Skip to content

feat: implement issue #1193 — SonarCloud: shell script hygiene - #1196

Open
don-petry wants to merge 23 commits into
mainfrom
dev-lead/issue-1193-20260929-2126
Open

don-petry wants to merge 23 commits into
mainfrom
dev-lead/issue-1193-20260929-2126

Conversation

@don-petry

@don-petry don-petry commented Sep 29, 2026 •

Copy link
Copy Markdown
Contributor

Problem

SonarCloud: shell script hygiene

From the issue: 1212 open SonarCloud finding(s) in petry-projects/.github, worst severity CRITICAL. Generated by the org SonarCloud Audit.

Risk

Low — changes automation shell logic under scripts/, covered by shellcheck (--severity=warning) and the bats suite.

Test plan

No test files were added or updated. Verification: bash scripts/dev-lead-lint.sh (shellcheck --severity=warning) ran pre-commit; the existing CI (bats + lint) guards the change.

Rollback

Revert this PR. No non-revertible side effects (no tags, migrations, or external state).

Monitoring

This PR's Lint (shellcheck) and bats checks show pass/fail; watch subsequent dev-lead / pr-review runs for behavioral regressions.

Closes #1193

Review in cubic

@don-petry
don-petry requested a review from a team as a code owner September 29, 2026 21:44
@chatgpt-codex-connector

Copy link
Copy Markdown

You have reached your Codex usage limits for code reviews. You can see your limits in the Codex usage dashboard.
To continue using code reviews, you can upgrade your account or add credits to your account and enable them for code reviews in your settings.

@coderabbitai

This comment has been minimized.

@don-petry

Copy link
Copy Markdown
Contributor Author

Dev-Lead — waiting on PR blockers (intent: review-changes)

PR: #1196
No changes were committed, but the PR still can't be marked done: required check SonarCloud is still pending. The retry cron will re-attempt automatically. Next attempt after: 2026-09-29T22:16:54Z

@don-petry

Copy link
Copy Markdown
Contributor Author

Note

@don-petry I reviewed this PR and no code changes were needed, but I can't mark it done yet: required check SonarCloud is still pending. I'll re-check automatically.
Next attempt after: 2026-09-29T22:16:54Z

@don-petry
don-petry enabled auto-merge (squash) September 29, 2026 21:47
Comment thread scripts/pinned-version-report.sh
Comment thread scripts/bootstrap-new-repo.sh
# on this org plan). If a plan-gated key is "disabled" (present, not null),
# that is a failure — the key exists but was not enabled.
if [ "$is_plan_gated" = true ] && [ "$post_actual" = "null" ]; then
if [[ "$is_plan_gated" = true ]] && [[ "$post_actual" = "null" ]]; then

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Suggestion: When GitHub leaves a plan-gated setting disabled after an accepted PATCH, this condition treats it as a failure and makes repository setup fail.

Assessment: 🟠 Major · 🔁 Occurrence: Sometimes · 🏷️ Api mismatch

Use CodeAnt Skill Fix in Cursor Fix in VSCode Claude

Prompt for AI Agent 🤖
This is a comment left during a code review.

**Path:** scripts/lib/push-protection.sh
**Line:** 197:197
**Comment:**
	*Api Mismatch: When GitHub leaves a plan-gated setting disabled after an accepted PATCH, this condition treats it as a failure and makes repository setup fail.

Validate the correctness of the flagged issue. If correct, How can I resolve this? If you propose a fix, implement it and please make it concise.
Once fix is implemented, also check other comments on the same PR, and ask user if the user wants to fix the rest of the comments as well. if said yes, then fetch all the comments validate the correctness and implement a minimal fix
👍 | 👎

Copy link
Copy Markdown
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Skipping — after validation this is a deliberate, documented design decision (#1038, AC6b), not a defect. The apply-path verify models an unavailable plan-gated feature as reporting null (see the secret_scanning_ai_detection note in PP_REQUIRED_SA_SETTINGS: "absent means the feature is unavailable for the current org plan"), and treats a plan-gated key that is present-but-disabled as a genuinely-fixable failure. Unlike the GHAS-gated keys — which have an independent advanced_security.status signal to confirm the plan is absent — there is no plan-status signal to distinguish "disabled because the plan silently ignored the PATCH" from "disabled but enable-able." Treating every disabled plan-gated key as a skip would silently accept a disabled security control, so I'm leaving the fail-closed behavior in place. If GitHub is confirmed to return disabled (not null) for an unavailable plan feature, a maintainer should reopen with that evidence.

fi
done
if [ "$is_plan_gated" = true ] && [ "$actual" = "null" ]; then
if [[ "$is_plan_gated" = true ]] && [[ "$actual" = "null" ]]; then

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Suggestion: When a plan-gated setting is reported as disabled, this condition still creates a compliance finding even though unsupported plans may silently ignore the setting.

