Skip to content

fix: prevent silent findings_count=0 fallback when jq fails or is missing (#129) - #150

Open
00200200 wants to merge 1 commit into
anthropics:mainfrom
00200200:fix/prevent-silent-jq-failure
Open

00200200 wants to merge 1 commit into
anthropics:mainfrom
00200200:fix/prevent-silent-jq-failure

Conversation

@00200200

Copy link
Copy Markdown

Description

Resolves #129.

Currently in action.yml:

  1. The dependency installation step attempts sudo apt-get update && sudo apt-get install -y jq without checking if it succeeded.
  2. In Run ClaudeCode scan, jq -e '.error' and CLAUDECODE_FINDINGS_COUNT=$(jq -r ... 2>/dev/null || echo "0") swallow jq failures (such as missing jq or malformed JSON), silently defaulting findings_count=0. This causes scans with real findings to be reported as clean passes when jq is broken or unavailable.

Proposed Changes

  • Dependency installation: Check if jq is already present before running apt-get (avoiding redundant package updates on runners where jq is pre-installed). If missing, attempt to install it and verify command -v jq, failing loudly with ::error:: if it cannot be found.
  • Pre-parsing validation: Before evaluating results, verify jq is available in PATH.
  • JSON validity check: Run jq empty claudecode/claudecode-results.json to verify the output file is well-formed JSON before accessing fields, surfacing claudecode-error.log and exiting non-zero if invalid.
  • Fail-safe parsing: Remove silent || echo "0" / || echo '[]' fallbacks that mask execution errors, failing explicitly if result parsing fails.

…sing (anthropics#129)

- Verify jq is present or successfully installed in 'Install dependencies', failing loudly if unavailable
- In 'Run ClaudeCode scan', verify jq is available in PATH before attempting to parse
- Validate claudecode-results.json is valid JSON before parsing findings
- Remove silent fallback to findings_count=0 on jq execution failure, failing with an explicit error instead

Fixes anthropics#129
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Silent findings_count=0 fallback when jq is unavailable can mask real findings

1 participant