Skip to content

Hypatia RE005: review exit-masking steps (|| true / continue-on-error) (20 instances) #942

Description

@hyperpolymath

Research rule RE005 flags || true / continue-on-error as exit-masking. Several instances are deliberate fail-closed designs (checkout-best-effort + a next step that fails closed naming the missing piece — e.g. ci-pipeline Deno ledger, governance dupkey helpers). Each of the 20 needs classification: verified fail-closed vs genuine masking bug.

Acknowledged in .hypatia-baseline.json (hypatia triage 2026-09-22, expires 2026-12-22) by the main-red fix-forward. This issue is the tracking item; closing it requires either remediating the instances or renewing the acknowledgement.

Instances (20):

  • research_extensions/RE005 warn — .github/workflows/affinescript-verify.yml
    workflow .github/workflows/affinescript-verify.yml:89 step Checkout AffineScript compiler swallows non-zero exit via continue-on-error: true — failures will be masked
  • research_extensions/RE005 warn — .github/workflows/changelog-reusable.yml
    workflow .github/workflows/changelog-reusable.yml:117 step Mode = check-only — verify no drift swallows non-zero exit via || true — failures will be masked
  • research_extensions/RE005 warn — .github/workflows/ci-pipeline.yml
    workflow .github/workflows/ci-pipeline.yml:404 step Checkout the pinned Standards Deno ledger swallows non-zero exit via continue-on-error: true — failures will be masked
  • research_extensions/RE005 warn — .github/workflows/echidna-verify.yml
    workflow .github/workflows/echidna-verify.yml:123 step Type-check proofs swallows non-zero exit via || true — failures will be masked
  • research_extensions/RE005 warn — .github/workflows/governance-reusable.yml
    workflow .github/workflows/governance-reusable.yml:405 step Check banned-language files (ReScript / Go / Python / Java / Kotlin / Groovy / Swift / Dart / V-lang / Makefile) swallows non-zero exit via || true — failur
  • research_extensions/RE005 warn — .github/workflows/governance-reusable.yml
    workflow .github/workflows/governance-reusable.yml:539 step Check for npm/yarn artifacts swallows non-zero exit via || true — failures will be masked
  • research_extensions/RE005 warn — .github/workflows/governance-reusable.yml
    workflow .github/workflows/governance-reusable.yml:710 step Security checks swallows non-zero exit via || true — failures will be masked
  • research_extensions/RE005 warn — .github/workflows/governance-reusable.yml
    workflow .github/workflows/governance-reusable.yml:949 step Check file permissions swallows non-zero exit via continue-on-error: true — failures will be masked
  • research_extensions/RE005 warn — .github/workflows/governance-reusable.yml
    workflow .github/workflows/governance-reusable.yml:954 step Check TODO/FIXME swallows non-zero exit via continue-on-error: true — failures will be masked
  • research_extensions/RE005 warn — .github/workflows/governance-reusable.yml
    workflow .github/workflows/governance-reusable.yml:960 step Check for large files swallows non-zero exit via continue-on-error: true — failures will be masked
  • research_extensions/RE005 warn — .github/workflows/governance-reusable.yml
    workflow .github/workflows/governance-reusable.yml:965 step EditorConfig check swallows non-zero exit via continue-on-error: true — failures will be masked
  • research_extensions/RE005 warn — .github/workflows/governance-reusable.yml
    workflow .github/workflows/governance-reusable.yml:1048 step Mixed content check swallows non-zero exit via || true — failures will be masked
  • research_extensions/RE005 warn — .github/workflows/governance-reusable.yml
    workflow .github/workflows/governance-reusable.yml:1077 step Checkout the pinned Standards policy helpers swallows non-zero exit via continue-on-error: true — failures will be masked
  • research_extensions/RE005 warn — .github/workflows/governance-reusable.yml
    workflow .github/workflows/governance-reusable.yml:1195 step Check locked or SHA-pinned actions swallows non-zero exit via || true — failures will be masked
  • research_extensions/RE005 warn — .github/workflows/hypatia-scan-reusable.yml
    workflow .github/workflows/hypatia-scan-reusable.yml:180 step Check out standards for the SARIF baseline filter swallows non-zero exit via continue-on-error: true — failures will be masked
  • research_extensions/RE005 warn — .github/workflows/readme-derive-reusable.yml
    workflow .github/workflows/readme-derive-reusable.yml:222 step Freshness check (fail-and-tell) swallows non-zero exit via || true — failures will be masked
  • research_extensions/RE005 warn — .github/workflows/scorecard-enforcer.yml
    workflow .github/workflows/scorecard-enforcer.yml:80 step Check for pinned dependencies swallows non-zero exit via || true — failures will be masked
  • research_extensions/RE005 warn — .github/workflows/secret-scanner-reusable.yml
    workflow .github/workflows/secret-scanner-reusable.yml:535 step Check for hardcoded secrets in Rust swallows non-zero exit via || true — failures will be masked
  • research_extensions/RE005 warn — .github/workflows/secret-scanner-reusable.yml
    workflow .github/workflows/secret-scanner-reusable.yml:696 step Check for hardcoded secrets in shell scripts swallows non-zero exit via || true — failures will be masked
  • research_extensions/RE005 warn — .github/workflows/security-gate-pr-target.yml
    workflow .github/workflows/security-gate-pr-target.yml:50 step Extract PR branch for safe checkout swallows non-zero exit via || true — failures will be masked

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions