[hermes] soteria #277: sonarqube_analysis_failure #1

Open
opened 2026-08-06 05:20:33 +00:00 by bstein · 0 comments
Owner

Hermes auto-triage classified incident soteria/277 as sonarqube_analysis_failure (confidence 0.96); first failed gate: sonarqube: SonarQube Go analysis could not parse internal/server/policy_runtime.go (external parser exit value 2).

Why a human is needed

A human must correct the Sonar analysis environment or repository/parser incompatibility, including ensuring Node.js is present if TypeScript analysis is required, then rerun the pipeline.

Facts

  • jenkins — Jenkins build soteria #277 finished with result FAILURE and exit code 1. (https://ci.bstein.dev/job/soteria/277/; console tail)
  • jenkins — During the enforced "Collect SonarQube and supply-chain evidence" stage, SonarQube reported that it could not parse internal/server/policy_runtime.go because its Go parser external process returned exit value 2 at 04:40:21.489. (console_failures[2], lines 04:40:21.488-04:40:21.489)
  • jenkins — Later in the same SonarQube analysis, the TypeScript analyzer failed to run "node -v" because the node executable was absent, with java.io.IOException: Cannot run program "node": error=2, No such file or directory. (console_failures[3] and console_failures[4], 04:40:29.008-04:40:29.010)
  • opensearch — The Jenkins agent pod was created, provisioned successfully, and reached Running before the build; termination occurred after the failed build completed. (kube-2026.08.06 records at 2026-08-06T04:34:40.997Z through 2026-08-06T05:19:21.437Z)

Inferences

  • The first enforced failure is the SonarQube analysis failure in the SonarQube-and-supply-chain evidence stage, first evidenced by the Go parser error for internal/server/policy_runtime.go; the missing Node.js executable is an additional later SonarQube analysis defect.
  • The available evidence does not show a connectivity, registry, DNS, TLS, image-pull, or other transient infrastructure failure, so retry_transient_infra is not justified.
  • Failed build: https://ci.bstein.dev/job/soteria/277/
  • Full evidence bundle and audit trail live in Ariadne at /api/admin/audit/events, event types hermes_autotriage_incident and hermes_autotriage_diagnosis.

Filed automatically by Ariadne from a Hermes Agent diagnosis (run run_ca7fda6135464ccf9a662dd70688ef1d). Hermes has no write access to this repository; no files or infrastructure were changed.

Hermes auto-triage classified incident `soteria/277` as **sonarqube_analysis_failure** (confidence 0.96); first failed gate: `sonarqube: SonarQube Go analysis could not parse internal/server/policy_runtime.go (external parser exit value 2)`. ## Why a human is needed A human must correct the Sonar analysis environment or repository/parser incompatibility, including ensuring Node.js is present if TypeScript analysis is required, then rerun the pipeline. ## Facts - **jenkins** — Jenkins build soteria #277 finished with result FAILURE and exit code 1. (`https://ci.bstein.dev/job/soteria/277/; console tail`) - **jenkins** — During the enforced "Collect SonarQube and supply-chain evidence" stage, SonarQube reported that it could not parse internal/server/policy_runtime.go because its Go parser external process returned exit value 2 at 04:40:21.489. (`console_failures[2], lines 04:40:21.488-04:40:21.489`) - **jenkins** — Later in the same SonarQube analysis, the TypeScript analyzer failed to run "node -v" because the node executable was absent, with java.io.IOException: Cannot run program "node": error=2, No such file or directory. (`console_failures[3] and console_failures[4], 04:40:29.008-04:40:29.010`) - **opensearch** — The Jenkins agent pod was created, provisioned successfully, and reached Running before the build; termination occurred after the failed build completed. (`kube-2026.08.06 records at 2026-08-06T04:34:40.997Z through 2026-08-06T05:19:21.437Z`) ## Inferences - The first enforced failure is the SonarQube analysis failure in the SonarQube-and-supply-chain evidence stage, first evidenced by the Go parser error for internal/server/policy_runtime.go; the missing Node.js executable is an additional later SonarQube analysis defect. - The available evidence does not show a connectivity, registry, DNS, TLS, image-pull, or other transient infrastructure failure, so retry_transient_infra is not justified. ## Links - Failed build: https://ci.bstein.dev/job/soteria/277/ - Full evidence bundle and audit trail live in Ariadne at `/api/admin/audit/events`, event types `hermes_autotriage_incident` and `hermes_autotriage_diagnosis`. Filed automatically by Ariadne from a Hermes Agent diagnosis (run `run_ca7fda6135464ccf9a662dd70688ef1d`). Hermes has no write access to this repository; no files or infrastructure were changed. <!-- hermes-triage job=soteria classification=sonarqube_analysis_failure incident=soteria/277 -->
Sign in to join this conversation.
No Label
1 Participants
Notifications
Due Date
No due date set.
Dependencies

No dependencies set.

Reference: titan/soteria#1
No description provided.