ci: reliable static-analysis gates and SARIF annotations - #1483
Draft
joaodinissf wants to merge 1 commit into
Draft
joaodinissf wants to merge 1 commit into
joaodinissf wants to merge 1 commit into
Conversation
joaodinissf
force-pushed
the
ci/static-analysis-sarif
branch
from
September 22, 2026 22:40
9727257 to
3e46952
Compare
This was referenced Sep 22, 2026
joaodinissf
force-pushed
the
ci/static-analysis-sarif
branch
from
September 26, 2026 09:24
3e46952 to
6a5e509
Compare
Run PMD/Checkstyle/CPD and SpotBugs in separate analysis lanes. Preserve Maven failure status with --fail-at-end and validate every expected raw and merged report before counting findings. Require successful invocation metadata for PMD and SpotBugs; Checkstyle omits it, so retain its valid format while preserving the producer process status. Parse CPD XML and reject processing errors instead of counting lines that resemble findings. Resolve each run's URI base chains and emit repository-relative artifact URIs, including secondary locations. A real GitHub upload accepted preserved base IDs but recorded package-relative paths that did not match the source tree. Explicit relative URIs remove that consumer dependency. Resolve rule indices before combining descriptors, preserve SpotBugs taxonomies, and reject conflicting or unsupported metadata instead of discarding it. Exercise extracted workflow blocks with real producer reports and negative fixtures, and run targeted mutation checks in a fast CI job. Cover absent reports, malformed input, incomplete analysis, notification errors, merged output corruption, source locations, descriptors and producer exit status. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
joaodinissf
force-pushed
the
ci/static-analysis-sarif
branch
from
September 26, 2026 12:02
6a5e509 to
230afc4
Compare
This branch has not been deployed
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Followed by #1484
Why the change
Static analysis in CI now fails whenever an analyser fails or produces an unusable report, and its findings appear as inline annotations on the pull request.
Special things to note
pmdandcheckstylejobs are replaced bylintandspotbugs. The master ruleset requires a check namedpmd, so it has to be updated when this merges.Change outline
The gate, in
.github/scripts/sarif.sh:Checked on this head: 112 report, merge and process cases and 8 mutation checks locally; all five CI jobs green (366 tests, 0 failures); a real SpotBugs finding shown as an inline annotation on a fork PR.
🤖 Generated with Claude Code