This guide explains how to integrate Sigrid into your BitBucket Pipelines continuous integration pipeline. Make sure you have also read the general Sigrid CI documentation before starting this guide.
- You have a Sigrid user account. Sigrid CI requires Sigrid, it is currently not supported to only use the CI integration without using Sigrid itself.
- You have on-boarded your system, i.e. your system is available in Sigrid. Request your system to be added if this is not yet the case.
- Python 3.7 or higher needs to be available in the CI environment. The client scripts for Sigrid CI are based on Python.
The account you use to submit code to Sigrid CI is different from your normal Sigrid user account. The account consists of an account name and a token, which you add to your CI environment's configuration in the next step.
You can obtain a Sigrid CI account by requesting one from [email protected]. Support for creating Sigrid CI accounts yourself will be added in a future version.
Once the account has been created, you can use Sigrid's user management feature to control which systems it is allowed to access. Similar to normal Sigrid user accounts, Sigrid CI accounts can either serve a specific system, a group of systems, or all systems in your portfolio.
Sigrid CI reads your Sigrid account credentials from two environment variables, called SIGRID_CI_ACCOUNT
and SIGRID_CI_TOKEN
. You can make these environment variables available to BitBucket Pipelines by creating "secrets" in your repository:
- Open "Repository settings" in your project menu
- Select "Repository variables" located in the section "Pipelines"
- Create a secret named
SIGRID_CI_ACCOUNT
with the account name you have received
- Add another secret named
SIGRID_CI_TOKEN
with the token you have received.
Sigrid CI consists of a number of Python-based client scripts, that interact with Sigrid in order to analyze your project's source code and provide feedback based on the results. These client scripts need to be available to the CI environment, in order to call the scripts from the CI pipeline. You can configure your Pipeline to both download the Sigrid CI client scripts and then run Sigrid CI.
We will create two pipelines:
- The first will publish the main/master branch to sigrid-says.com after every commit.
- The second will provide pull request integration: it will compare the contents of the pull request against the main/master branch.
In your BitBucket repository, create a file bitbucket-pipelines.yml
. You can then configure both pipelines in the same configuration file:
image: atlassian/default-image:latest # Or any image you're using as build environment.
pipelines:
branches:
master:
- step:
name: Publish to Sigrid
image: python:3.9 # The client scripts for Sigrid CI are based on Python.
script:
- "git clone https://github.com/Software-Improvement-Group/sigridci.git sigridci"
- "./sigridci/sigridci/sigridci.py --customer examplecustomername --system examplesystemname --source . --publish"
pull-requests:
- step:
name: Sigrid CI
image: python:3.9 # The client scripts for Sigrid CI are based on Python.
script:
- "git clone https://github.com/Software-Improvement-Group/sigridci.git sigridci"
- "./sigridci/sigridci/sigridci.py --customer examplecustomername --system examplesystemname --source . --targetquality 3.5"
Note the branch name master
in the example. This should refer to your primary branch. In most projects this is called either master
or main
, but the default project name could be different for your project.
The example uses the Docker container python:3.9-buster
, but any Docker container that contains Python 3 will do.
Security note: This example downloads the Sigrid CI client scripts directly from GitHub. That might be acceptable for some projects, and is in fact increasingly common. However, some projects might not allow this as part of their security policy. In those cases, you can simply download the sigridci
directory in this repository, and make it available to your runners (either by placing the scripts in a known location, or packaging them into a Docker container).
Refer to the BitBucket Pipelines documentation for more information on when and how these steps will be performed. The bitbucket-pipelines.yml documentation describes the file format used for the configuration file.
The relevant command that starts Sigrid CI is the call to the sigridci.py
script, which starts the Sigrid CI analysis. The scripts supports a number of arguments that you can use to configure your Sigrid CI run. The scripts and its command line interface are explained in using the Sigrid CI client script.
Finally, note that you need to perform this step for every project where you wish to use Sigrid CI. Be aware that you can set a project-specific target quality, you don't necessarily have to use the same target for every project.
Once Sigrid CI has been enabled, you can access it from the list of pipeline runs by accessing "Pipelines" from your repository's menu:
The check will succeed if the code quality meets the specified target, and will fail otherwise. In addition to this central overview, you can also find the Sigrid CI indicator next to all commits:
You can access the results by clicking on the pipeline's success/failure indicator. Sigrid CI provides multiple levels of feedback. The first and fastest type of feedback is directly produced in the CI output, as shown in the following screenshot:
The output consists of the following:
- A list of refactoring candidates that were introduced in your merge request. This allows you to understand what quality issues you caused, which in turn allows you to fix them quickly. Note that quality is obviously important, but you are not expected to always fix every single issue. As long as you meet the target, it's fine.
- An overview of all ratings, compared against the system as a whole. This allows you to check if your changes improved the system, or accidentally made things worse.
- The final conclusion on whether your changes and merge request meet the quality target.
In addition to the textual output, Sigrid CI also generates a static HTML file that shows the results in a more graphical form. This is similar to test coverage tools, which also tend to produce a HTML report. The information in the HTML report is based on the aforementioned list, though it includes slightly more detail.
Finally, if you want to have more information on the system as a whole, you can also access Sigrid, which gives you more information on the overall quality of the system, its architecture, and more.
Feel free to contact SIG's support department for any questions or issues you may have after reading this document, or when using Sigrid or Sigrid CI. Users in Europe can also contact us by phone at +31 20 314 0953.