Compliance audit: violations found #11
Labels
No labels
bug
compliance
dependencies
documentation
duplicate
enhancement
good first issue
help wanted
invalid
javascript
question
wontfix
No milestone
No project
No assignees
1 participant
Due date
No due date set.
Dependencies
No dependencies set.
Reference: adam/amazon-po-parser#11
Loading…
Add table
Reference in a new issue
No description provided.
Delete branch "%!s()"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
The weekly compliance audit found violations in this repo.
Audit report
Sea Haven Industries Compliance Audit
Repo:
Sea-Haven-Industries/.github(default branchmain). The repo hosts both the engineering handbook (.engineering-handbook/) and an Amazon/Coupa PO scraper project (Node + Python scripts, no IaC). Categories tied to SAM/Lambda/CFN/CDK are mostly N/A because there is notemplate.yaml,cdk.json, Terraform, or Lambda code in the tree.Violations
❌ Dependabot — missing
github-actionsecosystem.github/dependabot.ymlonly tracksnpm, but.github/workflows/ci.yamlexists. Pergithub-standards.md, repos with.github/workflows/*.ymlmust include agithub-actionsecosystem entry.❌ Dependabot — missing
assignees: amoussa1229github-standards.mdexplicitly requires: "All entries must assign PRs toamoussa1229." The currentdependabot.ymlhas noassignees:field on its npm entry. (It usesgroups: minor-and-patch, which is fine, but the assignees block is mandatory and absent.)❌ CI workflow references a reusable workflow that does not exist here
.github/workflows/ci.yamlcallsSea-Haven-Industries/.github/.github/workflows/ci-python-sam.yaml@main. This is theSea-Haven-Industries/.githubrepo, but.github/workflows/only containsci.yaml—ci-python-sam.yamlis missing. Percicd.md, reusable CI workflows should live in this repo; either the reusable workflow is missing from the host repo or the consumer reference is dead. Either way the CI job will fail to resolve.❌
.gitignoremissing__pycache__/(and*.pyc)parse-mbox.pyis a committed Python script. The handbook's standard.gitignore(sam-project-layout.md) and the audit category both call out__pycache__/. Current.gitignorecovers.env,node_modules/,output/*,chrome-profile*/,cookies.json,.DS_Store— but not__pycache__/or*.pyc.❌ Project name inconsistency
Three different names for the same project:
.githubREADME.mdH1:amazon-po-parserpackage.jsonname:coupa-po-scrapernaming-conventions.mdrequires kebab-case and that stack names match repo names. There is no stack here, but the README/package.json disagreement is a real project-hygiene issue. (The GitHub repo name.githubis the org meta-repo convention and isn't itself a violation, but it does mean this repo's dual role — handbook host and application code — is unusual.)❌
package.jsondescription emptypackage.jsonhas"description": "".github-standards.md: "Every repo gets a one-line description." (Could not verify the GitHub repo-leveldescriptionfield —gh api repos/...was denied — so the GitHub-side description may or may not also be empty.)Passes
main(github-standards.md)..github/dependabot.ymland is on a weekly schedule.pull_requesttrigger onmain).README.mddescribes architecture, data flow, scripts, and the DynamoDB schema (aws-infrastructure.mdREADME requirement).process.env.COUPA_EMAIL/COUPA_PASSWORD)..gitignorecovers.env.Not applicable (skipped)
template.yaml,samconfig.toml(.example),src/) — not a SAM project..gitignoreentries for.aws-sam/andsamconfig.toml— N/A without a SAM project.stack-name/secret-namenaming and Lambda env-var prohibition — no Lambda or IaC env-var surface in this repo.cicd.mdscopes the pipeline requirement to deployable repos.main— could not verify (GitHub API call was not permitted in this environment); not flagged as a violation, just unverified.Check the latest audit run for details.
Closing - false-positives