Assessment: 🟠 Major · 🔁 Occurrence: Sometimes · 🏷️ Api mismatch

Use CodeAnt Skill Fix in Cursor Fix in VSCode Claude

Prompt for AI Agent 🤖
This is a comment left during a code review.

**Path:** scripts/lib/push-protection.sh
**Line:** 295:295
**Comment:**
	*Api Mismatch: When a plan-gated setting is reported as disabled, this condition still creates a compliance finding even though unsupported plans may silently ignore the setting.

Validate the correctness of the flagged issue. If correct, How can I resolve this? If you propose a fix, implement it and please make it concise.
Once fix is implemented, also check other comments on the same PR, and ask user if the user wants to fix the rest of the comments as well. if said yes, then fetch all the comments validate the correctness and implement a minimal fix
👍 | 👎

Copy link
Copy Markdown
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Skipping — same rationale as the apply-path thread at line 197: this is the deliberate, documented behavior from #1038, not a defect. The audit models an unavailable plan-gated feature as null (skipped, no finding) and a present-but-disabled plan-gated key as a genuinely-fixable finding. There is no independent plan-status signal (as GHAS has via advanced_security.status) to tell "disabled because the plan silently ignores it" apart from "disabled but enable-able," so suppressing a finding for every disabled plan-gated key would let a disabled security control read as compliant. Note the finding is warning severity, not error. Leaving as-is; a maintainer who can confirm the disabled-when-unavailable API behavior should reopen.

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

✅ Customized review instruction saved!

Instruction:

Do not flag plan-gated settings as API mismatches when present-but-disabled values are intentionally treated as fixable findings; only unavailable settings represented as null should be skipped.

Applied to:

  • scripts/lib/push-protection.sh

💡 To manage or update this instruction, visit: CodeAnt AI Settings

Comment thread scripts/lib/push-protection.sh
rc=1; continue
fi
if [ -z "$maintainer" ] || [ "$maintainer" = "—" ] || [ "$maintainer" = "-" ]; then
if [[ -z "$maintainer" ]] || [[ "$maintainer" = "—" ]] || [[ "$maintainer" = "-" ]]; then

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Suggestion: The validator still rejects non-empty maintainer names that are not GitHub handles, contradicting the required non-empty attribution-only rule.

Assessment: 🟠 Major · 🔁 Occurrence: Sometimes · 🏷️ Logic error

Use CodeAnt Skill Fix in Cursor Fix in VSCode Claude

Prompt for AI Agent 🤖
This is a comment left during a code review.

**Path:** scripts/agents-md-cycle-log.sh
**Line:** 140:140
**Comment:**
	*Logic Error: The validator still rejects non-empty maintainer names that are not GitHub handles, contradicting the required non-empty attribution-only rule.

Validate the correctness of the flagged issue. If correct, How can I resolve this? If you propose a fix, implement it and please make it concise.
Once fix is implemented, also check other comments on the same PR, and ask user if the user wants to fix the rest of the comments as well. if said yes, then fetch all the comments validate the correctness and implement a minimal fix
👍 | 👎

Copy link
Copy Markdown
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Skipping — this appears to be a false positive. The required rule for agents-md-cycle-log is not "non-empty attribution only"; the standard requires the "Determined by" field to be a GitHub @handle. That is enforced deliberately (line 144) and covered by an explicit test — tests/agents_md_cycle_log.bats: "validate rejects a maintainer that is not a GitHub @handle" — whose rationale is that arbitrary attribution text like "Alice" is not attribution the append-only log can hold anyone accountable to. Relaxing the validator to accept any non-empty name would regress that tested requirement, so no change. (If the standard itself is meant to change from @handle to free-text attribution, that's a standards-doc decision to make first.)

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

✅ Customized review instruction saved!

