Docs menu

CI must not be told to ignore failures

WARN Frame app-correctness/no-weakened-ci

Flags CI settings that let a failing step or job pass:

  • continue-on-error: true (GitHub Actions)
  • allow_failure: true (GitLab CI)
  • || true and || exit 0 after a command
  • set +e in a script step

Scanned files: .github/workflows/*.yml, .gitlab-ci.yml, .circleci/config.yml, bitbucket-pipelines.yml, azure-pipelines.yml, .woodpecker.yml and .woodpecker/*.yml, .drone.yml, .buildkite/pipeline.yml, Jenkinsfile. Comment lines are ignored.

Why it matters with coding agents: when CI fails, making the step “not fail” is a one-line change that turns the pipeline green without fixing anything.

WARN only: nothing is blocked. The frame sees the files as pushed, so it reports every unmarked case present, not only new ones; after a one-time pass to fix or mark the existing ones, each warning is a new shortcut.

Fix#

Let the step fail and fix the cause. If a step may fail by design (an optional upload, a best-effort cache step), record why: a whitelist entry with a reason, or # appframes:disable-next-line app-correctness/no-weakened-ci on the line above.

WARN lets the push through and records the finding. Turn frames on per repo on the dashboard's Policy page - see choosing what the gate checks.

Source on GitHub Live demo How it works Questions: contact@nimblegate.com