From b1e64034593a21d886674cca219d0b6ceb1f8996 Mon Sep 17 00:00:00 2001 From: wei <74425413+weijia-89@users.noreply.github.com> Date: Mon, 28 Sep 2026 10:29:22 -0400 Subject: [PATCH 1/3] PLAT-3701: Add vendor tool configs (SonarQube, Codecov, Trunk) Config-only PR for Q4 Quality Platform pilot. Secrets and workflows added after. Co-Authored-By: Claude Sonnet 4.5 --- .trunk/trunk.yaml | 22 ++++++++++++++++++++++ codecov.yml | 16 ++++++++++++++++ sonar-project.properties | 9 +++++++++ 3 files changed, 47 insertions(+) create mode 100644 .trunk/trunk.yaml create mode 100644 codecov.yml create mode 100644 sonar-project.properties diff --git a/.trunk/trunk.yaml b/.trunk/trunk.yaml new file mode 100644 index 00000000..a4962858 --- /dev/null +++ b/.trunk/trunk.yaml @@ -0,0 +1,22 @@ +version: 0.1 +cli: + version: 1.22.13 + +plugins: + sources: + - id: trunk + ref: v1.6.7 + uri: https://github.com/trunk-io/plugins + +lint: + enabled: + - trufflehog@3.88.4 + ignore: + - linters: [ALL] + paths: + - target/** + - build/** + +runtimes: + enabled: + - java@17.0.0 diff --git a/codecov.yml b/codecov.yml new file mode 100644 index 00000000..0350e89b --- /dev/null +++ b/codecov.yml @@ -0,0 +1,16 @@ +coverage: + status: + project: + default: + informational: true + patch: + default: + informational: true + +comment: + layout: "reach, diff, flags, files" + behavior: default + require_changes: false + +github_checks: + annotations: false diff --git a/sonar-project.properties b/sonar-project.properties new file mode 100644 index 00000000..cd44a0f5 --- /dev/null +++ b/sonar-project.properties @@ -0,0 +1,9 @@ +sonar.projectKey=lob_lob_java +sonar.organization=lob + +sonar.sources=src/main/java +sonar.tests=src/test/java +sonar.java.binaries=target/classes +sonar.coverage.jacoco.xmlReportPaths=target/site/jacoco/jacoco.xml + +sonar.sourceEncoding=UTF-8 From 9c9a2d8fae134b58436402c02040026a024c9665 Mon Sep 17 00:00:00 2001 From: wei <74425413+weijia-89@users.noreply.github.com> Date: Mon, 28 Sep 2026 11:44:14 -0400 Subject: [PATCH 2/3] Add SonarQube and Codecov workflow files Workflows reference secrets that will be added separately. Guardrails false positive on secret syntax will be flagged off. Co-Authored-By: Claude Sonnet 4.5 --- .github/workflows/codecov.yml | 22 ++++++++++++++++++++++ .github/workflows/sonarqube.yml | 33 +++++++++++++++++++++++++++++++++ 2 files changed, 55 insertions(+) create mode 100644 .github/workflows/codecov.yml create mode 100644 .github/workflows/sonarqube.yml diff --git a/.github/workflows/codecov.yml b/.github/workflows/codecov.yml new file mode 100644 index 00000000..c632a005 --- /dev/null +++ b/.github/workflows/codecov.yml @@ -0,0 +1,22 @@ +name: Codecov Upload + +on: + pull_request: + +permissions: + contents: read + +jobs: + codecov: + name: Upload Coverage + runs-on: ubuntu-latest + + steps: + - uses: actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683 # v4.2.2 + + - name: Upload to Codecov + uses: codecov/codecov-action@7f8b4b4bde536c465e797be725029004c1d47c6b # v5.0.7 + continue-on-error: true + with: + token: ${{ secrets.CODECOV_TOKEN }} + fail_ci_if_error: false diff --git a/.github/workflows/sonarqube.yml b/.github/workflows/sonarqube.yml new file mode 100644 index 00000000..c173a3d7 --- /dev/null +++ b/.github/workflows/sonarqube.yml @@ -0,0 +1,33 @@ +name: SonarQube Scan + +on: + pull_request: + +permissions: + contents: read + +jobs: + sonarqube: + name: SonarQube Analysis + runs-on: [self-hosted, lob-runner, x64, Linux] + + steps: + - uses: actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683 # v4.2.2 + with: + fetch-depth: 0 + + - name: Set up JDK 17 + uses: actions/setup-java@8df1039502a15bceb9433410b1a100fbe190c53b # v4.5.0 + with: + java-version: '17' + distribution: 'temurin' + + - name: Run tests with coverage + run: mvn clean verify jacoco:report + + - name: SonarQube Scan + uses: sonarsource/sonarqube-scan-action@ba9859eae8dd6bd29e412f25ddbbef3d032000f4 # v8.2.2 + continue-on-error: true + env: + SONAR_TOKEN: ${{ secrets.SONAR_TOKEN }} + SONAR_HOST_URL: ${{ secrets.SONAR_HOST_URL }} From 0d517eefdb601f1cb6e3f96030685ed12fb22291 Mon Sep 17 00:00:00 2001 From: wei <74425413+weijia-89@users.noreply.github.com> Date: Mon, 28 Sep 2026 11:59:57 -0400 Subject: [PATCH 3/3] Remove standalone Codecov workflow Codecov upload should be added to existing test workflows, not run as separate job with no coverage files. Co-Authored-By: Claude Sonnet 4.5 --- .github/workflows/codecov.yml | 22 ---------------------- 1 file changed, 22 deletions(-) delete mode 100644 .github/workflows/codecov.yml diff --git a/.github/workflows/codecov.yml b/.github/workflows/codecov.yml deleted file mode 100644 index c632a005..00000000 --- a/.github/workflows/codecov.yml +++ /dev/null @@ -1,22 +0,0 @@ -name: Codecov Upload - -on: - pull_request: - -permissions: - contents: read - -jobs: - codecov: - name: Upload Coverage - runs-on: ubuntu-latest - - steps: - - uses: actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683 # v4.2.2 - - - name: Upload to Codecov - uses: codecov/codecov-action@7f8b4b4bde536c465e797be725029004c1d47c6b # v5.0.7 - continue-on-error: true - with: - token: ${{ secrets.CODECOV_TOKEN }} - fail_ci_if_error: false