Skip to content

B5: Codeac analyze results fails on every PR — analysis crash from A1 invalid JSON (+ commit processing timeout) #90

Description

@arena-ai-coding-agent

Audit follow-up. The Codeac analyze results check (Codeac GitHub App) fails on every PR (e.g. PR #81). It is not a required context — PRs merge anyway — but it is permanent red noise.

Findings (from the Codeac analysis page for the last commit + Codeac's own docs at codeac.io/documentation/thresholds.html):

  1. The fail state is an analysis crash, not findings. Codeac docs: "If the threshold is not specified, Codeac will signal a success to all commits with finished analysis. The failed state is used only when the whole analysis fails, for example with configuration issues or other errors." — this repo has no .codeac.yml thresholds, so its ~31k findings alone would still report success.
  2. The crash: ESLint 8.57.1 aborted on praxis/SymbolicEngine/graphql/package.json — Error: Expected double-quoted property name in JSON at position 1399 — i.e. exactly issue A1: praxis/SymbolicEngine/graphql/package.json is invalid JSON (trailing comma after "bun-types") #82's invalid JSON. Plus "Processing of this commit timed out."

So: fixing #82 removes the ESLint crash and is the in-repo fix for this check. The residual risk is the processing timeout on this monorepo's volume.

It IS configurable: per-tool native configs (ESLint, PHPMD, SCSS Lint, jscpd via .jscpd.json, ignore files like .codesizeignore), and optional .codeac.yml thresholds. But the analysis set (phpmd clean-code rules like CamelCase* on WordPress-style PHP, scsslint style rules on journal-theme) will keep producing thousands of style findings this codebase will never "fix", and taming that means maintaining several suppression configs.

Recommendation: fix #82 and re-check on the follow-up PR. If analysis still times out or keeps failing for tool crashes, disable it (uninstall the Codeac GitHub App or at least keep it out of required contexts) — it duplicates CodeFactor + Semgrep + GitGuardian + Hypatia Security Scan + gitleaks, which all pass here.

Verification plan: watch this check on the fixing PR; close this issue if it goes green after #82 lands.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions