如何在SonarCloud中正确配置托管于GitHub的Java+Angular单体仓库代码分析?
Let's break down what's going wrong with your current setup and walk through the correct steps to get both your Java backend and Angular frontend analyzed on SonarCloud via GitHub Actions.
1. First: Validate SonarCloud & GitHub Pre-Requisites
Before diving into config fixes, confirm these foundational steps are done:
- Link your GitHub account to SonarCloud, and ensure your
softwaremagicoorganization exists there. - Create separate projects in SonarCloud for your backend (
kendo-tournament-backend) and frontend (kendo-tournament-frontend)—the project keys must exactly match what you reference in your configs. - Double-check that your
SONAR_TOKENis added as a GitHub Repository Secret (under Settings > Secrets and variables > Actions > New repository secret). This token should be generated from your SonarCloud organization or project settings.
2. Fix Your GitHub Actions Workflow (build.yml)
Your current workflow has two critical issues preventing analysis from running correctly:
Issue 1: Invalid with parameter in the Maven run step
The run step does not support a with block. To target your backend directory, either cd into it first or pass the project base dir as a Maven property.
Issue 2: Frontend analysis lacks Angular-specific configuration
The SonarCloud GitHub Action needs clear guidance on where your Angular source lives, and which files to exclude.
Here's the corrected workflow file:
name: Build & SonarCloud Analysis on: push: branches: - master pull_request: types: [opened, synchronize, reopened] jobs: sonarcloud: name: SonarCloud Analysis runs-on: ubuntu-latest steps: - uses: actions/checkout@v4 with: fetch-depth: 0 # Required for full commit history analysis # Backend (Java/Maven) Analysis - name: Set up JDK 11 uses: actions/setup-java@v4 with: java-version: '11' distribution: 'temurin' - name: Cache SonarCloud packages uses: actions/cache@v3 with: path: ~/.sonar/cache key: ${{ runner.os }}-sonar restore-keys: ${{ runner.os }}-sonar - name: Cache Maven packages uses: actions/cache@v3 with: path: ~/.m2/repository key: ${{ runner.os }}-maven-${{ hashFiles('backend/**/pom.xml') }} restore-keys: ${{ runner.os }}-maven - name: Analyze Backend env: GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }} SONAR_TOKEN: ${{ secrets.SONAR_TOKEN }} run: | cd ./backend/ mvn -B verify org.sonarsource.scanner.maven:sonar-maven-plugin:sonar \ -Dsonar.projectKey=kendo-tournament-backend \ -Dsonar.organization=softwaremagico \ -Dsonar.host.url=https://sonarcloud.io # Frontend (Angular) Analysis - name: Set up Node.js for Angular uses: actions/setup-node@v4 with: node-version: 18 # Match your Angular project's required Node version cache: 'npm' cache-dependency-path: frontend/package-lock.json - name: Install Frontend Dependencies run: | cd ./frontend/ npm ci - name: Run ESLint (Optional but recommended) run: | cd ./frontend/ ng lint --format json > eslint-report.json - name: Analyze Frontend uses: SonarSource/sonarcloud-github-action@v2.2.0 env: GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }} SONAR_TOKEN: ${{ secrets.SONAR_TOKEN }} with: projectBaseDir: ./frontend/
3. Update Frontend sonar-project.properties
Your current frontend config is missing key settings for Angular. Replace frontend/sonar-project.properties with this:
sonar.projectKey=kendo-tournament-frontend sonar.organization=softwaremagico sonar.projectName=Kendo Tournament Manager Frontend sonar.projectVersion=1.0 sonar.sources=src sonar.exclusions=node_modules/**, dist/**, src/test/** sonar.javascript.eslint.reportPaths=eslint-report.json sonar.sourceEncoding=UTF-8 sonar.host.url=https://sonarcloud.io
sonar.sources=src: Points directly to your Angular source code directorysonar.exclusions: Filters out irrelevant folders likenode_modules,dist, and test files (adjust if you want test coverage analyzed)sonar.javascript.eslint.reportPaths: Links your ESLint results to SonarCloud for richer analysis
4. Confirm Backend pom.xml Config
Your existing backend pom.xml properties are valid, but you can keep these for clarity:
<properties> <sonar.organization>softwaremagico</sonar.organization> <sonar.host.url>https://sonarcloud.io</sonar.host.url> </properties>
5. Test the Workflow
- Push a commit to
masteror open a pull request to trigger the workflow. - Navigate to your GitHub repo's Actions tab to check if the workflow runs without errors.
- If failures occur, click into the run logs to debug (common issues: invalid token, missing SonarCloud project, incorrect directory paths).
内容的提问来源于stack exchange,提问作者King Midas

