Compliance audit: violations found #17

Closed
opened 2026-06-08 15:34:07 +00:00 by ghost · 1 comment
ghost commented 2026-06-08 15:34:07 +00:00 (Migrated from github.com)

The weekly compliance audit found violations in this repo.

Audit report

Sea Haven Industries Compliance Audit — Sea-Haven-Industries/.github

Repo character: This repo's working tree is an application (Coupa → Amazon Payee Central PO scraper: scrape.mjs, scrape-payee-chunk.mjs, scrape-fill-chunk.mjs, gen-po-list.mjs, monitor.mjs, parse-mbox.py, output/site-state-extra-mapping.json, prompts/po-email-parser.md). There is no AWS IaC (no template.yaml, CDK app, or CloudFormation). Lambda/SAM/CDK/Secrets-Manager categories are therefore mostly N/A.

Naming — N/A

No IaC templates or CloudFormation/SAM/CDK stacks exist, so "kebab-case resource names" and "stack name matches repo name" do not apply.

  • Aside (not a rule violation): project identity is inconsistent — repo .github, package.json name coupa-po-scraper, README title amazon-po-parser.

Secrets — PASS (applicable parts)

  • No Lambdas/SSM/Secrets Manager exist, so the "no secrets in Lambda env vars/SSM" rules don't apply.
  • Credentials read from env vars (COUPA_EMAIL, COUPA_PASSWORD in scrape.mjs); .env is gitignored; no secret material (keys/tokens/cookies) is committed. cookies.json is gitignored.

Lambda defaults — N/A

No Lambda functions exist.

CI/CD — PASS (with note)

  • CI on PR ✅ — .github/workflows/ci.yaml triggers on pull_request → main and uses an org reusable workflow (Sea-Haven-Industries/.github/.github/workflows/ci-python-sam.yaml@main). dependency-review.yml also calls a reusable workflow. ✅
  • CD on push to main — N/A: this is local tooling, not an AWS-deployable stack, so no deploy.yaml is required.
  • Note: CI invokes the Python-SAM reusable workflow for a repo that is not a SAM project (Node scripts + one Python file); worth aligning to an appropriate reusable workflow.

Git / GitHub — PARTIAL / UNVERIFIED

  • PR-based workflow ✅ — latest commit is a squash/merge of PR #15.
  • Branch protection on main — UNVERIFIED: GitHub API (gh api .../branches/main/protection) was blocked by the permission sandbox this run; could not confirm required-PR / no-force-push / no-deletion.
  • Repo description — UNVERIFIED: gh repo view/gh api blocked; description presence could not be confirmed.

SAM layout — N/A

Not a SAM project (no template.yaml, no samconfig.toml(.example), no src/<function>/ layout). Skipped.

Project hygiene — FAIL (one violation) + concern

  • README architecture ✅ — README.md has a clear Architecture/data-flow/schema section.
  • .gitignore gap — VIOLATION: covers .env and node_modules/ ✅, but omits __pycache__/ and *.pyc despite committed Python code (parse-mbox.py). Handbook standard .gitignore requires these. (.aws-sam/ correctly N/A — no SAM.)
  • CloudFormation outputs (ARNs/URLs) — N/A (no CFN).

Cross-cutting — Company-specific data in a meta-repo (FLAG / VIOLATION if public)

Application code + company-specific data is committed into the org .github repository:

  • parse-mbox.py:236 → mbox path embedding company email info@seahavenind.com
  • scrape.mjs:12-13 → hardcoded internal identifiers SUPPLIER_ID = "895025" and company Coupa instance amazon.coupahost.com
  • output/site-state-extra-mapping.json → curated internal Amazon facility-code → US-state business data (392 codes)
  • Vendor portal flows/URLs (supplier.coupahost.com, payeecentral.amazon.com)

The handbook's Public Repos standard requires scrubbing employee/company identifiers, internal data, and API subdomains before a repo is public. Org .github repos are commonly public. Repo visibility could not be verified (API blocked) — if this repo is public, the above constitutes a clear violation of the public-repo scrubbing standard; if private, it remains a hygiene concern (application + business data does not belong in the org meta-repo).


Action items

  1. Add __pycache__/ and *.pyc to .gitignore.
  2. Verify main branch protection (require PR, block force-push/deletion) and that the repo has a description.
  3. Confirm repo visibility; if public, scrub info@seahavenind.com, SUPPLIER_ID, the Coupa instance, and internal data from the working tree and git history (per handbook, prefer a clean re-init over history rewrite).
  4. Reconsider hosting this scraper in the org .github meta-repo; move it to a dedicated repo and point CI at an appropriate (non-SAM) reusable workflow.

Check the latest audit run for details.

The weekly compliance audit found violations in this repo. ## Audit report ## Sea Haven Industries Compliance Audit — `Sea-Haven-Industries/.github` **Repo character:** This repo's working tree is an application (Coupa → Amazon Payee Central PO scraper: `scrape.mjs`, `scrape-payee-chunk.mjs`, `scrape-fill-chunk.mjs`, `gen-po-list.mjs`, `monitor.mjs`, `parse-mbox.py`, `output/site-state-extra-mapping.json`, `prompts/po-email-parser.md`). There is **no AWS IaC** (no `template.yaml`, CDK app, or CloudFormation). Lambda/SAM/CDK/Secrets-Manager categories are therefore mostly N/A. ### Naming — N/A No IaC templates or CloudFormation/SAM/CDK stacks exist, so "kebab-case resource names" and "stack name matches repo name" do not apply. - *Aside (not a rule violation):* project identity is inconsistent — repo `.github`, `package.json` name `coupa-po-scraper`, README title `amazon-po-parser`. ### Secrets — PASS (applicable parts) - No Lambdas/SSM/Secrets Manager exist, so the "no secrets in Lambda env vars/SSM" rules don't apply. - Credentials read from env vars (`COUPA_EMAIL`, `COUPA_PASSWORD` in `scrape.mjs`); `.env` is gitignored; no secret material (keys/tokens/cookies) is committed. `cookies.json` is gitignored. ### Lambda defaults — N/A No Lambda functions exist. ### CI/CD — PASS (with note) - CI on PR ✅ — `.github/workflows/ci.yaml` triggers on `pull_request` → `main` and uses an org reusable workflow (`Sea-Haven-Industries/.github/.github/workflows/ci-python-sam.yaml@main`). `dependency-review.yml` also calls a reusable workflow. ✅ - CD on push to `main` — **N/A**: this is local tooling, not an AWS-deployable stack, so no `deploy.yaml` is required. - *Note:* CI invokes the **Python-SAM** reusable workflow for a repo that is not a SAM project (Node scripts + one Python file); worth aligning to an appropriate reusable workflow. ### Git / GitHub — PARTIAL / UNVERIFIED - PR-based workflow ✅ — latest commit is a squash/merge of PR #15. - Branch protection on `main` — **UNVERIFIED**: GitHub API (`gh api .../branches/main/protection`) was blocked by the permission sandbox this run; could not confirm required-PR / no-force-push / no-deletion. - Repo description — **UNVERIFIED**: `gh repo view`/`gh api` blocked; description presence could not be confirmed. ### SAM layout — N/A Not a SAM project (no `template.yaml`, no `samconfig.toml(.example)`, no `src/<function>/` layout). Skipped. ### Project hygiene — FAIL (one violation) + concern - README architecture ✅ — `README.md` has a clear Architecture/data-flow/schema section. - **`.gitignore` gap — VIOLATION:** covers `.env` and `node_modules/` ✅, but **omits `__pycache__/` and `*.pyc`** despite committed Python code (`parse-mbox.py`). Handbook standard `.gitignore` requires these. (`.aws-sam/` correctly N/A — no SAM.) - CloudFormation outputs (ARNs/URLs) — N/A (no CFN). ### Cross-cutting — Company-specific data in a meta-repo (FLAG / VIOLATION if public) Application code + company-specific data is committed into the org `.github` repository: - `parse-mbox.py:236` → mbox path embedding company email `info@seahavenind.com` - `scrape.mjs:12-13` → hardcoded internal identifiers `SUPPLIER_ID = "895025"` and company Coupa instance `amazon.coupahost.com` - `output/site-state-extra-mapping.json` → curated internal Amazon facility-code → US-state business data (392 codes) - Vendor portal flows/URLs (`supplier.coupahost.com`, `payeecentral.amazon.com`) The handbook's **Public Repos** standard requires scrubbing employee/company identifiers, internal data, and API subdomains before a repo is public. Org `.github` repos are commonly public. **Repo visibility could not be verified (API blocked)** — if this repo is public, the above constitutes a clear violation of the public-repo scrubbing standard; if private, it remains a hygiene concern (application + business data does not belong in the org meta-repo). --- ### Action items 1. Add `__pycache__/` and `*.pyc` to `.gitignore`. 2. Verify `main` branch protection (require PR, block force-push/deletion) and that the repo has a description. 3. Confirm repo visibility; if public, scrub `info@seahavenind.com`, `SUPPLIER_ID`, the Coupa instance, and internal data from the working tree **and git history** (per handbook, prefer a clean re-init over history rewrite). 4. Reconsider hosting this scraper in the org `.github` meta-repo; move it to a dedicated repo and point CI at an appropriate (non-SAM) reusable workflow. Check the [latest audit run](https://github.com/Sea-Haven-Industries/.github/actions/workflows/compliance-audit.yaml) for details.
amoussa1229 commented 2026-06-10 22:33:28 +00:00 (Migrated from github.com)

Closing — the weekly Compliance Audit workflow has been deprecated (Sea-Haven-Industries/.github#49; workflow disabled and schedule removed). These auto-filed violation issues are no longer maintained. Compliance now runs via the Claude Code App on PRs + the engineering handbook.

Closing — the weekly Compliance Audit workflow has been deprecated (Sea-Haven-Industries/.github#49; workflow disabled and schedule removed). These auto-filed violation issues are no longer maintained. Compliance now runs via the Claude Code App on PRs + the engineering handbook.
This repo is archived. You cannot comment on issues.
No description provided.