted publishing #13

Workflow file for this run

---
name: Sonar
"on":
pull_request:
push:
branches:
- main
permissions:
contents: read
concurrency:
group: ${{ github.workflow }}-${{ github.ref }}
cancel-in-progress: ${{ github.ref != 'refs/heads/main' }}
env:
CARGO_TERM_COLOR: always
jobs:
sonar:
name: SonarQube scan
runs-on: ubuntu-latest
timeout-minutes: 30
# Neither a fork's pull request nor a Dependabot run can read SONAR_TOKEN.
if: >-
github.event_name == 'push' ||
(github.event.pull_request.head.repo.full_name == github.repository &&
github.event.pull_request.user.login != 'dependabot[bot]')
steps:
- uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
with:
# Full history improves blame-based new-code attribution.
fetch-depth: 0
- name: Install stable toolchain with clippy and llvm-tools
run: |
rustup toolchain install stable \
--profile minimal \
--component clippy \
--component llvm-tools-preview
- uses: taiki-e/install-action@7623a79cdfecb99d681017af368ca353d9f49bb5 # v2.87.19
with:
tool: cargo-llvm-cov
- name: Test coverage
run: cargo +stable llvm-cov --all-targets --lcov --output-path lcov.info
- name: SonarQube scan
uses: SonarSource/sonarqube-scan-action@ba9859eae8dd6bd29e412f25ddbbef3d032000f4 # v8.2.2
env:
SONAR_TOKEN: ${{ secrets.SONAR_TOKEN }}