Fail loudly when scan results cannot be parsed - #135
Closed
CedricConday wants to merge 1 commit into
Closed
CedricConday wants to merge 1 commit into
CedricConday wants to merge 1 commit into
Conversation
The results-parsing step is entirely jq based, and every jq call had a fallback that swallowed failure: the findings count fell back to "0" and the findings array fell back to "[]". A missing or broken jq therefore reported a clean scan rather than an error, and the security check went green without having read the results at all. The install step does not verify that `apt-get install -y jq` succeeded, so this is reachable whenever that install is a no-op or fails. Verify jq is present right after the install, where the cause is still obvious, and treat a parse failure as an error rather than as an absence of findings. Demonstrated with jq off PATH against a results file holding two findings: the old expression yields findings_count=0, the new one stops the job. Closes anthropics#129
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
The results-parsing step is entirely jq based, and every jq call had a fallback that swallowed failure: the findings count fell back to
"0"and the findings array fell back to[]. A missing or broken jq therefore reported a clean scan rather than an error, and the security check went green without having read the results at all.The install step does not verify that
apt-get install -y jqsucceeded, so this is reachable whenever that install is a no-op or fails.This verifies jq is present right after the install, where the cause is still obvious, and treats a parse failure as an error rather than as an absence of findings.
Demonstrated with jq off
PATHagainst a results file holding two findings: the old expression yieldsfindings_count=0, the new one stops the job.Closes #129