Skip to content

feat(ai-review): have reviewers fix SonarQube findings - #14

Merged
ryanmelt merged 1 commit into
mainfrom
ai-review-sonarqube
Sep 29, 2026
Merged

ryanmelt merged 1 commit into
mainfrom
ai-review-sonarqube

Conversation

@ryanmelt

@ryanmelt ryanmelt commented Sep 29, 2026 •

Copy link
Copy Markdown
Member

Why

The AI review of OpenC3/cosmos#3942 converged with "CI passed" while SonarQube's quality gate was failing on two Major issues. The gate only collected GitHub Actions runs (actions/runs). SonarQube reports through its own GitHub App as a check run, so its findings never reached the reviewers, who have no network access to look them up. And the prompt's "no stylistic changes" rule meant reviewers would likely have left code-smell findings alone even if they had seen them.

What changes

  • Gate: finds the SonarQube Cloud check run on the PR head, waits for it to finish (up to sonar_wait_minutes, default 10) and fetches the PR's failed quality gate conditions, open issues and hotspots waiting for review into sonar_findings.md. The project key comes from the check run's link, or from the new sonar_project_key input. Any Sonar trouble (no check run, outage, error page, no checks: read) only leaves the findings out, with a warning. Hotspots are listed but not counted, because marking one safe takes a person in SonarQube.
  • Fix rounds: when the head is an AI fix commit, remaining Sonar findings send it round again like a CI failure, still limited by MAX_CI_ROUNDS.
  • Loop: adds a "SonarQube findings" section to each turn's prompt and a line to the PR summary.
  • Prompt: a new step tells reviewers to fix every finding, code smells included. It says what to do in edge cases: no NOSONAR and no weakened tests; false positives and out-of-scope fixes go to unresolved_concerns; coverage and duplication conditions need their own fix; hotspots are fixed if they are real problems. The "no stylistic changes" rule now allows what SonarQube rejects.
  • Private projects: an optional SONAR_TOKEN secret. curl gets it through stdin, never the command line.
  • Workflows and template: checks: read is added to the gate job and documented for callers.

Caller change needed

A called workflow can't get more permission than its caller gives it, so each caller must add checks: read. For cosmos, that's OpenC3/cosmos#3958. Without it the review still runs but leaves the Sonar findings out, with a warning.

Testing

  • python3 -m unittest discover -s tests: 82 tests pass, 9 of them new. They cover findings reaching the review, the project key override, the token going only through stdin, waiting for and giving up on the analysis, Sonar outages, AI fix rounds, and the loop prompt and summary.
  • ruff, shellcheck and actionlint (with the CI flags) are clean.
  • I ran the Sonar step on its own against the real OPENC3_LOCAL_ONLY_TARGETS cosmos#3942 and SonarCloud. It reported the failed new_code_smells_severity condition and both open issues (storage_controller.rb:495, test_storage.py:325).

🤖 Generated with Claude Code

SonarQube reports through its GitHub App as a check run, so the gate,
which only read Actions runs, never passed its findings to the reviewers.
The gate now waits for the analysis, collects the PR's failed quality gate
conditions, open issues and hotspots, and the prompt has reviewers fix them.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
@ryanmelt
ryanmelt merged commit 940bb4a into main Sep 29, 2026
3 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant