From the round-4 review of #212 (follows #239).
Where: scripts/fleet/check_cards.py main() and check().
main() runs json.loads on the audit, and check() walks audit["repositories"] without checking its shape. Invalid JSON, a list at the top level, or a repositories entry without repo raises before any row prints. That undercuts #239, which runs the check after a failed test step precisely so its report prints. The dependency on the audit is new in this PR.
Fix: load and shape-check the audit inside the check, and report any problem as an AUDIT row, as pin-time errors already are.
From the round-4 review of #212 (follows #239).
Where:
scripts/fleet/check_cards.pymain()andcheck().main()runsjson.loadson the audit, andcheck()walksaudit["repositories"]without checking its shape. Invalid JSON, a list at the top level, or a repositories entry withoutreporaises before any row prints. That undercuts #239, which runs the check after a failed test step precisely so its report prints. The dependency on the audit is new in this PR.Fix: load and shape-check the audit inside the check, and report any problem as an AUDIT row, as pin-time errors already are.