Make scan_scanners return 0 so a passing repo doesn't trip set -e
scan_scanners communicates results via globals (T1_BLOCK/T1_CRIT/T1_HIGH); its last statement was a bare [ $rc -eq 1 ] && T1_BLOCK=1. On a PASS (rc=0) that test is false, so the function returned non-zero and set -e killed the whole sweep at the first passing repo in tier 1 (right after the unbound-variable fix let it get that far). Add an explicit return 0. Audited the rest of the tier1/tier2/summary path; scan_agentic and the others already end on a zero-status command.
This commit is contained in:
parent
6d65c54b58
commit
f4bb2bce8a
1 changed files with 1 additions and 0 deletions
|
|
@ -202,6 +202,7 @@ scan_scanners() { # target slug
|
|||
T1_CRIT="$(jq -r '(.summary.confirmed_critical // 0)' "$result_json" 2>/dev/null || echo 0)"
|
||||
T1_HIGH="$(jq -r '(.summary.confirmed_high // 0)' "$result_json" 2>/dev/null || echo 0)"
|
||||
[ "$rc" -eq 1 ] && T1_BLOCK=1
|
||||
return 0 # MUST return 0: results go via globals; a falsey last cmd would trip set -e in the caller
|
||||
}
|
||||
|
||||
# --- TIER 2: agentic run_headless + full review.sh over a target dir ----------
|
||||
|
|
|
|||
Reference in a new issue