CLP-1097 Migrate Orchestrator downloads to the JFrog Edge node for sonar-java - #6257
Conversation
|
🔗 Commit SHA: a01053a | Docs | View more details | Give us feedback! |
|
❌ Ruling needs updating. A fix PR has been created: #6290 Please review and merge it into your branch. |
e92a8b1 to
b98d8d5
Compare
| with: | ||
| version: 2026.9.17 | ||
| - uses: SonarSource/ci-github-actions/build-maven@v2 | ||
| - uses: SonarSource/ci-github-actions/build-maven@c3a85ac3a2f67f86966e2fb1fdf9a7c1bdc997dc # 2.2.0 |
There was a problem hiding this comment.
For our actions we should point to the tag.
External actions point to hash.
There was a problem hiding this comment.
Superseded by the correction below.
There was a problem hiding this comment.
Correction to my earlier reply: the final PR keeps the existing @v2 references. The v2 branch currently includes the 2.2.0 release and its Edge support. The final diff only adds the Edge repox-url inputs.
b98d8d5 to
75ea530
Compare
75ea530 to
a01053a
Compare
Code Review ✅ Approved 3 closed / 3 findings🟡 Medium risk · CI dependency and Orchestrator downloads now resolve through a different artifact endpoint. Routes Maven dependency resolution and Orchestrator downloads through the JFrog Edge node by configuring ✅ 3 closed✅ Edge Case: Probe curl has no timeout, so the 2-minute bound can be exceeded
✅ Quality: unified-dogfooding.yml still uses build-maven@v2 without the Edge repox-url
✅ Quality: PR description no longer matches the code: token-wait and #353 were dropped
Review coverage🧪 Functional validation 1 of 1 objectives covered 📋 Rules No rules evaluated 🤖 Auto-approval Not enabled · Set up Implementation Status ✅ 1 of 1 objectives covered✅ CLP-918 - 1 of 1 objectives coveredThis PR covers migrating the Orchestrator's SonarQube download source to the JFrog Edge node. ✅ 1 covered here
OptionsAuto-apply is off → Gitar will not commit updates to this branch. Comment with these commands to change the behavior for this request:
Was this helpful? React with 👍 / 👎 | Gitar |
|





Part of CLP-918
Summary
https://repox-internal.dev.sonar.build).build-mavenandconfig-maveninbuild.ymlandunified-dogfooding.ymlreceive the Edgerepox-url. The existing shared action references stay at@v2.ARTIFACTORY_URLandARTIFACTORY_ACCESS_TOKENfrom the configured environment. Master already containssonar-scanner-integration-tester1.3.0.1396, whose bundled Orchestrator is 6.4.3; this PR no longer changes that dependency.Validation
repox-urlinputs across the two workflows;git diff --checkpasses.@v2head: build, Windows unit and scanner integration tests, plugin QA, ruling QA, andTest Analyzepassed. The first analysis attempt received HTTP 503 from the Sonar server at/api/server/version; the rerun passed.