Skip to content

GHA-427 SONAR tickets have the "fixVersion" filled in automatically - #214

Merged
jonas-wielage-sonarsource merged 9 commits into
masterfrom
jw/integration-ticket-fix-versions
Oct 7, 2026
Merged

jonas-wielage-sonarsource merged 9 commits into
masterfrom
jw/integration-ticket-fix-versions

Conversation

@jonas-wielage-sonarsource

@jonas-wielage-sonarsource jonas-wielage-sonarsource commented Oct 6, 2026 •

Copy link
Copy Markdown
Contributor

Part of


Summary by Gitar

  • Automated Fix versions:
    • Automatically set Jira fixVersions on integration tickets based on the selected edition and open project versions
    • Cross-reference and skip versions already tagged in sonar-enterprise using vault credentials or a GitHub token input
  • Action inputs and workflow:
    • Added secret-name and token inputs to create-integration-ticket action to support secure tag lookups
    • Updated automated release workflow and documentation to pass plugin-specific release automation secret names

This will update automatically on new commits.

@jonas-wielage-sonarsource
jonas-wielage-sonarsource marked this pull request as draft October 6, 2026 09:54
@jonas-wielage-sonarsource
jonas-wielage-sonarsource force-pushed the jw/integration-ticket-fix-versions branch 2 times, most recently from 52f1447 to 4e9eefa Compare October 6, 2026 09:58
Comment thread create-integration-ticket/action.yml Outdated
@jonas-wielage-sonarsource
jonas-wielage-sonarsource force-pushed the jw/integration-ticket-fix-versions branch from 4e9eefa to b8bbe80 Compare October 6, 2026 10:20
Comment thread .okf/actions/create-integration-ticket.md Outdated
@jonas-wielage-sonarsource
jonas-wielage-sonarsource force-pushed the jw/integration-ticket-fix-versions branch from 74248eb to 30455c3 Compare October 6, 2026 11:33
Comment thread .github/workflows/automated-release.yml Outdated
@jonas-wielage-sonarsource

Copy link
Copy Markdown
Contributor Author

@jonas-wielage-sonarsource jonas-wielage-sonarsource changed the title Automatically add fix version to SQS Integration ticket GHA-427 SONAR tickets have the "fixVersion" filled in automatically Oct 6, 2026
@jonas-wielage-sonarsource

Copy link
Copy Markdown
Contributor Author

@sonarqubecloud

sonarqubecloud Bot commented Oct 7, 2026

Copy link
Copy Markdown

@gitar-bot

gitar-bot Bot commented Oct 7, 2026

Copy link
Copy Markdown
Code Review ✅ Approved 3 closed / 3 findings

🔴 High risk · Automatically assigns fix versions to Jira tickets, changing their release-tracking data.

Automatically populates Jira fixVersions on integration tickets based on the selected edition and open project versions, with cross-referencing against sonar-enterprise tags via vault or GitHub token. Resolved vault secret name handling, corrected documentation for the default secret name, and removed the feature-branch pin from the Create SQS Ticket step. Ready for merge.

✅ 3 closed
✅ Bug: Vault secret name ignores automated-release's release-automation-secret-name

📄 create-integration-ticket/action.yml:61-68 📄 docs/AUTOMATED_RELEASE.md:179
The new vault step always reads development/github/token/{REPO_OWNER_NAME_DASH}-release-automation, which resolves to SonarSource-<repo>-release-automation. automated-release.yml gets sonar-enterprise access a different way: it uses SonarSource-${secret-name}, where secret-name is inputs.release-automation-secret-name || 'sonar-{plugin-name}-release-automation' (update-analyzer etc.). The SQS ticket step (line 880) passes no secret name. So a consumer who overrides release-automation-secret-name, or whose repo name differs from sonar-<plugin-name>, gets no vault token. The action then falls back to github.token, which can't read the private sonar-enterprise repo. The tag lookup fails with a warning and only Jira is checked, so a version that has already shipped can be put on the ticket. That contradicts the new AUTOMATED_RELEASE.md line saying the SQS ticket skips tagged versions using the release-automation vault token. Fix: add a secret-name input to create-integration-ticket that is used in the vault path, and pass the same expression from automated-release.yml as the update-analyzer steps do.

✅ Quality: OKF doc gives truncated default vault secret name -release-automation

📄 .okf/actions/create-integration-ticket.md:47
Line 47 of the knowledge doc says the token comes from vault SonarSource-<secret-name> when secret-name is set, "else -release-automation". The real fallback in action.yml (line 71) is {REPO_OWNER_NAME_DASH}-release-automation, and the README describes it that way too. Without the {REPO_OWNER_NAME_DASH} prefix, anyone reading this doc to find the vault path will get the wrong secret name.

✅ Bug: Create SQS Ticket step pinned to feature branch; revert before merge

📄 .github/workflows/automated-release.yml:880
The Create SQS Ticket step now uses create-integration-ticket@jw/integration-ticket-fix-versions. Every other SonarSource/release-github-actions/* reference in this workflow, including the other create-integration-ticket steps, still uses @master. If this merges as is, the reusable workflow keeps pointing at the feature branch. Once that branch is deleted after merge, every caller with sqs-integration: true will fail at this step. Even before deletion, the step would skip any later fixes that land on master. Point it back at @master before taking the PR out of draft.

Review coverage

🧪 Functional validation No results

📋 Rules No rules evaluated

Cross-repo coverage 2 repositories selected

Cross-repo inspection is incomplete. Unread code may contain additional impacts.

🤖 Auto-approval Not enabled · Set up

Options

Auto-apply is off → Gitar will not commit updates to this branch.
Display: compact → Counting what did not apply, without listing it.

Comment with these commands to change the behavior for this request:

Auto-apply Compact
gitar auto-apply:on         
gitar display:verbose         

Was this helpful? React with 👍 / 👎 | Gitar

Comment thread create-integration-ticket/create_integration_ticket.py

@yasen-pavlov-sonarsource yasen-pavlov-sonarsource left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

❤️

@jonas-wielage-sonarsource
jonas-wielage-sonarsource merged commit e9a93a9 into master Oct 7, 2026
21 checks passed
@jonas-wielage-sonarsource
jonas-wielage-sonarsource deleted the jw/integration-ticket-fix-versions branch October 7, 2026 10:53
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants