Compliance audit: violations found #11

Closed
opened 2026-05-11 21:01:33 +00:00 by ghost · 1 comment
ghost commented 2026-05-11 21:01:33 +00:00 (Migrated from github.com)

The weekly compliance audit found violations in this repo.

Audit report

Sea Haven Industries Compliance Audit

Repo: Sea-Haven-Industries/.github (default branch main). The repo hosts both the engineering handbook (.engineering-handbook/) and an Amazon/Coupa PO scraper project (Node + Python scripts, no IaC). Categories tied to SAM/Lambda/CFN/CDK are mostly N/A because there is no template.yaml, cdk.json, Terraform, or Lambda code in the tree.

Violations

❌ Dependabot — missing github-actions ecosystem

.github/dependabot.yml only tracks npm, but .github/workflows/ci.yaml exists. Per github-standards.md, repos with .github/workflows/*.yml must include a github-actions ecosystem entry.

❌ Dependabot — missing assignees: amoussa1229

github-standards.md explicitly requires: "All entries must assign PRs to amoussa1229." The current dependabot.yml has no assignees: field on its npm entry. (It uses groups: minor-and-patch, which is fine, but the assignees block is mandatory and absent.)

❌ CI workflow references a reusable workflow that does not exist here

.github/workflows/ci.yaml calls Sea-Haven-Industries/.github/.github/workflows/ci-python-sam.yaml@main. This is the Sea-Haven-Industries/.github repo, but .github/workflows/ only contains ci.yaml — ci-python-sam.yaml is missing. Per cicd.md, reusable CI workflows should live in this repo; either the reusable workflow is missing from the host repo or the consumer reference is dead. Either way the CI job will fail to resolve.

❌ .gitignore missing __pycache__/ (and *.pyc)

parse-mbox.py is a committed Python script. The handbook's standard .gitignore (sam-project-layout.md) and the audit category both call out __pycache__/. Current .gitignore covers .env, node_modules/, output/*, chrome-profile*/, cookies.json, .DS_Store — but not __pycache__/ or *.pyc.

❌ Project name inconsistency

Three different names for the same project:

  • GitHub repo: .github
  • README.md H1: amazon-po-parser
  • package.json name: coupa-po-scraper

naming-conventions.md requires kebab-case and that stack names match repo names. There is no stack here, but the README/package.json disagreement is a real project-hygiene issue. (The GitHub repo name .github is the org meta-repo convention and isn't itself a violation, but it does mean this repo's dual role — handbook host and application code — is unusual.)

❌ package.json description empty

package.json has "description": "". github-standards.md: "Every repo gets a one-line description." (Could not verify the GitHub repo-level description field — gh api repos/... was denied — so the GitHub-side description may or may not also be empty.)

Passes

  • ✅ Default branch is main (github-standards.md).
  • ✅ Dependabot config file is present at .github/dependabot.yml and is on a weekly schedule.
  • ✅ CI on PR is wired up (pull_request trigger on main).
  • ✅ README.md describes architecture, data flow, scripts, and the DynamoDB schema (aws-infrastructure.md README requirement).
  • ✅ No hardcoded secrets in scripts; credentials are read from env vars (process.env.COUPA_EMAIL / COUPA_PASSWORD).
  • ✅ .gitignore covers .env.

Not applicable (skipped)

  • Lambda defaults / runtime / arm64 / log retention — no Lambdas in repo.
  • SAM layout (template.yaml, samconfig.toml(.example), src/) — not a SAM project.
  • CloudFormation outputs (ARNs/URLs) — no CFN/SAM/CDK templates.
  • .gitignore entries for .aws-sam/ and samconfig.toml — N/A without a SAM project.
  • Secrets Manager stack-name/secret-name naming and Lambda env-var prohibition — no Lambda or IaC env-var surface in this repo.
  • CD on push to main — repo has no deployable artifact (no IaC, no Lambda, no static site). Scripts are run manually; cicd.md scopes the pipeline requirement to deployable repos.
  • Branch protection on main — could not verify (GitHub API call was not permitted in this environment); not flagged as a violation, just unverified.

Check the latest audit run for details.

The weekly compliance audit found violations in this repo. ## Audit report # Sea Haven Industries Compliance Audit Repo: `Sea-Haven-Industries/.github` (default branch `main`). The repo hosts both the engineering handbook (`.engineering-handbook/`) and an Amazon/Coupa PO scraper project (Node + Python scripts, no IaC). Categories tied to SAM/Lambda/CFN/CDK are mostly N/A because there is no `template.yaml`, `cdk.json`, Terraform, or Lambda code in the tree. ## Violations ### ❌ Dependabot — missing `github-actions` ecosystem `.github/dependabot.yml` only tracks `npm`, but `.github/workflows/ci.yaml` exists. Per `github-standards.md`, repos with `.github/workflows/*.yml` must include a `github-actions` ecosystem entry. ### ❌ Dependabot — missing `assignees: amoussa1229` `github-standards.md` explicitly requires: "All entries must assign PRs to `amoussa1229`." The current `dependabot.yml` has no `assignees:` field on its npm entry. (It uses `groups: minor-and-patch`, which is fine, but the assignees block is mandatory and absent.) ### ❌ CI workflow references a reusable workflow that does not exist here `.github/workflows/ci.yaml` calls `Sea-Haven-Industries/.github/.github/workflows/ci-python-sam.yaml@main`. This *is* the `Sea-Haven-Industries/.github` repo, but `.github/workflows/` only contains `ci.yaml` — `ci-python-sam.yaml` is missing. Per `cicd.md`, reusable CI workflows should live in this repo; either the reusable workflow is missing from the host repo or the consumer reference is dead. Either way the CI job will fail to resolve. ### ❌ `.gitignore` missing `__pycache__/` (and `*.pyc`) `parse-mbox.py` is a committed Python script. The handbook's standard `.gitignore` (`sam-project-layout.md`) and the audit category both call out `__pycache__/`. Current `.gitignore` covers `.env`, `node_modules/`, `output/*`, `chrome-profile*/`, `cookies.json`, `.DS_Store` — but not `__pycache__/` or `*.pyc`. ### ❌ Project name inconsistency Three different names for the same project: - GitHub repo: `.github` - `README.md` H1: `amazon-po-parser` - `package.json` `name`: `coupa-po-scraper` `naming-conventions.md` requires kebab-case and that stack names match repo names. There is no stack here, but the README/package.json disagreement is a real project-hygiene issue. (The GitHub repo name `.github` is the org meta-repo convention and isn't itself a violation, but it does mean this repo's dual role — handbook host *and* application code — is unusual.) ### ❌ `package.json` description empty `package.json` has `"description": ""`. `github-standards.md`: "Every repo gets a one-line description." (Could not verify the GitHub repo-level `description` field — `gh api repos/...` was denied — so the GitHub-side description may or may not also be empty.) ## Passes - ✅ Default branch is `main` (`github-standards.md`). - ✅ Dependabot config file is present at `.github/dependabot.yml` and is on a weekly schedule. - ✅ CI on PR is wired up (`pull_request` trigger on `main`). - ✅ `README.md` describes architecture, data flow, scripts, and the DynamoDB schema (`aws-infrastructure.md` README requirement). - ✅ No hardcoded secrets in scripts; credentials are read from env vars (`process.env.COUPA_EMAIL` / `COUPA_PASSWORD`). - ✅ `.gitignore` covers `.env`. ## Not applicable (skipped) - **Lambda defaults / runtime / arm64 / log retention** — no Lambdas in repo. - **SAM layout (`template.yaml`, `samconfig.toml(.example)`, `src/`)** — not a SAM project. - **CloudFormation outputs (ARNs/URLs)** — no CFN/SAM/CDK templates. - **`.gitignore` entries for `.aws-sam/` and `samconfig.toml`** — N/A without a SAM project. - **Secrets Manager `stack-name/secret-name` naming and Lambda env-var prohibition** — no Lambda or IaC env-var surface in this repo. - **CD on push to main** — repo has no deployable artifact (no IaC, no Lambda, no static site). Scripts are run manually; `cicd.md` scopes the pipeline requirement to deployable repos. - **Branch protection on `main`** — could not verify (GitHub API call was not permitted in this environment); not flagged as a violation, just unverified. Check the [latest audit run](https://github.com/Sea-Haven-Industries/.github/actions/workflows/compliance-audit.yaml) for details.
amoussa1229 commented 2026-06-03 00:11:02 +00:00 (Migrated from github.com)

Closing - false-positives

Closing - false-positives
This repo is archived. You cannot comment on issues.
No description provided.