GitHub Actions中SonarQube PR分析未仅扫描变更文件求助
问题:GitHub Actions执行SonarQube PR分析时无法仅扫描变更文件
目标是仅扫描PR提交中的变更文件,但实际扫描时出现0 files indexed,无法正确识别变更文件。以下是相关配置和日志:
原配置信息
workflow.yml
name: SCA-TEST0306 - DIFF ONLY on: pull_request: branches: - TEST-0306 jobs: build: runs-on: ubuntu-latest steps: - name: Checkout pull request branch uses: actions/checkout@v2 with: ref: ${{ github.event.pull_request.head.ref }} - name: Fetch repository run: git fetch - name: Get diff of code changes run: git diff --name-only origin/${{ github.event.pull_request.base.ref }} -- ${{ github.event.pull_request.head.ref }} > files_changed.txt - name: Sonar Scan uses: docker://sonarsource/sonar-scanner-cli:latest env: GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }} SONAR_TOKEN: ${{ secrets.SONAR_TOKEN }} SONAR_HOST_URL: ${{ secrets.SONAR_HOST_URL }}
SonarQube配置文件
sonar.projectKey=********** sonar.exclusions=force-app/main/default/staticresources/**, force-app/main/default/contentassets/**, lib/**, config/**, LICENSE/**, Release Folders/**, scripts/**, **/.png**/.jgp,**/.jpeg,**/.jar,**/.svg,**/.tar,**/.zip sonar.inclusions=$(cat files_changed.txt | tr '\n' ',') SONAR_RUNNER_OPTS="-Xmx3062m -XX:MaxPermSize=512m -XX:ReservedCodeCacheSize=128m"
扫描日志片段
INFO: SCM collecting changed files in the branch (done) | time=224ms INFO: Indexing files... INFO: Project configuration: INFO: Included sources: $(cat files_changed.txt | tr ' ' ', ') INFO: Excluded sources: force-app/main/default/staticresources/**, force-app/main/default/contentassets/**, lib/**, config/**, LICENSE/**, Release Folders/**, scripts/**, **/.png**/.jgp, **/.jpeg, **/.jar, **/.svg, **/.tar, **/.zip INFO: Excluded sources for coverage: sonar.coverage.exclusions=**/*.* INFO: 0 files indexed INFO: 250910 files ignored because of inclusion/exclusion patterns INFO: 0 files ignored because of scm ignore settings
错误原因分析
- Sonar配置无法解析Shell命令:
sonar.inclusions的值被当作字面量$(cat files_changed.txt | tr '\n' ',')处理,SonarQube不会执行Shell命令,因此无法读取实际的变更文件列表,导致无文件被索引。 - Git操作配置错误:
actions/checkout@v2默认是浅克隆,缺少完整分支历史,Git diff无法正确跨分支对比变更。- Git diff命令写法错误,
origin/base -- head的格式无法正确获取PR分支与基准分支的差异文件。
- 未利用SonarQube原生PR分析能力:SonarQube针对PR场景有内置逻辑,可自动识别变更文件,无需手动维护包含列表。
修正方案
方案1:使用SonarQube原生PR分析模式(推荐)
直接利用SonarQube的PR分析参数,自动扫描变更文件,无需手动处理diff:
name: SCA-TEST0306 - DIFF ONLY on: pull_request: branches: - TEST-0306 jobs: build: runs-on: ubuntu-latest steps: - name: Checkout code uses: actions/checkout@v4 with: fetch-depth: 0 # 拉取完整仓库历史,用于SCM对比 - name: Sonar Scan (PR Analysis) uses: docker://sonarsource/sonar-scanner-cli:latest env: GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }} SONAR_TOKEN: ${{ secrets.SONAR_TOKEN }} SONAR_HOST_URL: ${{ secrets.SONAR_HOST_URL }} with: args: > -Dsonar.projectKey=********** -Dsonar.exclusions=force-app/main/default/staticresources/**,force-app/main/default/contentassets/**,lib/**,config/**,LICENSE/**,Release Folders/**,scripts/**,**/*.png,**/*.jpg,**/*.jpeg,**/*.jar,**/*.svg,**/*.tar,**/*.zip -Dsonar.pullrequest.key=${{ github.event.pull_request.number }} -Dsonar.pullrequest.base=${{ github.event.pull_request.base.ref }} -Dsonar.pullrequest.head=${{ github.event.pull_request.head.ref }} -Dsonar.pullrequest.github.repository=${{ github.repository }}
方案2:手动传递变更文件列表(不推荐)
若需手动处理diff,需确保Shell命令被正确解析后传递给SonarQube:
name: SCA-TEST0306 - DIFF ONLY on: pull_request: branches: - TEST-0306 jobs: build: runs-on: ubuntu-latest steps: - name: Checkout code uses: actions/checkout@v4 with: fetch-depth: 0 # 拉取完整历史 - name: Fetch base branch run: git fetch origin ${{ github.event.pull_request.base.ref }} - name: Get diff of code changes run: | # 用三点语法获取两个分支的变更文件 git diff --name-only origin/${{ github.event.pull_request.base.ref }}...${{ github.event.pull_request.head.ref }} > files_changed.txt # 处理空文件情况,避免inclusions为空导致扫描全量文件 if [ ! -s files_changed.txt ]; then echo "No files changed" > files_changed.txt fi - name: Sonar Scan uses: docker://sonarsource/sonar-scanner-cli:latest env: GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }} SONAR_TOKEN: ${{ secrets.SONAR_TOKEN }} SONAR_HOST_URL: ${{ secrets.SONAR_HOST_URL }} with: args: > -Dsonar.projectKey=********** -Dsonar.exclusions=force-app/main/default/staticresources/**,force-app/main/default/contentassets/**,lib/**,config/**,LICENSE/**,Release Folders/**,scripts/**,**/*.png,**/*.jpg,**/*.jpeg,**/*.jar,**/*.svg,**/*.tar,**/*.zip -Dsonar.inclusions=$(cat files_changed.txt | tr '\n' ',')
关键修正点说明
- 完整克隆仓库:
fetch-depth: 0确保获取完整历史,让Git和SonarQube的SCM功能能正确识别变更。 - 正确的Git Diff命令:使用
origin/base...head(三点语法)对比两个分支的最新提交差异,准确获取PR中的变更文件。 - 参数直接传递:通过
args传递Sonar配置,Shell会解析$(cat files_changed.txt)命令,将实际文件列表传给SonarQube。 - 原生PR模式:
sonar.pullrequest.*参数自动启用PR分析,SonarQube会自动只扫描变更文件,无需手动维护包含列表,更稳定可靠。
内容的提问来源于stack exchange,提问作者Sai K
相关产品推荐
相关产品推荐

