fix(ci): make cargo-audit-check fail when it cannot read the audit - #730
Merged
Merged
Conversation
The script ignored cargo audit's exit status, so a run that produced no report at all (advisory DB fetch failed, cargo-audit missing) left every count blank. `[ "" -gt 0 ]` then errored inside an `if`, which set -e does not catch, and the script printed "0 real vulnerabilities" and exited 0. Now it checks for jq and cargo-audit up front and refuses to pass unless cargo audit returned a JSON report, surfacing cargo audit's stderr when it did not. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_019uLE7rJcohc7WDPstJ7yCL
Upstream moved the v1 tag to 02cb101, so check-action-pins.sh now fails on main's pin. Same change as dependabot's #723; ported here so this PR's Lint (workflows) job can pass. It no-ops once #723 merges. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_019uLE7rJcohc7WDPstJ7yCL
Owner
Author
|
Lint (workflows) failed on the first push, and the cause isn't this PR's diff. I ported dependabot's fix from #723 in 3b688ac. The cargo Audit will still be red until #728 merges. That failure is RUSTSEC-2026-0285 (rustls) on Generated by Claude Code |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Follow-up to the note in #728, where a local run of
scripts/cargo-audit-check.shsaid clean whilemaincarried RUSTSEC-2026-0285.What was actually wrong
That PR blamed a missing
jq. On bash 5, a missingjqalready makes the script exit 127 (late, and with a confusing message). The real silent pass is a different case:If
cargo auditproduces no report (advisory DB fetch fails, network error,cargo-auditnot installed), the output is empty and every count comes out as"". Then[ "" -gt 0 ]errors inside anif, whichset -edoesn't catch. The script prints "✅ cargo audit: 0 real vulnerabilities" and exits 0.Change
jqandcargo-auditare installed, and exits 2 with an::error::if either is missing.vulnerabilitieskey. Otherwise it exits 2 and prints cargo audit's stderr, which used to go to/dev/null.Verification (run locally)
jqmissingjq: command not foundpartway through'jq' is not installedcargo auditfails / empty outputdid not produce a report+ cargo's errormaintodayCI already installs
jqandcargo-audit(ci.yml), so the green path there is unchanged.🤖 Generated with Claude Code
https://claude.ai/code/session_019uLE7rJcohc7WDPstJ7yCL
Generated by Claude Code