You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

GitHub Actions中SonarQube PR分析未仅扫描变更文件求助

问题:GitHub Actions执行SonarQube PR分析时无法仅扫描变更文件

目标是仅扫描PR提交中的变更文件,但实际扫描时出现0 files indexed,无法正确识别变更文件。以下是相关配置和日志:

原配置信息

workflow.yml

name: SCA-TEST0306 - DIFF ONLY
on:
  pull_request:
    branches:
      - TEST-0306

jobs:
  build:
    runs-on: ubuntu-latest
    steps:      
    - name: Checkout pull request branch
      uses: actions/checkout@v2
      with:
        ref: ${{ github.event.pull_request.head.ref }}
        
    - name: Fetch repository
      run: git fetch
        
    - name: Get diff of code changes
      run: git diff --name-only origin/${{ github.event.pull_request.base.ref }} -- ${{ github.event.pull_request.head.ref }} > files_changed.txt
    
    - name: Sonar Scan
      uses: docker://sonarsource/sonar-scanner-cli:latest
      env:
          GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }}
          SONAR_TOKEN: ${{ secrets.SONAR_TOKEN }}
          SONAR_HOST_URL: ${{ secrets.SONAR_HOST_URL }}

SonarQube配置文件

sonar.projectKey=**********
sonar.exclusions=force-app/main/default/staticresources/**, force-app/main/default/contentassets/**, lib/**, config/**, LICENSE/**, Release Folders/**, scripts/**, **/.png**/.jgp,**/.jpeg,**/.jar,**/.svg,**/.tar,**/.zip
sonar.inclusions=$(cat files_changed.txt | tr '\n' ',')
SONAR_RUNNER_OPTS="-Xmx3062m -XX:MaxPermSize=512m -XX:ReservedCodeCacheSize=128m"

扫描日志片段

INFO: SCM collecting changed files in the branch (done) | time=224ms
INFO: Indexing files...
INFO: Project configuration:
INFO:   Included sources: $(cat files_changed.txt | tr '
' ', ')
INFO:   Excluded sources: force-app/main/default/staticresources/**, force-app/main/default/contentassets/**, lib/**, config/**, LICENSE/**, Release Folders/**, scripts/**, **/.png**/.jgp, **/.jpeg, **/.jar, **/.svg, **/.tar, **/.zip
INFO:   Excluded sources for coverage: sonar.coverage.exclusions=**/*.*
INFO: 0 files indexed
INFO: 250910 files ignored because of inclusion/exclusion patterns
INFO: 0 files ignored because of scm ignore settings

错误原因分析

  1. Sonar配置无法解析Shell命令:sonar.inclusions的值被当作字面量$(cat files_changed.txt | tr '\n' ',')处理,SonarQube不会执行Shell命令,因此无法读取实际的变更文件列表,导致无文件被索引。
  2. Git操作配置错误:
    • actions/checkout@v2默认是浅克隆,缺少完整分支历史,Git diff无法正确跨分支对比变更。
    • Git diff命令写法错误,origin/base -- head的格式无法正确获取PR分支与基准分支的差异文件。
  3. 未利用SonarQube原生PR分析能力:SonarQube针对PR场景有内置逻辑,可自动识别变更文件,无需手动维护包含列表。

修正方案

方案1:使用SonarQube原生PR分析模式(推荐)

直接利用SonarQube的PR分析参数,自动扫描变更文件,无需手动处理diff:

name: SCA-TEST0306 - DIFF ONLY
on:
  pull_request:
    branches:
      - TEST-0306

jobs:
  build:
    runs-on: ubuntu-latest
    steps:      
    - name: Checkout code
      uses: actions/checkout@v4
      with:
        fetch-depth: 0  # 拉取完整仓库历史,用于SCM对比

    - name: Sonar Scan (PR Analysis)
      uses: docker://sonarsource/sonar-scanner-cli:latest
      env:
          GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }}
          SONAR_TOKEN: ${{ secrets.SONAR_TOKEN }}
          SONAR_HOST_URL: ${{ secrets.SONAR_HOST_URL }}
      with:
        args: >
          -Dsonar.projectKey=**********
          -Dsonar.exclusions=force-app/main/default/staticresources/**,force-app/main/default/contentassets/**,lib/**,config/**,LICENSE/**,Release Folders/**,scripts/**,**/*.png,**/*.jpg,**/*.jpeg,**/*.jar,**/*.svg,**/*.tar,**/*.zip
          -Dsonar.pullrequest.key=${{ github.event.pull_request.number }}
          -Dsonar.pullrequest.base=${{ github.event.pull_request.base.ref }}
          -Dsonar.pullrequest.head=${{ github.event.pull_request.head.ref }}
          -Dsonar.pullrequest.github.repository=${{ github.repository }}

方案2:手动传递变更文件列表(不推荐)

若需手动处理diff,需确保Shell命令被正确解析后传递给SonarQube:

name: SCA-TEST0306 - DIFF ONLY
on:
  pull_request:
    branches:
      - TEST-0306

jobs:
  build:
    runs-on: ubuntu-latest
    steps:      
    - name: Checkout code
      uses: actions/checkout@v4
      with:
        fetch-depth: 0  # 拉取完整历史

    - name: Fetch base branch
      run: git fetch origin ${{ github.event.pull_request.base.ref }}

    - name: Get diff of code changes
      run: |
        # 用三点语法获取两个分支的变更文件
        git diff --name-only origin/${{ github.event.pull_request.base.ref }}...${{ github.event.pull_request.head.ref }} > files_changed.txt
        # 处理空文件情况,避免inclusions为空导致扫描全量文件
        if [ ! -s files_changed.txt ]; then
          echo "No files changed" > files_changed.txt
        fi

    - name: Sonar Scan
      uses: docker://sonarsource/sonar-scanner-cli:latest
      env:
          GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }}
          SONAR_TOKEN: ${{ secrets.SONAR_TOKEN }}
          SONAR_HOST_URL: ${{ secrets.SONAR_HOST_URL }}
      with:
        args: >
          -Dsonar.projectKey=**********
          -Dsonar.exclusions=force-app/main/default/staticresources/**,force-app/main/default/contentassets/**,lib/**,config/**,LICENSE/**,Release Folders/**,scripts/**,**/*.png,**/*.jpg,**/*.jpeg,**/*.jar,**/*.svg,**/*.tar,**/*.zip
          -Dsonar.inclusions=$(cat files_changed.txt | tr '\n' ',')

关键修正点说明

  1. 完整克隆仓库:fetch-depth: 0确保获取完整历史,让Git和SonarQube的SCM功能能正确识别变更。
  2. 正确的Git Diff命令:使用origin/base...head(三点语法)对比两个分支的最新提交差异,准确获取PR中的变更文件。
  3. 参数直接传递:通过args传递Sonar配置,Shell会解析$(cat files_changed.txt)命令,将实际文件列表传给SonarQube。
  4. 原生PR模式:sonar.pullrequest.*参数自动启用PR分析,SonarQube会自动只扫描变更文件,无需手动维护包含列表,更稳定可靠。

内容的提问来源于stack exchange,提问作者Sai K

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.29 07:07:13