CI must not be told to ignore failures
Flags CI settings that let a failing step or job pass:
continue-on-error: true(GitHub Actions)allow_failure: true(GitLab CI)|| trueand|| exit 0after a commandset +ein a script step
Scanned files: .github/workflows/*.yml, .gitlab-ci.yml,
.circleci/config.yml, bitbucket-pipelines.yml, azure-pipelines.yml,
.woodpecker.yml and .woodpecker/*.yml, .drone.yml,
.buildkite/pipeline.yml, Jenkinsfile. Comment lines are ignored.
Why it matters with coding agents: when CI fails, making the step “not fail” is a one-line change that turns the pipeline green without fixing anything.
WARN only: nothing is blocked. The frame sees the files as pushed, so it reports every unmarked case present, not only new ones; after a one-time pass to fix or mark the existing ones, each warning is a new shortcut.
Fix#
Let the step fail and fix the cause. If a step may fail by design (an
optional upload, a best-effort cache step), record why: a whitelist entry with
a reason, or # appframes:disable-next-line app-correctness/no-weakened-ci on
the line above.
WARN lets the push through and records the finding. Turn frames on per repo on the dashboard's Policy page - see choosing what the gate checks.
Source on GitHub Live demo How it works Questions: contact@nimblegate.com