aws-samples / aws-samples/sample-autonomous-cloud-coding-agents

Security suite failed (main @ db52d5f)

Open
#593 1 comment 0 reactions 0 assignees View on GitHub
bug
Dominant language
TypeScript
Stars
143
Forks
46
Avg merge
3d 9h
Merged PRs (30d)
20

Description

The root `mise run security` suite failed in GitHub Actions. Use the log tail below and reproduce locally with the same command.

| Field | Value |
| --- | --- |
| Workflow run | [Security #15](https://github.com/aws-samples/sample-autonomous-cloud-coding-agents/actions/runs/29251309033) |
| Ref | `refs/heads/main` |
| SHA | [`db52d5fa7f4d3b66b8f25202e690ae54e4270f13`](https://github.com/aws-samples/sample-autonomous-cloud-coding-agents/commit/db52d5fa7f4d3b66b8f25202e690ae54e4270f13) |
| Actor | @krokoko |
| Event | `schedule` |

### Log tail (last 200 lines)

```text
[//:security:secrets] $ gitleaks git . --no-banner --redact
12:50PM INF 811 commits scanned.
12:50PM INF scanned ~26025917 bytes (26.03 MB) in 3.22s
12:50PM INF no leaks found
[//:security:deps] $ osv-scanner scan --lockfile agent/uv.lock --lockfile yarn.lock
Starting filesystem walk for root: /
Scanned /home/runner/work/sample-autonomous-cloud-coding-agents/sample-autonomous-cloud-coding-agents/agent/uv.lock file and found 128 packages
Scanned /home/runner/work/sample-autonomous-cloud-coding-agents/sample-autonomous-cloud-coding-agents/yarn.lock file and found 1156 packages
End status: 0 dirs visited, 2 inodes visited, 2 Extract calls, 35.973331ms elapsed, 35.973511ms wall time

No issues found
[//:security:sast] $ semgrep scan --config auto --config p/python --config p/typescript --config p/owasp-top-ten --config p/security-audit --error --quiet .
[//:security:sast:masking] $ semgrep test .semgrep/
2/2: ✓ All tests passed
No tests for fixes found.
[//:security:sast:masking] $ mkdir -p test-reports
[//:security:sast:masking] $ semgrep scan --config .semgrep/silent-success-masking.yaml --exclude '.semgrep/*' --sarif-output=test-reports/semgrep-silent-success-masking.sarif --error --quiet .


┌─────────────────┐
│ 7 Code Findings │
└─────────────────┘

agent/src/config.py
❯❱ semgrep.py-silent-success-masking
❰❰ Blocking ❱❱
This except block swallows the error and returns an empty default, so the caller cannot distinguish
failure from a genuinely empty result (silent-success masking, AI004). Fix: re-raise (`raise`),
raise a typed error that adds context (`raise XError(...) from exc`), or return a result shape that
encodes the failure. Logging alone is not enough — the failure must reach the caller. If this
fallback is intentional degraded-mode behavior, keep it and add on the return line "# nosemgrep: py-
silent-success-masking -- ".

392┆ return ""
⋮┆----------------------------------------
406┆ return None
⋮┆----------------------------------------
428┆ return ""

agent/src/observability.py
❯❱ semgrep.py-silent-success-masking
❰❰ Blocking ❱❱
This except block swallows the error and returns an empty default, so the caller cannot distinguish
failure from a genuinely empty result (silent-success masking, AI004). Fix: re-raise (`raise`),
raise a typed error that adds context (`raise XError(...) from exc`), or return a result shape that
encodes the failure. Logging alone is not enough — the failure must reach the caller. If this
fallback is intentional degraded-mode behavior, keep it and add on the return line "# nosemgrep: py-
silent-success-masking -- ".

86┆ return None

cdk/src/handlers/shared/jira-feedback.ts
❯❱ semgrep.ts-silent-success-masking
❰❰ Blocking ❱❱
This catch block swallows the error and returns an empty default, so the caller cannot distinguish
failure from a genuinely empty result (silent-success masking, AI004). Fix: re-throw (`throw err;`),
throw a typed error that adds context, or return a result shape that encodes the failure. Logging
alone is not enough — the failure must reach the caller. If this fallback is intentional degraded-
mode behavior, keep it and add on the return line "// nosemgrep: ts-silent-success-masking -- ".

152┆ return null;

cli/src/commands/jira.ts
❯❱ semgrep.ts-silent-success-masking
❰❰ Blocking ❱❱
This catch block swallows the error and returns an empty default, so the caller cannot distinguish
failure from a genuinely empty result (silent-success masking, AI004). Fix: re-throw (`throw err;`),
throw a typed error that adds context, or return a result shape that encodes the failure. Logging
alone is not enough — the failure must reach the caller. If this fallback is intentional degraded-
mode behavior, keep it and add on the return line "// nosemgrep: ts-silent-success-masking -- ".

434┆ return null;

cli/src/commands/linear.ts
❯❱ semgrep.ts-silent-success-masking
❰❰ Blocking ❱❱
This catch block swallows the error and returns an empty default, so the caller cannot distinguish
failure from a genuinely empty result (silent-success masking, AI004). Fix: re-throw (`throw err;`),
throw a typed error that adds context, or return a result shape that encodes the failure. Logging
alone is not enough — the failure must reach the caller. If this fallback is intentional degraded-
mode behavior, keep it and add on the return line "// nosemgrep: ts-silent-success-masking -- ".

1630┆ return [];

[//:security:sast:masking] ERROR task failed
```

Close this issue after `mise run security` succeeds on `main` (or the branch you merge to).

Contributor guide

Open the contributing guide

Research direction

Start with the five findings in agent/src/config.py, agent/src/observability.py, cdk/src/handlers/shared/jira-feedback.ts, cli/src/commands/jira.ts, and cli/src/commands/linear.ts. Reproduce with `mise run security`, review each silent-success-masking result, and ensure the intended error handling is explicit so the command completes successfully on the branch merged to main.

Written by the indexing model from the issue text.

Assessment

Tech stack
github-actions, python, typescript
Domain
ci-cd, security
Issue type
Bug
Difficulty
3/5
Estimated time
1-2 days
Activity status
Quiet
Clarity
Mostly clear
Newbie friendliness
52/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.