mirror of
https://github.com/Sea-Haven-Industries/.github.git
synced 2026-09-30 09:23:11 +00:00
Fix compliance audit violation detection
Co-authored-by: Adam Moussa <amoussa1229@users.noreply.github.com>
This commit is contained in:
parent
4c8c033174
commit
2dc8a6e0e0
1 changed files with 23 additions and 3 deletions
26
.github/workflows/compliance-audit.yaml
vendored
26
.github/workflows/compliance-audit.yaml
vendored
|
|
@ -70,6 +70,7 @@ jobs:
|
|||
path: .engineering-handbook
|
||||
|
||||
- name: Run compliance audit
|
||||
id: audit
|
||||
uses: anthropics/claude-code-action@v1
|
||||
with:
|
||||
anthropic_api_key: ${{ secrets.ANTHROPIC_API_KEY }}
|
||||
|
|
@ -87,12 +88,20 @@ jobs:
|
|||
- **SAM layout:** template.yaml at root, samconfig.toml gitignored with .example committed, src/ directory structure
|
||||
- **Project hygiene:** README describes architecture, .gitignore covers .env/.aws-sam/__pycache__, CloudFormation outputs include ARNs and URLs
|
||||
|
||||
Output a concise markdown report with pass/fail per item. Only flag actual violations — skip items that don't apply to this repo (e.g., skip Lambda checks if no Lambdas exist).
|
||||
Return structured output with:
|
||||
- `has_violations`: true only when one or more actual compliance violations are found.
|
||||
- `report`: a concise markdown report with pass/fail per applicable item.
|
||||
|
||||
Only flag actual violations — skip items that don't apply to this repo (e.g., skip Lambda checks if no Lambdas exist).
|
||||
Do not create or modify files, issues, pull requests, or comments.
|
||||
claude_args: |
|
||||
--json-schema '{"type":"object","properties":{"has_violations":{"type":"boolean","description":"True when one or more actual compliance violations are found."},"report":{"type":"string","description":"Concise markdown report with pass/fail per applicable compliance item."}},"required":["has_violations","report"],"additionalProperties":false}'
|
||||
|
||||
- name: Create issue if violations found
|
||||
if: failure()
|
||||
if: ${{ fromJSON(steps.audit.outputs.structured_output).has_violations == true }}
|
||||
env:
|
||||
GH_TOKEN: ${{ steps.app-token.outputs.token }}
|
||||
AUDIT_RESULT: ${{ steps.audit.outputs.structured_output }}
|
||||
run: |
|
||||
gh label create compliance \
|
||||
--repo "Sea-Haven-Industries/${{ matrix.repo }}" \
|
||||
|
|
@ -105,9 +114,20 @@ jobs:
|
|||
--json number \
|
||||
--jq 'length')
|
||||
if [ "$existing" -eq 0 ]; then
|
||||
report=$(jq -r '.report' <<< "$AUDIT_RESULT")
|
||||
body_file=$(mktemp)
|
||||
{
|
||||
echo "The weekly compliance audit found violations in this repo."
|
||||
echo
|
||||
echo "## Audit report"
|
||||
echo
|
||||
printf '%s\n' "$report"
|
||||
echo
|
||||
echo "Check the [latest audit run](https://github.com/Sea-Haven-Industries/.github/actions/workflows/compliance-audit.yaml) for details."
|
||||
} > "$body_file"
|
||||
gh issue create \
|
||||
--repo "Sea-Haven-Industries/${{ matrix.repo }}" \
|
||||
--title "Compliance audit: violations found" \
|
||||
--body "The weekly compliance audit found violations in this repo. Check the [latest audit run](https://github.com/Sea-Haven-Industries/.github/actions/workflows/compliance-audit.yaml) for details." \
|
||||
--body-file "$body_file" \
|
||||
--label "compliance"
|
||||
fi
|
||||
|
|
|
|||
Loading…
Add table
Reference in a new issue