Fix compliance audit violation detection

Co-authored-by: Adam Moussa <amoussa1229@users.noreply.github.com>
This commit is contained in:
Cursor Agent 2026-05-11 20:31:40 +00:00
parent 4c8c033174
commit 2dc8a6e0e0
No known key found for this signature in database

View file

@ -70,6 +70,7 @@ jobs:
path: .engineering-handbook
- name: Run compliance audit
id: audit
uses: anthropics/claude-code-action@v1
with:
anthropic_api_key: ${{ secrets.ANTHROPIC_API_KEY }}
@ -87,12 +88,20 @@ jobs:
- **SAM layout:** template.yaml at root, samconfig.toml gitignored with .example committed, src/ directory structure
- **Project hygiene:** README describes architecture, .gitignore covers .env/.aws-sam/__pycache__, CloudFormation outputs include ARNs and URLs
Output a concise markdown report with pass/fail per item. Only flag actual violations — skip items that don't apply to this repo (e.g., skip Lambda checks if no Lambdas exist).
Return structured output with:
- `has_violations`: true only when one or more actual compliance violations are found.
- `report`: a concise markdown report with pass/fail per applicable item.
Only flag actual violations — skip items that don't apply to this repo (e.g., skip Lambda checks if no Lambdas exist).
Do not create or modify files, issues, pull requests, or comments.
claude_args: |
--json-schema '{"type":"object","properties":{"has_violations":{"type":"boolean","description":"True when one or more actual compliance violations are found."},"report":{"type":"string","description":"Concise markdown report with pass/fail per applicable compliance item."}},"required":["has_violations","report"],"additionalProperties":false}'
- name: Create issue if violations found
if: failure()
if: ${{ fromJSON(steps.audit.outputs.structured_output).has_violations == true }}
env:
GH_TOKEN: ${{ steps.app-token.outputs.token }}
AUDIT_RESULT: ${{ steps.audit.outputs.structured_output }}
run: |
gh label create compliance \
--repo "Sea-Haven-Industries/${{ matrix.repo }}" \
@ -105,9 +114,20 @@ jobs:
--json number \
--jq 'length')
if [ "$existing" -eq 0 ]; then
report=$(jq -r '.report' <<< "$AUDIT_RESULT")
body_file=$(mktemp)
{
echo "The weekly compliance audit found violations in this repo."
echo
echo "## Audit report"
echo
printf '%s\n' "$report"
echo
echo "Check the [latest audit run](https://github.com/Sea-Haven-Industries/.github/actions/workflows/compliance-audit.yaml) for details."
} > "$body_file"
gh issue create \
--repo "Sea-Haven-Industries/${{ matrix.repo }}" \
--title "Compliance audit: violations found" \
--body "The weekly compliance audit found violations in this repo. Check the [latest audit run](https://github.com/Sea-Haven-Industries/.github/actions/workflows/compliance-audit.yaml) for details." \
--body-file "$body_file" \
--label "compliance"
fi