Skip to content

ci: fix main SonarCloud quality gate findings - #316

Open
krowvin wants to merge 4 commits into
mainfrom
fix/main-quality-gate
Open

krowvin wants to merge 4 commits into
mainfrom
fix/main-quality-gate

Conversation

@krowvin

@krowvin krowvin commented Sep 10, 2026 •

Copy link
Copy Markdown
Collaborator

Main's SonarCloud quality gate fails on three reliability findings and ten unpinned workflow dependencies. This fixes the reported findings without changing the runtime API.

  • Let deletion assertions and unexpected API errors fail the level tests. Verify the temporary dated level exists before deleting it, then check that CDA no longer returns that effective date; CDA can legitimately fall back to the previous level. Verify deleted specified levels are absent from the returned list.
  • Iterate office collections with FIRST/NEXT so database setup handles empty or sparse collections.
  • Pin the six flagged third-party Actions to the commits currently referenced by their existing tags.

Validation: 98 mock/doctest tests, strict mypy, pre-commit, and actionlint pass locally. All eight normal PR checks pass, including SonarCloud, CodeQL, and Python 3.9/latest unit tests. Failure probes confirm that undeleted data, HTTP 500, and unexpected errors fail, while the previous effective level and HTTP 404 are accepted. The corrected tests pass all 80 integration tests on Python 3.9 with production CDA and production schema. The remaining combinations in the full matrix are still running: https://github.com/HydrologicEngineeringCenter/cwms-python/actions/runs/34545073336.

@krowvin
krowvin requested a review from msweier September 11, 2026 00:23
# Use actions-poetry to handle installation
- name: Install Poetry and Dependencies
uses: abatilo/actions-poetry@v4
uses: abatilo/actions-poetry@0dd19c9498c3dc8728967849d0d2eae428a8a3d8 # v4

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I don't understand this change. Why is simply the version as before not applicable? when we update are we going to have to look for the tag instead of just going @v5?

Copy link
Copy Markdown
Collaborator Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Sonar flagged this

We could remove that check but it's because of

https://docs.github.com/en/actions/reference/security/secure-use#using-third-party-actions
And

We could use dependabot to enable this so we don't have to be looking up the hash each time

https://docs.github.com/en/actions/reference/security/secure-use#keeping-the-actions-in-your-workflows-secure-and-up-to-date

We probably aren't pinning hashes in other repo but I've started with all the supply chain stuff going on.

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

alright. sounds good. as long as dependabot is able to update it.

@sonarqubecloud

Copy link
Copy Markdown

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants