Black Duck integration and added config to run bundle install to generate lock file at runtime#689
Merged
sanjain-progress merged 5 commits intomainfrom Feb 12, 2026
Merged
Conversation
Signed-off-by: Sachin Jain <Sachin.jain@chef.io>
46d5c2d to
3abba78
Compare
Signed-off-by: Sachin Jain <Sachin.jain@chef.io>
sanghinitin
approved these changes
Feb 11, 2026
ashiqueps
approved these changes
Feb 11, 2026
Signed-off-by: Sachin Jain <Sachin.jain@chef.io>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
This pull request introduces a new GitHub Actions workflow stub for CI on the main branch and significantly enhances the SonarQube configuration for the repository. The changes focus on improving CI/CD automation and providing a more comprehensive and maintainable SonarQube analysis setup.
CI/CD Workflow Enhancements:
.github/workflows/ci-main-pull-request-stub-1.0.7.ymlthat serves as a stub to call a common GitHub Action for CI checks on pull requests and pushes to themainandrelease/**branches. This workflow:ci-main-pull-request.yml) with a wide range of configurable inputs for build, test, security scanning, packaging, and reporting, supporting advanced features like SonarQube, BlackDuck, Polaris, and SBOM generation.Description
Related Issue
Types of changes
Checklist:
Gemfile.lockhas changed, I have used--conservativeto do it and included the full output in the Description above.