Skip to content

fix(ci): don't let the clean no-credentials scan result abort the release - #13

Merged
zero2005x merged 1 commit into
mainfrom
fix/release-secret-scan-exit-code
Oct 1, 2026
Merged

zero2005x merged 1 commit into
mainfrom
fix/release-secret-scan-exit-code

Conversation

@zero2005x

Copy link
Copy Markdown
Owner

Why

The v1.5.1 Release run (36826457541) failed at Verify no Rokid credential reached the staged artifacts. Build, 16 KB alignment and signature checks all passed; the canary check and the upload were skipped, so no GitHub Release was created.

scripts/verify-bundle-secrets.sh printed "no Rokid credentials configured locally; nothing to look for" and exited 2, which is the expected clean state in CI. The step already treats 2 as acceptable, but Actions runs it under bash -e (shell: /usr/bin/bash -e {0} in the log). The bare call aborts the step right there, so rc=$? and the case were never reached.

This check was added in #8, and this is the first tag push since then, so it had never run.

Change

.github/workflows/release.yml, that one step only: capture the exit code with || rc=$?, and emit an ::error:: annotation when the scan reports a real failure.

The next step ("Verify release builds ignore configured credentials") is unchanged. There the canaries are configured, so the script returns 0 or 1, and under -e any non-zero (including 2) fails the step, which is the strict behaviour we want.

Verification

I ran the step's actual run: block, extracted from the workflow, under bash -e with a stub scan script:

scan rc before after
0 (clean) exit 0 exit 0
2 (nothing configured) exit 2 exit 0
1 (leak) exit 1 exit 1, with an error annotation per artifact

The workflow YAML still parses. The real fix can only be proven by a tag push.

Not in this PR

workflow_dispatch is also broken, so it can't be used to re-run a release: TAG="${GITHUB_REF_NAME:-${{ github.event.inputs.tag }}}" never falls back, because GITHUB_REF_NAME is always set (to the branch name on a dispatch), and the checkout doesn't use the tag input. Left for a separate change.

🤖 Generated with Claude Code

…abort the release

verify-bundle-secrets.sh exits 2 when no credentials are configured, which is
the expected state in CI. The release step documented 2 as acceptable, but
Actions runs steps under `bash -e`, so the bare call aborted the step before
`rc=$?` was reached and the `case` never ran. The v1.5.1 release failed here
before the canary check and the upload.

Capture the exit code with `|| rc=$?` and emit an error annotation when the
scan reports a real failure.

Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com>
@sonarqubecloud

sonarqubecloud Bot commented Oct 1, 2026

Copy link
Copy Markdown

@zero2005x
zero2005x merged commit 8628541 into main Oct 1, 2026
3 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant