This image is used for javascript and typescript projects, and contains the jq library to allow PR features in bitbucket pipelines, plus the newest version of npm to allow npm ci, which is a slightly faster way to npm install for CI builds.
Build:
docker build -t sonar-scanner .
Interact:
docker run -it sonar-scanner bash
This image is meant for use as part of a CI build pipeline. Here is an example on how to use the image with Bitbucket Pipeline:
# Sonar code coverage for javascript/typescript project, tested with Angular CLI
# -----
# coverage is specific for the sonar modules that sonarcloud uses
# https://docs.sonarqube.org/display/PLUG/TypeScript+Test+Execution+and+Coverage+Results+Import
# https://docs.sonarqube.org/display/PLUG/JavaScript+Coverage+Results+Import
# -----
pipelines:
default:
master:
- step:
name: Build Angular
image: itminds/sonar-runner
caches:
- node
script:
# Install and test js/ts. This script can be replaced with specific install/test commands
- bash node-coverage
# Build project
- npm run build
# Update sonarcloud stats
- sonar-scanner -Dsonar.login=${SONARQUBE_TOKEN}
-Dsonar.typescript.lcov.reportPaths="$BITBUCKET_CLONE_DIR/coverage/lcov.info"
-Dsonar.javascript.lcov.reportPaths="$BITBUCKET_CLONE_DIR/coverage/lcov.info"
This example features a single step build for javascript/typescript projects with Sonar analysis and coverage. The sonar-scanner settings need to be configured in sonar-scanner.properties in the root folder at project start, to specify meta information about the project as well as the location of test coverage, excluded files and test inclusions. The $SONARQUBE token is defined as a global environment variable for the IT Minds Bitbucket. Additional parameters can also be appended directly to the sonar-scanner call as shown in the example (where it is used to make use of Bitbucket environment variables in the report paths).
Project specific Sonar settings need to be added in sonar-scanner.properties in the root directory of your project. This example shows how to specify projectKey which is used by Sonarcloud to uniquely identify your project, sources which specifies the source directory of your project, exclusions and test.inclusions which are used to specify folders that Sonar needs to ignore or use for test data.
All official Sonarqube parameters can be found at docs.sonarqube.org, but your project might require parameters that are SonarQube plugin specific.
# https://docs.sonarqube.org/display/SONAR/Analysis+Parameters
# ----- Mandatory Parameters -----
# Project Configuration
sonar.projectKey=sonar-ng-test
sonar.sources=src
# ----- Optional Parameters -----
# Exclusions / Inclusions
sonar.exclusions="**/node_modules/**,**/coverage/**,**/dist/**"
sonar.test.inclusions="**/sonarqube-xunit-test/**,**/__tests__/**"
All the scripts are added to the image PATH, and are accessible through bash script-name
node-coverage
is used to run npm or yarn test and install in all directories containing a package.json, it will prefer yarn if available. Make sure to enable code coverage and specify the coverage report paths in the project ymlgit-merge-master
is used on Bitbucket to merge master into the current branch that is being build. This is meant to be used in combination with is-pr to build and test on the result of the pull request.is-pr
is used on Bitbucket to check if there is an open pull request for the current branch being build. See the PR Example.This example features the complete yml for the sonar ng test project in the IT Minds Bitbucket. It shows how is-pr and git-merge-master can be used.
# Sonar code coverage for javascript/typescript project, tested with Angular CLI
# -----
# coverage is specific for the sonar modules that sonarcloud uses
# https://docs.sonarqube.org/display/PLUG/TypeScript+Test+Execution+and+Coverage+Results+Import
# https://docs.sonarqube.org/display/PLUG/JavaScript+Coverage+Results+Import
# -----
pipelines:
default:
- step:
name: Build Angular
image: itminds/sonar-runner
caches:
- node
script:
- export IS_PR=$(bash is-pr)
# if there is a PR open for the current branch, run test for post-merge result
- if [ $IS_PR == 'true' ]; then echo "PR detected, running test for post-merge result"; fi
- if [ $IS_PR == 'true' ]; then bash git-merge-master; fi
# Install and test js/ts. This script can be replaced with specific install/test commands
- bash node-coverage
# Build project
- npm run build
# Update sonarcloud stats when it is a PR
- if [ $IS_PR == 'true' ]; then sonar-scanner -Dsonar.login=${SONARQUBE_TOKEN}
-Dsonar.typescript.lcov.reportPaths="$BITBUCKET_CLONE_DIR/coverage/lcov.info"
-Dsonar.javascript.lcov.reportPaths="$BITBUCKET_CLONE_DIR/coverage/lcov.info"; fi
branches:
master:
- step:
name: Build Angular
image: itminds/sonar-runner
caches:
- node
script:
# Install and test js/ts. This script can be replaced with specific install/test commands
- bash node-coverage
# Build project
- npm run build
# Update sonarcloud stats
- sonar-scanner -Dsonar.login=${SONARQUBE_TOKEN}
-Dsonar.typescript.lcov.reportPaths="$BITBUCKET_CLONE_DIR/coverage/lcov.info"
-Dsonar.javascript.lcov.reportPaths="$BITBUCKET_CLONE_DIR/coverage/lcov.info"
Content type
Image
Digest
Size
306.1 MB
Last updated
about 8 years ago
docker pull itminds/sonar-runner