Skip to content

ci: reliable static-analysis gates and SARIF annotations - #1483

Draft
joaodinissf wants to merge 1 commit into
masterfrom
ci/static-analysis-sarif
Draft

joaodinissf wants to merge 1 commit into
masterfrom
ci/static-analysis-sarif

Conversation

@joaodinissf

@joaodinissf joaodinissf commented Aug 3, 2026 •

Copy link
Copy Markdown
Collaborator

Followed by #1484

Why the change

Static analysis in CI now fails whenever an analyser fails or produces an unusable report, and its findings appear as inline annotations on the pull request.

Special things to note

  • The pmd and checkstyle jobs are replaced by lint and spotbugs. The master ruleset requires a check named pmd, so it has to be updated when this merges.
  • Source locations in the merged SARIF are rewritten to repository-relative paths, because GitHub ignores custom URI bases.
  • Merge this first; ci: scope pull-request analysis and avoid redundant compilation #1484 builds on it.

Change outline

 verify.yml jobs
-  pmd                   PMD + CPD, no compile
-  checkstyle
+  lint                  compile → PMD, CPD, Checkstyle → validate reports → merged SARIF → gate
+  spotbugs              compile → SpotBugs → validate reports → merged SARIF → gate
+  analysis-regression   report, merge, mutation and scope fixtures
   line-endings
   maven-verify          build and tests

The gate, in .github/scripts/sarif.sh:

every expected module's report
  valid SARIF, analysis succeeded, no error notifications     else fail
merge
  repository-relative source paths, rules and taxonomies unioned
  conflicting or unsupported metadata                         → fail
results > 0 → fail          (Code Scanning upload never gates)
CPD: XML parsed structurally; malformed report or error      → fail

Checked on this head: 112 report, merge and process cases and 8 mutation checks locally; all five CI jobs green (366 tests, 0 failures); a real SpotBugs finding shown as an inline annotation on a fork PR.

🤖 Generated with Claude Code

@joaodinissf joaodinissf changed the title ci/static analysis sarif ci: fast static analysis with early-fail lint + inline SARIF (PMD/Checkstyle/SpotBugs) Aug 3, 2026
@joaodinissf
joaodinissf force-pushed the ci/static-analysis-sarif branch from 9727257 to 3e46952 Compare September 22, 2026 22:40
@joaodinissf
joaodinissf force-pushed the ci/static-analysis-sarif branch from 3e46952 to 6a5e509 Compare September 26, 2026 09:24
Run PMD/Checkstyle/CPD and SpotBugs in separate analysis lanes. Preserve
Maven failure status with --fail-at-end and validate every expected raw
and merged report before counting findings. Require successful invocation
metadata for PMD and SpotBugs; Checkstyle omits it, so retain its valid
format while preserving the producer process status. Parse CPD XML and
reject processing errors instead of counting lines that resemble findings.

Resolve each run's URI base chains and emit repository-relative artifact
URIs, including secondary locations. A real GitHub upload accepted preserved
base IDs but recorded package-relative paths that did not match the source
tree. Explicit relative URIs remove that consumer dependency. Resolve rule
indices before combining descriptors, preserve SpotBugs taxonomies, and
reject conflicting or unsupported metadata instead of discarding it.

Exercise extracted workflow blocks with real producer reports and negative
fixtures, and run targeted mutation checks in a fast CI job. Cover absent
reports, malformed input, incomplete analysis, notification errors, merged
output corruption, source locations, descriptors and producer exit status.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
@joaodinissf
joaodinissf force-pushed the ci/static-analysis-sarif branch from 6a5e509 to 230afc4 Compare September 26, 2026 12:02
@joaodinissf joaodinissf changed the title ci: fast static analysis with early-fail lint + inline SARIF (PMD/Checkstyle/SpotBugs) ci: reliable static-analysis gates and SARIF annotations Sep 26, 2026

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant