CI: Add Nexus IQ scan to rip-app/ad 31/14431/2
authorAnil Belur <abelur@linuxfoundation.org>
Mon, 19 May 2025 08:18:57 +0000 (18:18 +1000)
committerAnil Belur <abelur@linuxfoundation.org>
Mon, 19 May 2025 08:20:27 +0000 (18:20 +1000)
Issue: IT-28096
Change-Id: Ic1c77e1f4b57306481702ce0f43d033828740d0b
Signed-off-by: Anil Belur <abelur@linuxfoundation.org>
.github/workflows/gerrit-novote-merge.yaml

index 1e289f5..f625bc6 100644 (file)
@@ -93,9 +93,17 @@ jobs:
             -Dsonar.sources=ad
             -Dsonar.verbose=true
 
+  call-sonartype-lifecycle:
+    name: "Sonatype Lifecycle Scan"
+    needs: notify
+    # yamllint disable-line rule:line-length
+    uses: lfit/releng-reusable-workflows/.github/workflows/reuse-sonatype-lifecycle.yaml@ac846b1cfeaf3a7cac6f28413a5206afc9951464 # v0.2.11
+    secrets:
+      NEXUS_IQ_PASSWORD: ${{ secrets.NEXUS_IQ_PASSWORD }}
+
   report-status:
     if: ${{ always() }}
-    needs: [notify, call-sonarcloud-scan]
+    needs: [notify, call-sonarcloud-scan, call-sonartype-lifecycle]
     runs-on: ubuntu-latest
     steps:
       - name: Get workflow conclusion