Skip to content

Fail loudly when scan results cannot be parsed - #135

Closed
CedricConday wants to merge 1 commit into
anthropics:mainfrom
CedricConday:fix/jq-missing-silent-zero
Closed

CedricConday wants to merge 1 commit into
anthropics:mainfrom
CedricConday:fix/jq-missing-silent-zero

Conversation

@CedricConday

Copy link
Copy Markdown

The results-parsing step is entirely jq based, and every jq call had a fallback that swallowed failure: the findings count fell back to "0" and the findings array fell back to []. A missing or broken jq therefore reported a clean scan rather than an error, and the security check went green without having read the results at all.

The install step does not verify that apt-get install -y jq succeeded, so this is reachable whenever that install is a no-op or fails.

This verifies jq is present right after the install, where the cause is still obvious, and treats a parse failure as an error rather than as an absence of findings.

Demonstrated with jq off PATH against a results file holding two findings: the old expression yields findings_count=0, the new one stops the job.

Closes #129

The results-parsing step is entirely jq based, and every jq call had a
fallback that swallowed failure: the findings count fell back to "0" and
the findings array fell back to "[]". A missing or broken jq therefore
reported a clean scan rather than an error, and the security check went
green without having read the results at all.

The install step does not verify that `apt-get install -y jq` succeeded,
so this is reachable whenever that install is a no-op or fails.

Verify jq is present right after the install, where the cause is still
obvious, and treat a parse failure as an error rather than as an absence
of findings.

Demonstrated with jq off PATH against a results file holding two findings:
the old expression yields findings_count=0, the new one stops the job.

Closes anthropics#129
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Silent findings_count=0 fallback when jq is unavailable can mask real findings

1 participant