From f4bb2bce8af968c1b99bad872bff299bcbfa8540 Mon Sep 17 00:00:00 2001 From: Adam Moussa Date: Tue, 16 Jun 2026 16:43:35 -0400 Subject: [PATCH] Make scan_scanners return 0 so a passing repo doesn't trip set -e scan_scanners communicates results via globals (T1_BLOCK/T1_CRIT/T1_HIGH); its last statement was a bare [ $rc -eq 1 ] && T1_BLOCK=1. On a PASS (rc=0) that test is false, so the function returned non-zero and set -e killed the whole sweep at the first passing repo in tier 1 (right after the unbound-variable fix let it get that far). Add an explicit return 0. Audited the rest of the tier1/tier2/summary path; scan_agentic and the others already end on a zero-status command. --- security-review/nightly_sweep.sh | 1 + 1 file changed, 1 insertion(+) diff --git a/security-review/nightly_sweep.sh b/security-review/nightly_sweep.sh index fefa4f2..a0b88ab 100755 --- a/security-review/nightly_sweep.sh +++ b/security-review/nightly_sweep.sh @@ -202,6 +202,7 @@ scan_scanners() { # target slug T1_CRIT="$(jq -r '(.summary.confirmed_critical // 0)' "$result_json" 2>/dev/null || echo 0)" T1_HIGH="$(jq -r '(.summary.confirmed_high // 0)' "$result_json" 2>/dev/null || echo 0)" [ "$rc" -eq 1 ] && T1_BLOCK=1 + return 0 # MUST return 0: results go via globals; a falsey last cmd would trip set -e in the caller } # --- TIER 2: agentic run_headless + full review.sh over a target dir ----------