Compliance audit: violations found #30

Closed
opened 2026-05-11 20:57:20 +00:00 by ghost · 1 comment
ghost commented 2026-05-11 20:57:20 +00:00 (Migrated from github.com)

The weekly compliance audit found violations in this repo.

Audit report

Sea Haven Compliance Audit — Sea-Haven-Industries/.github

This audit covers the exec-aide CDK application that lives in the Sea-Haven-Industries/.github repository.

Naming

  • FAIL — Stack name must match repo name. bin/exec-aide.ts:11 sets stackName: 'exec-aide', but the GitHub repo is Sea-Haven-Industries/.github (per .git/config). Per naming-conventions.md, the CloudFormation stack name must match the repo name. More fundamentally, the application code appears to be in the org's special .github repo, which is reserved for org-level configuration (reusable workflows, org profile) — exec-aide belongs in its own exec-aide repo.
  • PASS — All CDK resource names are kebab-case (Lambda functions exec-aide-fetch-classify, exec-aide-daily-digest, exec-aide-conversation, exec-aide-reminder; DynamoDB exec-aide; ECS cluster/service/repo exec-aide-listener; schedules, roles, etc.).

Secrets

  • PASS — Sensitive values stored in Secrets Manager with exec-aide/gmail-oauth and exec-aide/slack-credentials (correct stack-name/secret-name form).
  • PASS — Lambda environment variables hold only non-sensitive identifiers (TABLE_NAME, secret/parameter names, ARNs). No secret material in env vars or SSM.
  • PASS — Non-sensitive config (VIP lists, Slack user ID, thresholds) in SSM under /exec-aide/*.

Lambda defaults

  • PASS — Runtime PYTHON_3_12 on all four Lambdas (lib/constructs/email-pipeline.ts:80,114,160,185).
  • PASS — Architecture ARM_64 on all four Lambdas.
  • PASS — logRetention: logs.RetentionDays.TWO_MONTHS (60 days) set explicitly on every function and on the listener ECS log group.

CI/CD

  • PASS — CI workflow on PRs (.github/workflows/ci.yaml) calls reusable ci-python-sam.yaml and ci-typescript-cdk.yaml from Sea-Haven-Industries/.github.
  • PASS — CD workflow on push to main (.github/workflows/deploy.yaml) calls reusable cd-cdk.yaml.
  • Note: the handbook prefers CodePipeline + CodeBuild for SAM/CDK stacks; the README also claims that pattern ("CodePipeline + CodeBuild — auto-deploys on push to main. Pipeline stack: exec-aide-pipeline"). The actual implementation is GitHub Actions, and no exec-aide-pipeline CDK stack exists. The README is inaccurate here, but a working pipeline does exist, so I'm not flagging this as a CI/CD violation — just noting the doc/reality mismatch.

Git / GitHub

  • PASS — PR-based workflow is in use (CI triggers on pull_request).
  • Branch protection on main and the repo's GitHub-side description cannot be verified from the working tree; skipping.

Dependabot (.github/dependabot.yml)

  • FAIL — Missing assignees: [amoussa1229] on every entry. github-standards.md requires all Dependabot entries assign PRs to amoussa1229; none of the three entries do.
  • FAIL — Missing github-actions ecosystem. The repo has .github/workflows/*.yaml, so a package-ecosystem: "github-actions" entry is required per the ecosystem table in github-standards.md.

SAM project layout

  • N/A — This project uses CDK, not SAM. The .gitignore still correctly covers .env, .aws-sam/, __pycache__/, and samconfig.toml.

Project hygiene

  • PASS — README describes architecture, Lambdas/services, data flow, and configuration requirements.
  • PASS — .gitignore covers .env, .aws-sam/, __pycache__/, cdk.out/, node_modules/.
  • FAIL — CloudFormation outputs incomplete. lib/exec-aide-stack.ts:17 exports only TableName. aws-infrastructure.md requires every stack to export Function ARNs and externally-consumable URLs. None of the four Lambda ARNs (fetch-classify, daily-digest, conversation, reminder) are emitted as CfnOutputs. (The repo's own PLAN.md even called for FetchClassifyFunctionArn and DailyDigestFunctionArn outputs that never got implemented.)

Check the latest audit run for details.

