Skip to content

Commit bc1a463

Browse files
aringuyen3claude
andcommitted
fix: align the base-URL test with this trunk, and stop Bandit failing on reporting
Two failures on the promote pull request, both caught by CI on the staged commits rather than in production. tests/test_client.py asserted the default base URL is http://localhost:5003. This trunk's src/agentex/_client.py resolves https://agentex.sgp.scale.com, which is what stainless.yml configures; production is the stale side of that pair. The restore in 73ea73e took the whole tests/ tree from production and so pulled the old assertion back with it -- the one file there where production was behind rather than ahead. 1739 tests passed and only these two failed, which is what confined the mistake to this assertion. Bandit's "Send unified results to logging cluster" step is annotated `shell: bash {0} # don't fail the job if the logging fails`, but that only drops `-e`: a step still fails when its LAST command fails, and curl was the last command. Neither this repo nor the production repo defines N8N_PRODSEC_ACTIONS_ENDPOINT or _TOKEN, so curl exited 2 ("no URL specified") and failed the Bandit job on every run. Now it skips with a visible warning when the endpoint is unset and tolerates a failed POST, matching the intent already stated in the step. The scan itself is unchanged and still runs. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
1 parent 73ea73e commit bc1a463

2 files changed

Lines changed: 20 additions & 7 deletions

File tree

‎.github/workflows/bandit-ci.yml‎

Lines changed: 18 additions & 5 deletions
Original file line numberDiff line numberDiff line change
@@ -60,10 +60,23 @@ jobs:
6060
# directly, so size is irrelevant; it wraps the file's values in an array, hence [0].
6161
jq --slurpfile scanResults tmp.json '.results += $scanResults[0]' tmp-output.json > output.json
6262
- name: Send unified results to logging cluster
63+
# `shell: bash {0}` drops `-e`, but a step still fails when its LAST command does,
64+
# and curl was the last command -- so a repo without these secrets failed the whole
65+
# Bandit job on a reporting problem, contradicting the intent stated right here.
66+
# Neither this repo nor the production repo defines them, so this failed every run.
67+
# Stay non-fatal, but say so rather than reporting nothing silently.
6368
shell: bash {0} # don't fail the job if the logging fails
69+
env:
70+
ENDPOINT: ${{ secrets.N8N_PRODSEC_ACTIONS_ENDPOINT }}
71+
TOKEN: ${{ secrets.N8N_PRODSEC_ACTIONS_TOKEN }}
6472
run: |
65-
curl -X POST \
66-
-H "Content-Type: application/json" \
67-
-H "Authorization: Bearer ${{ secrets.N8N_PRODSEC_ACTIONS_TOKEN }}" \
68-
-d @./output.json \
69-
${{ secrets.N8N_PRODSEC_ACTIONS_ENDPOINT }}
73+
if [ -z "${ENDPOINT:-}" ]; then
74+
echo "::warning title=Bandit results not reported::N8N_PRODSEC_ACTIONS_ENDPOINT is not set on this repository, so the scan results were not sent to the logging cluster. The scan itself ran and its findings are in the job log."
75+
exit 0
76+
fi
77+
curl -sS -X POST \
78+
-H "Content-Type: application/json" \
79+
-H "Authorization: Bearer ${TOKEN}" \
80+
-d @./output.json \
81+
"$ENDPOINT" \
82+
|| echo "::warning title=Bandit results not reported::the POST to the logging cluster failed; the scan itself still ran."

‎tests/test_client.py‎

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -719,7 +719,7 @@ def test_base_url_env(self) -> None:
719719
Agentex(api_key=api_key, _strict_response_validation=True, environment="production")
720720

721721
client = Agentex(base_url=None, api_key=api_key, _strict_response_validation=True, environment="production")
722-
assert str(client.base_url).startswith("http://localhost:5003")
722+
assert str(client.base_url).startswith("https://agentex.sgp.scale.com")
723723

724724
client.close()
725725

@@ -1652,7 +1652,7 @@ async def test_base_url_env(self) -> None:
16521652
client = AsyncAgentex(
16531653
base_url=None, api_key=api_key, _strict_response_validation=True, environment="production"
16541654
)
1655-
assert str(client.base_url).startswith("http://localhost:5003")
1655+
assert str(client.base_url).startswith("https://agentex.sgp.scale.com")
16561656

16571657
await client.close()
16581658

0 commit comments

Comments
 (0)