Instruction:

Require the 'Determined by' maintainer field to be a GitHub @handle; do not relax validation to accept arbitrary non-empty names.

Applied to:

  • scripts/agents-md-cycle-log.sh

💡 To manage or update this instruction, visit: CodeAnt AI Settings

Comment thread scripts/sonarcloud-audit.sh Outdated
@don-petry

Copy link
Copy Markdown
Contributor Author

No description provided.

Comment thread scripts/canary-rollout.sh Outdated
Comment thread scripts/compliance-audit.sh Outdated
Comment thread scripts/lib/agent-rate-limit.sh
@don-petry
don-petry disabled auto-merge September 29, 2026 21:47
@codeant-ai

This comment has been minimized.

@gemini-code-assist gemini-code-assist Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Code Review

This pull request systematically migrates conditional checks across numerous shell scripts from single brackets [ to double brackets [[ for improved robustness. Additionally, it updates sonar-project.properties to exclude node_modules/** from SonarCloud analysis to prevent third-party code findings. A critical issue was identified in scripts/lib/canary-rollout.sh where using double brackets [[ for numeric comparisons of version components (e.g., _semver_gt) can trigger octal interpretation errors and runtime crashes if components contain leading zeros (like 08 or 09); it is recommended to revert to single brackets [ for these specific comparisons.

Comment thread scripts/lib/canary-rollout.sh Outdated
@qodo-code-review

Copy link
Copy Markdown

ⓘ Qodo reviews are paused because your trial has ended. Ask your workspace admin to add credits to resume reviews. Manage billing

@don-petry

Copy link
Copy Markdown
Contributor Author

Acknowledged — this is a Codex usage-limit notice, not a code finding; no action required on the PR. Code review for this branch is otherwise covered by the other reviewers (CodeAnt, SonarCloud, CodeQL).

@don-petry

This comment has been minimized.

@don-petry

Copy link
Copy Markdown
Contributor Author

Acknowledged — SonarCloud reports the Quality Gate as Passed for this PR; this is a status notice with no finding to action.

@don-petry

Copy link
Copy Markdown
Contributor Author

Reviewed all 4 nitpicks — each is a real, small robustness issue (truncation warning in sonarcloud-audit.sh, missing-vs-empty log in agents-md-cycle-log.sh, --help before token validation in fix-check-suite-prefs.sh, and unexpected-operand rejection in seed-repo-template.sh). They fall outside the defined scope of #1193 (this PR's specific SonarCloud hygiene items), so rather than expand this PR's blast radius I've funneled them into a single follow-up tracking issue for a batched hygiene PR. The seed-repo-template.sh operand nitpick mirrors the fix already applied to bootstrap-new-repo.sh in this PR.

@don-petry

Copy link
Copy Markdown
Contributor Author

Dev-Lead — fix-reviews (partial)

A commit was pushed, but not every requested change was applied. Per requested item:

  • scripts/pinned-version-report.sh:37 — applied
  • scripts/bootstrap-new-repo.sh:463 — not applied
  • scripts/lib/push-protection.sh:197 — not applied
  • scripts/lib/push-protection.sh:295 — not applied
  • scripts/lib/push-protection.sh:367 — applied
  • scripts/agents-md-cycle-log.sh:140 — not applied
  • scripts/sonarcloud-audit.sh:203 — applied
  • scripts/canary-rollout.sh:1266 — applied
  • scripts/compliance-audit.sh:955 — applied
  • scripts/lib/agent-rate-limit.sh:894 — applied

The unaddressed items above still need work.

@don-petry
don-petry enabled auto-merge (squash) September 29, 2026 22:06
@don-petry

don-petry commented Sep 29, 2026 •

Copy link
Copy Markdown
Contributor Author
Resolved — the `needs-human-review` hold was lifted; dev-lead has picked this item up. Click to expand the prior hold notice.

dev-lead is withholding action on this item.

It is labeled needs-human-review (flagged for human review — this label is applied by automation as well as by people, so an item can become held without anyone noticing), so dev-lead will not pick it up while that label is present. This notice is posted once so the withhold is visible rather than looking like a stalled run.

To re-enable automated pickup: remove the needs-human-review label.

@don-petry

Copy link
Copy Markdown
Contributor Author

Dev-Lead — fix-bot-comment (applied)

Changes committed and pushed.

