CI Mode

Use --ci to enforce the configured risk threshold, policy requirements, and optional unknown-SQL gate.

Basic

bash
pgfence analyze --ci migrations/*.sql

With the default --max-risk high threshold, CRITICAL findings fail. Error-level policy violations still fail independently of the risk threshold.

Custom Threshold

bash
pgfence analyze --ci --max-risk medium migrations/*.sql

With --max-risk medium, HIGH or CRITICAL findings fail.

Exit Codes

CodeMeaning
0The command completed and the configured gate passed
1Risk threshold exceeded, policy error, blocked unknown SQL, trace mismatch, or command error
2The entire run analyzed zero SQL statements, or a bin-like launch could not be confirmed safely

Exit 2 is a fail-closed state, not a stricter risk finding. Raising --max-risk does not change it. See the CLI reference for the complete meaning.