fix(ci): fail-closed hardening trio — BP-404 + tracker-lint + SOP_FAIL_OPEN (core) #2363

Merged
devops-engineer merged 3 commits from fix/fail-closed-hardening-trio into main 2026-06-06 21:57:49 +00:00
@@ -305,9 +305,9 @@ def validate_tracker(
if status == "error":
sys.stderr.write(
f"::error::issue {slug}#{num} fetch errored — treating as "
f"unverified, skipping this check.\n"
f"unverified, FAILING CLOSED (do not skip on outage).\n"
)
return (True, "fetch-error — skipped")
return (False, f"{slug}#{num} fetch erroredcannot verify tracker")
assert payload is not None
state = payload.get("state", "")