@don-petry
don-petry enabled auto-merge (squash) September 30, 2026 00:15
@don-petry
don-petry disabled auto-merge September 30, 2026 00:17
@don-petry
don-petry enabled auto-merge (squash) October 3, 2026 17:21
@donpetry-bot

Copy link
Copy Markdown
Contributor

No description provided.

@don-petry
don-petry disabled auto-merge October 3, 2026 18:40
@don-petry

Copy link
Copy Markdown
Contributor Author

All actionable code review findings have been addressed in commits on this branch:

  • agents-md-cycle-log.sh: base-10 numeric normalization to prevent octal interpretation
  • compliance-audit.sh: added mark_repo_inconclusive for ruleset-fetch failures
  • agent-rate-limit.sh: normalized failure counts to decimal before comparisons
  • push-protection.sh: handled base64 decode failures in if-condition
  • sonarcloud-audit.sh: added validation to reject empty repository names
  • canary-rollout.sh: prevented --override from clearing AWAITING_CONFIRMATION state

The pre-merge scope/linkage checks are advisory guidance for future PRs, not blocking issues. All CI checks pass.

@don-petry

Copy link
Copy Markdown
Contributor Author

Dev-Lead — fix-bot-comment (no-changes)

Agent reasoning
**Issues addressed:** 6 actionable code findings (all already fixed in current commits)
- `scripts/agents-md-cycle-log.sh:145` — normalized counts to base 10 before arithmetic comparisons ✅ fixed
- `scripts/compliance-audit.sh:1033` — added `mark_repo_inconclusive` call on ruleset-fetch failures ✅ fixed  
- `scripts/lib/agent-rate-limit.sh:307` — normalized failure count to decimal before threshold comparison ✅ fixed
- `scripts/lib/push-protection.sh:366-369` — handled base64 decode failures within if-condition ✅ fixed
- `scripts/sonarcloud-audit.sh:219-222` — added validation to reject empty repository names ✅ fixed
- `scripts/canary-rollout.sh:1464` — prevented `--override` from clearing `AWAITING_CONFIRMATION` state ✅ fixed
**Comment disposition:** Posted `answered` marker to the summary comment noting all code findings addressed; the pre-merge scope/linkage warnings are advisory guidance, not code defects.
**Files changed:** All fixes were already applied in previous commits on this branch. No new changes required.
**Skipped:** Pre-merge check warnings are advisory notes about PR organization/scope relative to issue #1193, not code bugs to fix.

@don-petry
don-petry enabled auto-merge (squash) October 3, 2026 18:42
@don-petry

Copy link
Copy Markdown
Contributor Author

No description provided.

@don-petry
don-petry disabled auto-merge October 3, 2026 21:13
@don-petry
don-petry enabled auto-merge (squash) October 3, 2026 21:15
@donpetry-bot

Copy link
Copy Markdown
Contributor

No description provided.

@don-petry
don-petry disabled auto-merge October 3, 2026 21:54
@don-petry
don-petry enabled auto-merge (squash) October 3, 2026 21:55
@don-petry

Copy link
Copy Markdown
Contributor Author

Auto-rebase failed — merge conflict — this branch has conflicts with main that must be resolved.

dev-lead will attempt to resolve this automatically. If it cannot, a follow-up comment will explain what needs manual attention.

To resolve manually instead:

git fetch origin
git merge origin/main
# resolve conflicts, then:
git add .
git commit
git push

@don-petry
don-petry disabled auto-merge October 3, 2026 22:12
@don-petry

Copy link
Copy Markdown
Contributor Author

Dev-lead rebase aborted: this branch has no merge base with main (unrelated histories). A rebase would replay 543 non-merge commits, and the first one hits an add/add conflict in .github/workflows/org-scorecard.yml. There is no safe mechanical resolution, so I didn't push anything. A maintainer should recreate the branch from current main and cherry-pick the intended commits, or confirm how to proceed.

🤖 Generated with Claude Code

@don-petry

Copy link
Copy Markdown
Contributor Author

Dev-Lead — rebase (failed)

The engine run completed but PR #1196 is still CONFLICTING per GitHub's mergeable state — the rebase did not converge. Recorded as a failure so repeated no-op 'success' runs can no longer accumulate.

