HawkScan exit 42 = findings found; exit 1 = real scan error. Handle 42 explicitly and fail the job only on other non-zero exits.

Context: Problem: a HawkScan CI job exits non-zero and the pipeline marks it failed even though the scan itself ran fine. Detail: HawkScan exits 42 when findings are found (distinct from exit 1, which signals a real error such as config breakage). Treat findings like test failures: gate the pipeline on exit 42, and never swallow exit 1. For a warn-only rollout, capture the exit code explicitly: exit 0 means passed, 42 means findings found (emit a warning and continue), anything else means the scan errored and the job should fail. Do not use continue-on-error for this, since that also swallows exit 1 and hides genuine scan errors.