Repository navigation
Update GitHub Actions, remove SonarQube, and group dependabot updates - #202
Merged
thirtytwobits merged 3 commits intoSep 25, 2026
Merged
Conversation
Manually bumps actions/checkout, actions/cache, actions/upload-artifact, github/codeql-action, SonarSource/sonarqube-scan-action, actions/configure-pages, actions/upload-pages-artifact, and actions/deploy-pages to their current major versions, replacing several stale dependabot PRs. Also groups github-actions updates in dependabot.yml so future bumps land as a single PR instead of one per action. Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
This was referenced Sep 25, 2026
Drops the sonarqube job, its SONAR_TOKEN usage, the SonarSource/sonarqube-scan-action step, and the sonarqube.xml artifact uploads from cetlvast.yml, and removes the now-unneeded sonarqube dependency from deploy-docs. Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
SonarQube/SonarCloud is no longer used, so this removes it entirely: - Deletes sonar-project.properties, the cetlvast_sonar analysis-only build target and its sonar.cpp, and the JUnit-to-SonarQube XML conversion tooling (FindTestReport.cmake, test_report_util.py). - Removes the sonarqube/cobertura coverage report format from Findgcovr.cmake and the CMake targets/presets that referenced it (gcovr_sonarqube_report_for_unittest/examples), keeping the html coverage report path working. - Drops SonarCloud badges from README.md, the #sonar CI-trigger hashtag from CONTRIBUTING.md, and SonarLint settings/extension recommendations from .vscode. - Strips the now-meaningless NOSONAR/Sonar suppression comments from include/cetl headers, keeping the underlying rationale comments where they still apply. Verified locally: CMake configure, run_unittests, run_examples, and the Coverage-config html report all still build and pass. Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
thirtytwobits
deleted the
chore/update-github-actions-and-dependabot-grouping
branch
September 25, 2026 04:14
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
.github/workflows/*.ymlto their current major versions, superseding the stale dependabot PRs (Bump github/codeql-action from 3 to 4 #196, Bump actions/checkout from 5 to 6 #198, Bump actions/cache from 4 to 5 #199, Bump SonarSource/sonarqube-scan-action from 5.3.1 to 7.0.0 #200, Bump actions/upload-artifact from 4 to 6 #201), which have been closed in favor of this PR:actions/checkoutv5 → v7actions/cachev4 → v6actions/upload-artifactv4 → v7github/codeql-action/*v3 → v4actions/configure-pagesv5 → v6actions/upload-pages-artifactv4 → v5actions/deploy-pagesv4 → v5groupsentry to.github/dependabot.ymlso future github-actions updates are bundled into a single PR instead of one per action, reducing PR noise going forward.sonarqubeCI job,sonar-project.properties, the SonarCloud README badges, and the#sonarCI-trigger hashtag from CONTRIBUTING.md.FindTestReport.cmake,test_report_util.py) and the sonarqube/cobertura coverage report format fromFindgcovr.cmake, along with thegcovr_sonarqube_report_for_*targets from CMake presets.cetlvast_sonaranalysis-only build target and itssonar.cpp..vscode.NOSONAR/Sonar suppression comments frominclude/cetlheaders, keeping the underlying rationale where it still applies.gcovr_html_report_for_*) is preserved and still works.Test plan
cmake --preset configure-gcc-native-cpp-14-offline,run_unittests(162/162 passing),run_examples, and the Coverage-config html report all build/run successfully after the SonarQube removal.cetlvast.yml,codeql.yml) run successfully on this PR