Compliance audit: violations found #17
Labels
No labels
bug
compliance
dependencies
documentation
duplicate
enhancement
good first issue
help wanted
invalid
javascript
question
wontfix
No milestone
No project
No assignees
1 participant
Due date
No due date set.
Dependencies
No dependencies set.
Reference: adam/amazon-po-parser#17
Loading…
Add table
Reference in a new issue
No description provided.
Delete branch "%!s()"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
The weekly compliance audit found violations in this repo.
Audit report
Sea Haven Industries Compliance Audit —
Sea-Haven-Industries/.githubRepo character: This repo's working tree is an application (Coupa → Amazon Payee Central PO scraper:
scrape.mjs,scrape-payee-chunk.mjs,scrape-fill-chunk.mjs,gen-po-list.mjs,monitor.mjs,parse-mbox.py,output/site-state-extra-mapping.json,prompts/po-email-parser.md). There is no AWS IaC (notemplate.yaml, CDK app, or CloudFormation). Lambda/SAM/CDK/Secrets-Manager categories are therefore mostly N/A.Naming — N/A
No IaC templates or CloudFormation/SAM/CDK stacks exist, so "kebab-case resource names" and "stack name matches repo name" do not apply.
.github,package.jsonnamecoupa-po-scraper, README titleamazon-po-parser.Secrets — PASS (applicable parts)
COUPA_EMAIL,COUPA_PASSWORDinscrape.mjs);.envis gitignored; no secret material (keys/tokens/cookies) is committed.cookies.jsonis gitignored.Lambda defaults — N/A
No Lambda functions exist.
CI/CD — PASS (with note)
.github/workflows/ci.yamltriggers onpull_request→mainand uses an org reusable workflow (Sea-Haven-Industries/.github/.github/workflows/ci-python-sam.yaml@main).dependency-review.ymlalso calls a reusable workflow. ✅main— N/A: this is local tooling, not an AWS-deployable stack, so nodeploy.yamlis required.Git / GitHub — PARTIAL / UNVERIFIED
main— UNVERIFIED: GitHub API (gh api .../branches/main/protection) was blocked by the permission sandbox this run; could not confirm required-PR / no-force-push / no-deletion.gh repo view/gh apiblocked; description presence could not be confirmed.SAM layout — N/A
Not a SAM project (no
template.yaml, nosamconfig.toml(.example), nosrc/<function>/layout). Skipped.Project hygiene — FAIL (one violation) + concern
README.mdhas a clear Architecture/data-flow/schema section..gitignoregap — VIOLATION: covers.envandnode_modules/✅, but omits__pycache__/and*.pycdespite committed Python code (parse-mbox.py). Handbook standard.gitignorerequires these. (.aws-sam/correctly N/A — no SAM.)Cross-cutting — Company-specific data in a meta-repo (FLAG / VIOLATION if public)
Application code + company-specific data is committed into the org
.githubrepository:parse-mbox.py:236→ mbox path embedding company emailinfo@seahavenind.comscrape.mjs:12-13→ hardcoded internal identifiersSUPPLIER_ID = "895025"and company Coupa instanceamazon.coupahost.comoutput/site-state-extra-mapping.json→ curated internal Amazon facility-code → US-state business data (392 codes)supplier.coupahost.com,payeecentral.amazon.com)The handbook's Public Repos standard requires scrubbing employee/company identifiers, internal data, and API subdomains before a repo is public. Org
.githubrepos are commonly public. Repo visibility could not be verified (API blocked) — if this repo is public, the above constitutes a clear violation of the public-repo scrubbing standard; if private, it remains a hygiene concern (application + business data does not belong in the org meta-repo).Action items
__pycache__/and*.pycto.gitignore.mainbranch protection (require PR, block force-push/deletion) and that the repo has a description.info@seahavenind.com,SUPPLIER_ID, the Coupa instance, and internal data from the working tree and git history (per handbook, prefer a clean re-init over history rewrite)..githubmeta-repo; move it to a dedicated repo and point CI at an appropriate (non-SAM) reusable workflow.Check the latest audit run for details.
Closing — the weekly Compliance Audit workflow has been deprecated (Sea-Haven-Industries/.github#49; workflow disabled and schedule removed). These auto-filed violation issues are no longer maintained. Compliance now runs via the Claude Code App on PRs + the engineering handbook.