From 87028b4934dcb1ef299bb7e030a4ede215ae73ad Mon Sep 17 00:00:00 2001 From: Liang-Ting Date: Thu, 1 Oct 2026 14:57:02 +0800 Subject: [PATCH] fix(ci): don't let the clean "no credentials configured" scan result abort the release verify-bundle-secrets.sh exits 2 when no credentials are configured, which is the expected state in CI. The release step documented 2 as acceptable, but Actions runs steps under `bash -e`, so the bare call aborted the step before `rc=$?` was reached and the `case` never ran. The v1.5.1 release failed here before the canary check and the upload. Capture the exit code with `|| rc=$?` and emit an error annotation when the scan reports a real failure. Co-Authored-By: Claude Sonnet 5.5 --- .github/workflows/release.yml | 10 +++++++--- 1 file changed, 7 insertions(+), 3 deletions(-) diff --git a/.github/workflows/release.yml b/.github/workflows/release.yml index 81a33a6..6ce9cda 100644 --- a/.github/workflows/release.yml +++ b/.github/workflows/release.yml @@ -208,14 +208,18 @@ jobs: # only, so a release artifact must never contain them. This scans exactly # what is about to be published. Exit code 2 means "nothing configured to # look for", which is the expected state in CI and not a failure. + # + # Steps run under `bash -e`, so the exit code must be captured with `|| rc=$?`. + # A bare call followed by `rc=$?` aborts the step on the script's exit 2 and + # the `case` below is never reached. run: | failed=0 for artifact in dist/*.apk dist/*.aab; do - bash scripts/verify-bundle-secrets.sh "$artifact" - rc=$? + rc=0 + bash scripts/verify-bundle-secrets.sh "$artifact" || rc=$? case "$rc" in 0|2) ;; # 0 = clean, 2 = no credentials configured - *) failed=1 ;; + *) echo "::error::$artifact failed the Rokid credential scan (rc=$rc)"; failed=1 ;; esac done exit $failed