@don-petry

Copy link
Copy Markdown
Contributor Author

Auto-rebase failed — merge conflict — this branch has conflicts with main that must be resolved.

dev-lead will attempt to resolve this automatically. If it cannot, a follow-up comment will explain what needs manual attention.

To resolve manually instead:

git fetch origin
git merge origin/main
# resolve conflicts, then:
git add .
git commit
git push

@don-petry

Copy link
Copy Markdown
Contributor Author

Dev-lead rebase aborted: unresolvable add/add conflict in .github/workflows/org-scorecard.yml.

This PR's only unique commit (37b4012) adds org-scorecard.yml, but main already contains a much more evolved version of the same file. Main's version has a SHA-256-verified Scorecard v5.5.0 install, malformed-workflow handling, the Pinned-Dependencies first-party exemption, and a different cron. The PR's version is v5.1.1 with an unverified curl | tar, and reads .aggregate_score where main reads .score. Every hunk conflicts on the same logic, so a merge would either regress main or empty the PR.

Likely resolution: the PR is superseded by main and should be closed. If it intends to change something specific beyond what main has, please re-apply that delta on top of current main. The branch was left untouched and nothing was pushed.

🤖 Generated with Claude Code

@don-petry

Copy link
Copy Markdown
Contributor Author

Dev-Lead — rebase (failed)

The engine run completed but PR #1196 is still CONFLICTING per GitHub's mergeable state — the rebase did not converge. Recorded as a failure so repeated no-op 'success' runs can no longer accumulate.

@don-petry

Copy link
Copy Markdown
Contributor Author

Dev-Lead — rebase (exhausted)

This PR's rebase conflict failed automated resolution 2 time(s) (timeouts or unresolvable conflicts). Automated rebasing is paused to stop repeated full-timeout runs from the auto-rebase-conflict sentinel.

Reason for last failure: The engine run completed but PR #1196 is still CONFLICTING per GitHub's mergeable state — the rebase did not converge. Recorded as a failure so repeated no-op 'success' runs can no longer accumulate.

Resolve the conflict manually, then remove the needs-human-review label and delete this comment to re-enable automated rebasing.

@donpetry-bot

Copy link
Copy Markdown
Contributor

No description provided.

@don-petry

Copy link
Copy Markdown
Contributor Author

All CodeRabbit findings have been addressed in prior commits. Verified fixes in place across scripts/agents-md-cycle-log.sh, scripts/compliance-audit.sh, scripts/lib/agent-rate-limit.sh, scripts/lib/push-protection.sh, scripts/sonarcloud-audit.sh, and scripts/canary-rollout.sh. All CI checks passing.

@don-petry

Copy link
Copy Markdown
Contributor Author

No description provided.

@don-petry

Copy link
Copy Markdown
Contributor Author

Auto-rebase failed — merge conflict — this branch has conflicts with main that must be resolved.

dev-lead will attempt to resolve this automatically. If it cannot, a follow-up comment will explain what needs manual attention.

To resolve manually instead:

git fetch origin
git merge origin/main
# resolve conflicts, then:
git add .
git commit
git push

@donpetry-bot

Copy link
Copy Markdown
Contributor

No description provided.

@don-petry

Copy link
Copy Markdown
Contributor Author

Auto-rebase failed — merge conflict — this branch has conflicts with main that must be resolved.

dev-lead will attempt to resolve this automatically. If it cannot, a follow-up comment will explain what needs manual attention.

To resolve manually instead:

git fetch origin
git merge origin/main
# resolve conflicts, then:
git add .
git commit
git push

@don-petry

Copy link
Copy Markdown
Contributor Author

Auto-rebase failed — merge conflict — this branch has conflicts with main that must be resolved.

dev-lead will attempt to resolve this automatically. If it cannot, a follow-up comment will explain what needs manual attention.

To resolve manually instead:

git fetch origin
git merge origin/main
# resolve conflicts, then:
git add .
git commit
git push

@don-petry

Copy link
Copy Markdown
Contributor Author

Auto-rebase failed — merge conflict — this branch has conflicts with main that must be resolved.

dev-lead will attempt to resolve this automatically. If it cannot, a follow-up comment will explain what needs manual attention.

To resolve manually instead:

git fetch origin
git merge origin/main
# resolve conflicts, then:
git add .
git commit
git push

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

SonarCloud: shell script hygiene

2 participants