CI Mode
Use --ci to enforce the configured risk threshold, policy requirements, and optional unknown-SQL gate.
Basic
bash
pgfence analyze --ci migrations/*.sql With the default --max-risk high threshold, CRITICAL findings fail. Error-level policy violations still fail independently of the risk threshold.
Custom Threshold
bash
pgfence analyze --ci --max-risk medium migrations/*.sql With --max-risk medium, HIGH or CRITICAL findings fail.
Exit Codes
| Code | Meaning |
|---|---|
| 0 | The command completed and the configured gate passed |
| 1 | Risk threshold exceeded, policy error, blocked unknown SQL, trace mismatch, or command error |
| 2 | The entire run analyzed zero SQL statements, or a bin-like launch could not be confirmed safely |
Exit 2 is a fail-closed state, not a stricter risk finding. Raising --max-risk does not change it. See the CLI reference for the complete meaning.