diff --git a/Jenkinsfile b/Jenkinsfile index 1fd34b0..6bc2a2c 100644 --- a/Jenkinsfile +++ b/Jenkinsfile @@ -127,6 +127,49 @@ spec: } } } + stage('Run quality gate') { + steps { + container('tester') { + sh ''' + set -eu + apt-get update >/dev/null + apt-get install -y --no-install-recommends jq python3 ripgrep >/dev/null + mkdir -p build + set +e + bash scripts/check.sh + gate_rc=$? + set -e + if [ ! -f build/go-test.json ]; then + : > build/go-test.json + fi + tests_total="$(jq -s '[.[] | select(.Test != null and (.Action=="pass" or .Action=="fail" or .Action=="skip"))] | length' build/go-test.json 2>/dev/null || echo 0)" + tests_failed="$(jq -s '[.[] | select(.Test != null and .Action=="fail")] | length' build/go-test.json 2>/dev/null || echo 0)" + tests_skipped="$(jq -s '[.[] | select(.Test != null and .Action=="skip")] | length' build/go-test.json 2>/dev/null || echo 0)" + tests_errors="$(jq -s '[.[] | select(.Test == null and .Action=="fail")] | length' build/go-test.json 2>/dev/null || echo 0)" + tests_passed=$((tests_total - tests_failed - tests_skipped)) + if [ "${tests_passed}" -lt 0 ]; then + tests_passed=0 + fi + coverage_percent="$(jq -r '.coverage_percent // 0' build/quality-summary.json 2>/dev/null || echo 0)" + source_files_total="$(jq -r '.source_files_total // 0' build/quality-summary.json 2>/dev/null || echo 0)" + over_500="$(jq -r '.source_lines_over_500 // 0' build/quality-summary.json 2>/dev/null || echo 0)" + cat > build/test-summary.json < build/test.exitcode + ''' + } + } + } stage('Collect SonarQube and supply-chain evidence') { steps { container('quality-tools') { @@ -138,6 +181,8 @@ spec: "-Dsonar.login=${SONARQUBE_TOKEN}" "-Dsonar.projectKey=${SONARQUBE_PROJECT_KEY}" "-Dsonar.projectName=${SONARQUBE_PROJECT_KEY}" + "-Dsonar.qualitygate.wait=true" + "-Dsonar.qualitygate.timeout=300" "-Dsonar.sources=." "-Dsonar.exclusions=**/.git/**,**/build/**,**/dist/**,**/node_modules/**,**/.venv/**,**/__pycache__/**,**/coverage/**,**/test-results/**,**/playwright-report/**" "-Dsonar.test.inclusions=**/tests/**,**/testing/**,**/*_test.go,**/*.test.ts,**/*.test.tsx,**/*.spec.ts,**/*.spec.tsx" @@ -174,14 +219,11 @@ EOF } } } - stage('Run quality gate') { + stage('Read quality evidence') { steps { container('tester') { sh ''' set -eu - apt-get update >/dev/null - apt-get install -y --no-install-recommends jq python3 ripgrep >/dev/null - mkdir -p build python3 - <<'PY' import base64 import json @@ -227,37 +269,7 @@ if not ironbank_report.exists(): ironbank_report.parent.mkdir(parents=True, exist_ok=True) ironbank_report.write_text(json.dumps(ironbank_payload, indent=2, sort_keys=True) + "\\n", encoding="utf-8") PY - set +e - bash scripts/check.sh - gate_rc=$? - set -e - if [ ! -f build/go-test.json ]; then - : > build/go-test.json - fi - tests_total="$(jq -s '[.[] | select(.Test != null and (.Action=="pass" or .Action=="fail" or .Action=="skip"))] | length' build/go-test.json 2>/dev/null || echo 0)" - tests_failed="$(jq -s '[.[] | select(.Test != null and .Action=="fail")] | length' build/go-test.json 2>/dev/null || echo 0)" - tests_skipped="$(jq -s '[.[] | select(.Test != null and .Action=="skip")] | length' build/go-test.json 2>/dev/null || echo 0)" - tests_errors="$(jq -s '[.[] | select(.Test == null and .Action=="fail")] | length' build/go-test.json 2>/dev/null || echo 0)" - tests_passed=$((tests_total - tests_failed - tests_skipped)) - if [ "${tests_passed}" -lt 0 ]; then - tests_passed=0 - fi - coverage_percent="$(jq -r '.coverage_percent // 0' build/quality-summary.json 2>/dev/null || echo 0)" - source_files_total="$(jq -r '.source_files_total // 0' build/quality-summary.json 2>/dev/null || echo 0)" - over_500="$(jq -r '.source_lines_over_500 // 0' build/quality-summary.json 2>/dev/null || echo 0)" - cat > build/test-summary.json < build/test.exitcode + ''' } }