The weekly compliance audit found violations in this repo. ## Audit report ## Sea Haven Compliance Audit — `Sea-Haven-Industries/.github` This audit covers the `exec-aide` CDK application that lives in the `Sea-Haven-Industries/.github` repository. ### Naming - **FAIL — Stack name must match repo name.** `bin/exec-aide.ts:11` sets `stackName: 'exec-aide'`, but the GitHub repo is `Sea-Haven-Industries/.github` (per `.git/config`). Per `naming-conventions.md`, the CloudFormation stack name must match the repo name. More fundamentally, the application code appears to be in the org's special `.github` repo, which is reserved for org-level configuration (reusable workflows, org profile) — `exec-aide` belongs in its own `exec-aide` repo. - PASS — All CDK resource names are kebab-case (Lambda functions `exec-aide-fetch-classify`, `exec-aide-daily-digest`, `exec-aide-conversation`, `exec-aide-reminder`; DynamoDB `exec-aide`; ECS cluster/service/repo `exec-aide-listener`; schedules, roles, etc.). ### Secrets - PASS — Sensitive values stored in Secrets Manager with `exec-aide/gmail-oauth` and `exec-aide/slack-credentials` (correct `stack-name/secret-name` form). - PASS — Lambda environment variables hold only non-sensitive identifiers (`TABLE_NAME`, secret/parameter *names*, ARNs). No secret material in env vars or SSM. - PASS — Non-sensitive config (VIP lists, Slack user ID, thresholds) in SSM under `/exec-aide/*`. ### Lambda defaults - PASS — Runtime `PYTHON_3_12` on all four Lambdas (`lib/constructs/email-pipeline.ts:80,114,160,185`). - PASS — Architecture `ARM_64` on all four Lambdas. - PASS — `logRetention: logs.RetentionDays.TWO_MONTHS` (60 days) set explicitly on every function and on the listener ECS log group. ### CI/CD - PASS — CI workflow on PRs (`.github/workflows/ci.yaml`) calls reusable `ci-python-sam.yaml` and `ci-typescript-cdk.yaml` from `Sea-Haven-Industries/.github`. - PASS — CD workflow on push to `main` (`.github/workflows/deploy.yaml`) calls reusable `cd-cdk.yaml`. - Note: the handbook prefers CodePipeline + CodeBuild for SAM/CDK stacks; the README also claims that pattern ("CodePipeline + CodeBuild — auto-deploys on push to main. Pipeline stack: exec-aide-pipeline"). The actual implementation is GitHub Actions, and no `exec-aide-pipeline` CDK stack exists. The README is inaccurate here, but a working pipeline does exist, so I'm not flagging this as a CI/CD violation — just noting the doc/reality mismatch. ### Git / GitHub - PASS — PR-based workflow is in use (CI triggers on `pull_request`). - Branch protection on `main` and the repo's GitHub-side description cannot be verified from the working tree; skipping. ### Dependabot (`.github/dependabot.yml`) - **FAIL — Missing `assignees: [amoussa1229]` on every entry.** `github-standards.md` requires all Dependabot entries assign PRs to `amoussa1229`; none of the three entries do. - **FAIL — Missing `github-actions` ecosystem.** The repo has `.github/workflows/*.yaml`, so a `package-ecosystem: "github-actions"` entry is required per the ecosystem table in `github-standards.md`. ### SAM project layout - N/A — This project uses CDK, not SAM. The `.gitignore` still correctly covers `.env`, `.aws-sam/`, `__pycache__/`, and `samconfig.toml`. ### Project hygiene - PASS — README describes architecture, Lambdas/services, data flow, and configuration requirements. - PASS — `.gitignore` covers `.env`, `.aws-sam/`, `__pycache__/`, `cdk.out/`, `node_modules/`. - **FAIL — CloudFormation outputs incomplete.** `lib/exec-aide-stack.ts:17` exports only `TableName`. `aws-infrastructure.md` requires every stack to export **Function ARNs** and externally-consumable URLs. None of the four Lambda ARNs (fetch-classify, daily-digest, conversation, reminder) are emitted as `CfnOutput`s. (The repo's own `PLAN.md` even called for `FetchClassifyFunctionArn` and `DailyDigestFunctionArn` outputs that never got implemented.) Check the [latest audit run](https://github.com/Sea-Haven-Industries/.github/actions/workflows/compliance-audit.yaml) for details.
amoussa1229 commented 2026-06-03 00:10:52 +00:00 (Migrated from github.com)

Closing - false-positives

Closing - false-positives
This repo is archived. You cannot comment on issues.
No description provided.