You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

如何在Concourse中仅获取Git分支的PR以进行代码扫描?

针对Git PR执行Concourse代码扫描的配置方案

原配置仅能拉取指定分支代码,无法监听和获取PR内容,要实现PR专属代码扫描,可根据Git服务类型选择以下实用方案:

方案1:GitHub仓库专用配置

使用Concourse内置的github-pr资源类型,专门适配GitHub的PR场景,配置示例:

- name: databricks-repo-pr
  type: github-pr
  icon: github-circle
  source:
    repository: your-org/your-repo  # 替换为实际GitHub仓库路径(格式:用户名/仓库名)
    private_key: ((key))  # 保留原有SSH私钥用于拉取代码
    base_branch: master  # 指定监听的目标分支(PR要合并到的分支)
    ignore_drafts: true  # 可选:忽略草稿状态的PR,仅处理正式PR
    access_token: ((github-access-token))  # 可选:若需要获取PR详情(如标签、评论),添加带读取权限的GitHub Token

该资源会自动监听所有向master分支提交的PR,PR有代码更新时自动触发流水线,拉取PR的合并预览代码(或PR头部分支代码,可通过配置调整),直接用于代码扫描。

方案2:通用Git服务适配(GitLab/Bitbucket等)

针对GitLab、Bitbucket等其他Git服务,使用对应服务的专用资源类型:

GitLab示例(使用gitlab-mr资源)

- name: databricks-repo-mr
  type: gitlab-mr
  icon: gitlab
  source:
    uri: xyz.git
    private_key: ((key))
    project: your-org/your-project  # GitLab项目路径
    target_branch: master  # PR目标分支
    access_token: ((gitlab-access-token))  # 带读取合并请求权限的GitLab Token

Bitbucket示例(使用bitbucket-pr资源)

- name: databricks-repo-pr
  type: bitbucket-pr
  icon: bitbucket
  source:
    uri: xyz.git
    private_key: ((key))
    repo_slug: your-repo  # Bitbucket仓库名
    owner: your-org  # Bitbucket组织/用户名
    target_branch: master
    username: ((bitbucket-username))
    password: ((bitbucket-app-password))

流水线中接入扫描任务

无论使用哪种资源,都可以在流水线job中配置触发扫描:

jobs:
- name: pr-code-scan
  plan:
  - get: databricks-repo-pr  # 对应上面配置的资源名
    trigger: true  # PR更新时自动触发扫描
  - task: run-code-scan
    config:
      platform: linux
      image_resource:
        type: docker-image
        source: {repository: your-scanner-image}  # 替换为你的代码扫描工具镜像(如SonarQube、Checkmarx等)
      inputs:
      - name: databricks-repo-pr
      run:
        path: /bin/sh
        args:
        - -c
        - |
          cd databricks-repo-pr
          # 执行你的代码扫描命令,示例:
          sonar-scanner -Dsonar.projectKey=databricks-repo -Dsonar.sources=.

关键注意事项

  • 确保Concourse已安装对应资源类型:github-pr为Concourse内置资源,gitlab-mr/bitbucket-pr可能需要额外安装资源镜像
  • 权限配置:私钥或Token需具备拉取代码和读取PR/合并请求信息的权限
  • 可选过滤:可添加label_filter配置,仅扫描带有指定标签的PR(如needs-scan),减少不必要的触发

内容的提问来源于stack exchange,提问作者Sanjay

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.26 13:45:23