Skip to content

fix(ci): make cargo-audit-check fail when it cannot read the audit - #730

Merged
EVWorth merged 2 commits into
mainfrom
claude/determined-galileo-ho1kdn
Sep 24, 2026
Merged

EVWorth merged 2 commits into
mainfrom
claude/determined-galileo-ho1kdn

Conversation

@EVWorth

@EVWorth EVWorth commented Sep 24, 2026

Copy link
Copy Markdown
Owner

Follow-up to the note in #728, where a local run of scripts/cargo-audit-check.sh said clean while main carried RUSTSEC-2026-0285.

What was actually wrong

That PR blamed a missing jq. On bash 5, a missing jq already makes the script exit 127 (late, and with a confusing message). The real silent pass is a different case:

JSON_OUTPUT="$(cargo audit --json ... 2>/dev/null || true)"

If cargo audit produces no report (advisory DB fetch fails, network error, cargo-audit not installed), the output is empty and every count comes out as "". Then [ "" -gt 0 ] errors inside an if, which set -e doesn't catch. The script prints "✅ cargo audit: 0 real vulnerabilities" and exits 0.

Change

  • Checks up front that jq and cargo-audit are installed, and exits 2 with an ::error:: if either is missing.
  • After running, requires a JSON object with a vulnerabilities key. Otherwise it exits 2 and prints cargo audit's stderr, which used to go to /dev/null.
  • Nothing else changes. Real vulnerabilities still exit 1, and warnings still don't block.

Verification (run locally)

Case Before After
jq missing exit 127, jq: command not found partway through exit 2, 'jq' is not installed
cargo audit fails / empty output ✅ 0 vulnerabilities, exit 0 exit 2, did not produce a report + cargo's error
main today exit 1, RUSTSEC-2026-0285 exit 1, RUSTSEC-2026-0285 (unchanged)
with #728's lockfile exit 0 exit 0 (unchanged)

CI already installs jq and cargo-audit (ci.yml), so the green path there is unchanged.

🤖 Generated with Claude Code

https://claude.ai/code/session_019uLE7rJcohc7WDPstJ7yCL


Generated by Claude Code

The script ignored cargo audit's exit status, so a run that produced no
report at all (advisory DB fetch failed, cargo-audit missing) left every
count blank. `[ "" -gt 0 ]` then errored inside an `if`, which set -e does
not catch, and the script printed "0 real vulnerabilities" and exited 0.

Now it checks for jq and cargo-audit up front and refuses to pass unless
cargo audit returned a JSON report, surfacing cargo audit's stderr when it
did not.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_019uLE7rJcohc7WDPstJ7yCL
Upstream moved the v1 tag to 02cb101, so check-action-pins.sh now fails
on main's pin. Same change as dependabot's #723; ported here so this PR's
Lint (workflows) job can pass. It no-ops once #723 merges.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_019uLE7rJcohc7WDPstJ7yCL

EVWorth commented Sep 24, 2026

Copy link
Copy Markdown
Owner Author

Lint (workflows) failed on the first push, and the cause isn't this PR's diff. check-action-pins.sh reported MISMATCH dtolnay/rust-toolchain@6c977a6… — the comment says v1, which is 02cb101…. Upstream moved the v1 tag, so main's pin is now stale.

I ported dependabot's fix from #723 in 3b688ac. The .github changes are identical, and it becomes a no-op once #723 merges.

cargo Audit will still be red until #728 merges. That failure is RUSTSEC-2026-0285 (rustls) on main, not this change.


Generated by Claude Code

@EVWorth
EVWorth merged commit a94e399 into main Sep 24, 2026
12 checks passed
@EVWorth
EVWorth deleted the claude/determined-galileo-ho1kdn branch September 24, 2026 10:55
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants