Research rule RE005 flags || true / continue-on-error as exit-masking. Several instances are deliberate fail-closed designs (checkout-best-effort + a next step that fails closed naming the missing piece — e.g. ci-pipeline Deno ledger, governance dupkey helpers). Each of the 20 needs classification: verified fail-closed vs genuine masking bug.
Acknowledged in .hypatia-baseline.json (hypatia triage 2026-09-22, expires 2026-12-22) by the main-red fix-forward. This issue is the tracking item; closing it requires either remediating the instances or renewing the acknowledgement.
Instances (20):
research_extensions/RE005 warn — .github/workflows/affinescript-verify.yml
workflow .github/workflows/affinescript-verify.yml:89 step Checkout AffineScript compiler swallows non-zero exit via continue-on-error: true — failures will be masked
research_extensions/RE005 warn — .github/workflows/changelog-reusable.yml
workflow .github/workflows/changelog-reusable.yml:117 step Mode = check-only — verify no drift swallows non-zero exit via || true — failures will be masked
research_extensions/RE005 warn — .github/workflows/ci-pipeline.yml
workflow .github/workflows/ci-pipeline.yml:404 step Checkout the pinned Standards Deno ledger swallows non-zero exit via continue-on-error: true — failures will be masked
research_extensions/RE005 warn — .github/workflows/echidna-verify.yml
workflow .github/workflows/echidna-verify.yml:123 step Type-check proofs swallows non-zero exit via || true — failures will be masked
research_extensions/RE005 warn — .github/workflows/governance-reusable.yml
workflow .github/workflows/governance-reusable.yml:405 step Check banned-language files (ReScript / Go / Python / Java / Kotlin / Groovy / Swift / Dart / V-lang / Makefile) swallows non-zero exit via || true — failur
research_extensions/RE005 warn — .github/workflows/governance-reusable.yml
workflow .github/workflows/governance-reusable.yml:539 step Check for npm/yarn artifacts swallows non-zero exit via || true — failures will be masked
research_extensions/RE005 warn — .github/workflows/governance-reusable.yml
workflow .github/workflows/governance-reusable.yml:710 step Security checks swallows non-zero exit via || true — failures will be masked
research_extensions/RE005 warn — .github/workflows/governance-reusable.yml
workflow .github/workflows/governance-reusable.yml:949 step Check file permissions swallows non-zero exit via continue-on-error: true — failures will be masked
research_extensions/RE005 warn — .github/workflows/governance-reusable.yml
workflow .github/workflows/governance-reusable.yml:954 step Check TODO/FIXME swallows non-zero exit via continue-on-error: true — failures will be masked
research_extensions/RE005 warn — .github/workflows/governance-reusable.yml
workflow .github/workflows/governance-reusable.yml:960 step Check for large files swallows non-zero exit via continue-on-error: true — failures will be masked
research_extensions/RE005 warn — .github/workflows/governance-reusable.yml
workflow .github/workflows/governance-reusable.yml:965 step EditorConfig check swallows non-zero exit via continue-on-error: true — failures will be masked
research_extensions/RE005 warn — .github/workflows/governance-reusable.yml
workflow .github/workflows/governance-reusable.yml:1048 step Mixed content check swallows non-zero exit via || true — failures will be masked
research_extensions/RE005 warn — .github/workflows/governance-reusable.yml
workflow .github/workflows/governance-reusable.yml:1077 step Checkout the pinned Standards policy helpers swallows non-zero exit via continue-on-error: true — failures will be masked
research_extensions/RE005 warn — .github/workflows/governance-reusable.yml
workflow .github/workflows/governance-reusable.yml:1195 step Check locked or SHA-pinned actions swallows non-zero exit via || true — failures will be masked
research_extensions/RE005 warn — .github/workflows/hypatia-scan-reusable.yml
workflow .github/workflows/hypatia-scan-reusable.yml:180 step Check out standards for the SARIF baseline filter swallows non-zero exit via continue-on-error: true — failures will be masked
research_extensions/RE005 warn — .github/workflows/readme-derive-reusable.yml
workflow .github/workflows/readme-derive-reusable.yml:222 step Freshness check (fail-and-tell) swallows non-zero exit via || true — failures will be masked
research_extensions/RE005 warn — .github/workflows/scorecard-enforcer.yml
workflow .github/workflows/scorecard-enforcer.yml:80 step Check for pinned dependencies swallows non-zero exit via || true — failures will be masked
research_extensions/RE005 warn — .github/workflows/secret-scanner-reusable.yml
workflow .github/workflows/secret-scanner-reusable.yml:535 step Check for hardcoded secrets in Rust swallows non-zero exit via || true — failures will be masked
research_extensions/RE005 warn — .github/workflows/secret-scanner-reusable.yml
workflow .github/workflows/secret-scanner-reusable.yml:696 step Check for hardcoded secrets in shell scripts swallows non-zero exit via || true — failures will be masked
research_extensions/RE005 warn — .github/workflows/security-gate-pr-target.yml
workflow .github/workflows/security-gate-pr-target.yml:50 step Extract PR branch for safe checkout swallows non-zero exit via || true — failures will be masked
Research rule RE005 flags
|| true/continue-on-erroras exit-masking. Several instances are deliberate fail-closed designs (checkout-best-effort + a next step that fails closed naming the missing piece — e.g. ci-pipeline Deno ledger, governance dupkey helpers). Each of the 20 needs classification: verified fail-closed vs genuine masking bug.Acknowledged in
.hypatia-baseline.json(hypatia triage 2026-09-22, expires 2026-12-22) by the main-red fix-forward. This issue is the tracking item; closing it requires either remediating the instances or renewing the acknowledgement.Instances (20):
research_extensions/RE005warn —.github/workflows/affinescript-verify.ymlworkflow .github/workflows/affinescript-verify.yml:89 step
Checkout AffineScript compilerswallows non-zero exit viacontinue-on-error: true— failures will be maskedresearch_extensions/RE005warn —.github/workflows/changelog-reusable.ymlworkflow .github/workflows/changelog-reusable.yml:117 step
Mode = check-only — verify no driftswallows non-zero exit via|| true— failures will be maskedresearch_extensions/RE005warn —.github/workflows/ci-pipeline.ymlworkflow .github/workflows/ci-pipeline.yml:404 step
Checkout the pinned Standards Deno ledgerswallows non-zero exit viacontinue-on-error: true— failures will be maskedresearch_extensions/RE005warn —.github/workflows/echidna-verify.ymlworkflow .github/workflows/echidna-verify.yml:123 step
Type-check proofsswallows non-zero exit via|| true— failures will be maskedresearch_extensions/RE005warn —.github/workflows/governance-reusable.ymlworkflow .github/workflows/governance-reusable.yml:405 step
Check banned-language files (ReScript / Go / Python / Java / Kotlin / Groovy / Swift / Dart / V-lang / Makefile)swallows non-zero exit via|| true— failurresearch_extensions/RE005warn —.github/workflows/governance-reusable.ymlworkflow .github/workflows/governance-reusable.yml:539 step
Check for npm/yarn artifactsswallows non-zero exit via|| true— failures will be maskedresearch_extensions/RE005warn —.github/workflows/governance-reusable.ymlworkflow .github/workflows/governance-reusable.yml:710 step
Security checksswallows non-zero exit via|| true— failures will be maskedresearch_extensions/RE005warn —.github/workflows/governance-reusable.ymlworkflow .github/workflows/governance-reusable.yml:949 step
Check file permissionsswallows non-zero exit viacontinue-on-error: true— failures will be maskedresearch_extensions/RE005warn —.github/workflows/governance-reusable.ymlworkflow .github/workflows/governance-reusable.yml:954 step
Check TODO/FIXMEswallows non-zero exit viacontinue-on-error: true— failures will be maskedresearch_extensions/RE005warn —.github/workflows/governance-reusable.ymlworkflow .github/workflows/governance-reusable.yml:960 step
Check for large filesswallows non-zero exit viacontinue-on-error: true— failures will be maskedresearch_extensions/RE005warn —.github/workflows/governance-reusable.ymlworkflow .github/workflows/governance-reusable.yml:965 step
EditorConfig checkswallows non-zero exit viacontinue-on-error: true— failures will be maskedresearch_extensions/RE005warn —.github/workflows/governance-reusable.ymlworkflow .github/workflows/governance-reusable.yml:1048 step
Mixed content checkswallows non-zero exit via|| true— failures will be maskedresearch_extensions/RE005warn —.github/workflows/governance-reusable.ymlworkflow .github/workflows/governance-reusable.yml:1077 step
Checkout the pinned Standards policy helpersswallows non-zero exit viacontinue-on-error: true— failures will be maskedresearch_extensions/RE005warn —.github/workflows/governance-reusable.ymlworkflow .github/workflows/governance-reusable.yml:1195 step
Check locked or SHA-pinned actionsswallows non-zero exit via|| true— failures will be maskedresearch_extensions/RE005warn —.github/workflows/hypatia-scan-reusable.ymlworkflow .github/workflows/hypatia-scan-reusable.yml:180 step
Check out standards for the SARIF baseline filterswallows non-zero exit viacontinue-on-error: true— failures will be maskedresearch_extensions/RE005warn —.github/workflows/readme-derive-reusable.ymlworkflow .github/workflows/readme-derive-reusable.yml:222 step
Freshness check (fail-and-tell)swallows non-zero exit via|| true— failures will be maskedresearch_extensions/RE005warn —.github/workflows/scorecard-enforcer.ymlworkflow .github/workflows/scorecard-enforcer.yml:80 step
Check for pinned dependenciesswallows non-zero exit via|| true— failures will be maskedresearch_extensions/RE005warn —.github/workflows/secret-scanner-reusable.ymlworkflow .github/workflows/secret-scanner-reusable.yml:535 step
Check for hardcoded secrets in Rustswallows non-zero exit via|| true— failures will be maskedresearch_extensions/RE005warn —.github/workflows/secret-scanner-reusable.ymlworkflow .github/workflows/secret-scanner-reusable.yml:696 step
Check for hardcoded secrets in shell scriptsswallows non-zero exit via|| true— failures will be maskedresearch_extensions/RE005warn —.github/workflows/security-gate-pr-target.ymlworkflow .github/workflows/security-gate-pr-target.yml:50 step
Extract PR branch for safe checkoutswallows non-zero exit via|| true— failures will be masked