diff --git a/.github/workflows/compliance-audit.yaml b/.github/workflows/compliance-audit.yaml index 7ee18e6..dff1e85 100644 --- a/.github/workflows/compliance-audit.yaml +++ b/.github/workflows/compliance-audit.yaml @@ -70,6 +70,7 @@ jobs: path: .engineering-handbook - name: Run compliance audit + id: audit uses: anthropics/claude-code-action@v1 with: anthropic_api_key: ${{ secrets.ANTHROPIC_API_KEY }} @@ -87,12 +88,20 @@ jobs: - **SAM layout:** template.yaml at root, samconfig.toml gitignored with .example committed, src/ directory structure - **Project hygiene:** README describes architecture, .gitignore covers .env/.aws-sam/__pycache__, CloudFormation outputs include ARNs and URLs - Output a concise markdown report with pass/fail per item. Only flag actual violations — skip items that don't apply to this repo (e.g., skip Lambda checks if no Lambdas exist). + Return structured output with: + - `has_violations`: true only when one or more actual compliance violations are found. + - `report`: a concise markdown report with pass/fail per applicable item. + + Only flag actual violations — skip items that don't apply to this repo (e.g., skip Lambda checks if no Lambdas exist). + Do not create or modify files, issues, pull requests, or comments. + claude_args: | + --json-schema '{"type":"object","properties":{"has_violations":{"type":"boolean","description":"True when one or more actual compliance violations are found."},"report":{"type":"string","description":"Concise markdown report with pass/fail per applicable compliance item."}},"required":["has_violations","report"],"additionalProperties":false}' - name: Create issue if violations found - if: failure() + if: ${{ fromJSON(steps.audit.outputs.structured_output).has_violations == true }} env: GH_TOKEN: ${{ steps.app-token.outputs.token }} + AUDIT_RESULT: ${{ steps.audit.outputs.structured_output }} run: | gh label create compliance \ --repo "Sea-Haven-Industries/${{ matrix.repo }}" \ @@ -105,9 +114,20 @@ jobs: --json number \ --jq 'length') if [ "$existing" -eq 0 ]; then + report=$(jq -r '.report' <<< "$AUDIT_RESULT") + body_file=$(mktemp) + { + echo "The weekly compliance audit found violations in this repo." + echo + echo "## Audit report" + echo + printf '%s\n' "$report" + echo + echo "Check the [latest audit run](https://github.com/Sea-Haven-Industries/.github/actions/workflows/compliance-audit.yaml) for details." + } > "$body_file" gh issue create \ --repo "Sea-Haven-Industries/${{ matrix.repo }}" \ --title "Compliance audit: violations found" \ - --body "The weekly compliance audit found violations in this repo. Check the [latest audit run](https://github.com/Sea-Haven-Industries/.github/actions/workflows/compliance-audit.yaml) for details." \ + --body-file "$body_file" \ --label "compliance" fi