Skip to content

refactor(ci): satisfy the shell analysis the way SonarCloud asks, not around it - #53

Merged
hyperpolymath merged 2 commits into
mainfrom
ci/sonar-shell-followup
Sep 22, 2026
Merged

hyperpolymath merged 2 commits into
mainfrom
ci/sonar-shell-followup

Conversation

@hyperpolymath

Copy link
Copy Markdown
Owner

SonarCloud flagged the helper in #51 after that PR merged (the analysis ran late). Both
findings are fair for a script that is sourced into a bash workflow step:

  • [ over [[ — the script is bash (#!/usr/bin/env bash, and the step sources it
    into bash), so [[ is strictly better: no word splitting, no pathname expansion, and
    a -eq that cannot be talked into a string comparison.
  • Diagnostics on stdout — the ::error:: annotations now go to stderr. GitHub
    Actions reads workflow commands from either stream, so the annotations are unchanged;
    what changes is that a failure message no longer lands in a caller's captured stdout.

Behaviour is unchanged, and I re-verified it after the edit against the same real
failure modes rather than trusting the diff: a good download with the matching checksum
passes, an empty body is refused with its message on stderr, and an HTTP 404 still fails.
The pin test that guards the wiring passes 123/123; check-format and check-spdx
are clean.

Nothing is skipped or suppressed to make the analysis green — the tool's advice and the
script's behaviour agree here, so the script changed.

… around it

SonarCloud flagged the helper on two counts, both fair for a bash script
that is sourced into a bash workflow step:

- `[` over `[[`. The script runs under bash (`#!/usr/bin/env bash`, and
  the workflow sources it into a bash step), so `[[` is strictly the
  better construct: no word splitting, no pathname expansion, and a
  `-eq` that cannot be talked into a string comparison.
- Diagnostics on stdout. The `::error::` annotations now go to stderr.
  GitHub Actions reads workflow commands from either stream, so the
  annotations are unchanged; what changes is that a failure message no
  longer lands in a caller's captured stdout.

Behaviour is unchanged and re-verified against the same real failure
modes after the edit: a good download with the matching checksum passes,
an empty body is refused with its message on stderr, an HTTP 404 still
fails, and the pin test that guards the wiring still passes 123/123.
@coderabbitai

coderabbitai Bot commented Sep 22, 2026

Copy link
Copy Markdown

Review in Change Stack →

Navigate logical layers of code changes, visualize relationships, and explore their blast radius.

Note

Currently processing new changes in this PR. This may take a few minutes, please wait...

⚙️ Run configuration

Configuration used: Organization UI

Review profile: ASSERTIVE

Plan: Advanced

Run ID: 1d9d4f6a-3744-42a0-8d3e-2985308aa941

📥 Commits

Reviewing files that changed from the base of the PR and between 387fff5 and 7662f96.

📒 Files selected for processing (1)
  • scripts/ci/fetch_pinned.sh
 ______________________________________________________________________________________________________________________________________________________________________________________________________
< Debugging is twice as hard as writing the code in the first place. Therefore, if you write the code as cleverly as possible, you are, by definition, not smart enough to debug it. - Brian Kernighan >
 ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------
  \
   \   (\__/)
       (•ㅅ•)
       /   づ
✨ Finishing Touches
📝 Generate docstrings
  • Commit to this branch
  • Create a new PR

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@hyperpolymath
hyperpolymath merged commit 1a71048 into main Sep 22, 2026
@hyperpolymath
hyperpolymath deleted the ci/sonar-shell-followup branch September 22, 2026 10:04
@sonarqubecloud

Copy link
Copy Markdown

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant