mirror of
https://github.com/Sea-Haven-Industries/.github.git
synced 2026-10-02 03:53:19 +00:00
Fix compliance audit violation detection
Co-authored-by: Adam Moussa <amoussa1229@users.noreply.github.com>
This commit is contained in:
parent
4c8c033174
commit
2dc8a6e0e0
1 changed files with 23 additions and 3 deletions
26
.github/workflows/compliance-audit.yaml
vendored
26
.github/workflows/compliance-audit.yaml
vendored
|
|
@ -70,6 +70,7 @@ jobs:
|
||||||
path: .engineering-handbook
|
path: .engineering-handbook
|
||||||
|
|
||||||
- name: Run compliance audit
|
- name: Run compliance audit
|
||||||
|
id: audit
|
||||||
uses: anthropics/claude-code-action@v1
|
uses: anthropics/claude-code-action@v1
|
||||||
with:
|
with:
|
||||||
anthropic_api_key: ${{ secrets.ANTHROPIC_API_KEY }}
|
anthropic_api_key: ${{ secrets.ANTHROPIC_API_KEY }}
|
||||||
|
|
@ -87,12 +88,20 @@ jobs:
|
||||||
- **SAM layout:** template.yaml at root, samconfig.toml gitignored with .example committed, src/ directory structure
|
- **SAM layout:** template.yaml at root, samconfig.toml gitignored with .example committed, src/ directory structure
|
||||||
- **Project hygiene:** README describes architecture, .gitignore covers .env/.aws-sam/__pycache__, CloudFormation outputs include ARNs and URLs
|
- **Project hygiene:** README describes architecture, .gitignore covers .env/.aws-sam/__pycache__, CloudFormation outputs include ARNs and URLs
|
||||||
|
|
||||||
Output a concise markdown report with pass/fail per item. Only flag actual violations — skip items that don't apply to this repo (e.g., skip Lambda checks if no Lambdas exist).
|
Return structured output with:
|
||||||
|
- `has_violations`: true only when one or more actual compliance violations are found.
|
||||||
|
- `report`: a concise markdown report with pass/fail per applicable item.
|
||||||
|
|
||||||
|
Only flag actual violations — skip items that don't apply to this repo (e.g., skip Lambda checks if no Lambdas exist).
|
||||||
|
Do not create or modify files, issues, pull requests, or comments.
|
||||||
|
claude_args: |
|
||||||
|
--json-schema '{"type":"object","properties":{"has_violations":{"type":"boolean","description":"True when one or more actual compliance violations are found."},"report":{"type":"string","description":"Concise markdown report with pass/fail per applicable compliance item."}},"required":["has_violations","report"],"additionalProperties":false}'
|
||||||
|
|
||||||
- name: Create issue if violations found
|
- name: Create issue if violations found
|
||||||
if: failure()
|
if: ${{ fromJSON(steps.audit.outputs.structured_output).has_violations == true }}
|
||||||
env:
|
env:
|
||||||
GH_TOKEN: ${{ steps.app-token.outputs.token }}
|
GH_TOKEN: ${{ steps.app-token.outputs.token }}
|
||||||
|
AUDIT_RESULT: ${{ steps.audit.outputs.structured_output }}
|
||||||
run: |
|
run: |
|
||||||
gh label create compliance \
|
gh label create compliance \
|
||||||
--repo "Sea-Haven-Industries/${{ matrix.repo }}" \
|
--repo "Sea-Haven-Industries/${{ matrix.repo }}" \
|
||||||
|
|
@ -105,9 +114,20 @@ jobs:
|
||||||
--json number \
|
--json number \
|
||||||
--jq 'length')
|
--jq 'length')
|
||||||
if [ "$existing" -eq 0 ]; then
|
if [ "$existing" -eq 0 ]; then
|
||||||
|
report=$(jq -r '.report' <<< "$AUDIT_RESULT")
|
||||||
|
body_file=$(mktemp)
|
||||||
|
{
|
||||||
|
echo "The weekly compliance audit found violations in this repo."
|
||||||
|
echo
|
||||||
|
echo "## Audit report"
|
||||||
|
echo
|
||||||
|
printf '%s\n' "$report"
|
||||||
|
echo
|
||||||
|
echo "Check the [latest audit run](https://github.com/Sea-Haven-Industries/.github/actions/workflows/compliance-audit.yaml) for details."
|
||||||
|
} > "$body_file"
|
||||||
gh issue create \
|
gh issue create \
|
||||||
--repo "Sea-Haven-Industries/${{ matrix.repo }}" \
|
--repo "Sea-Haven-Industries/${{ matrix.repo }}" \
|
||||||
--title "Compliance audit: violations found" \
|
--title "Compliance audit: violations found" \
|
||||||
--body "The weekly compliance audit found violations in this repo. Check the [latest audit run](https://github.com/Sea-Haven-Industries/.github/actions/workflows/compliance-audit.yaml) for details." \
|
--body-file "$body_file" \
|
||||||
--label "compliance"
|
--label "compliance"
|
||||||
fi
|
fi
|
||||||
|
|
|
||||||
Loading…
Add table
Reference in a new issue