Compliance audit: violations found #30
Labels
No labels
app
bug
ci
compliance
dependencies
docs
documentation
duplicate
enhancement
good first issue
help wanted
infra
invalid
javascript
python
question
wontfix
No milestone
No project
No assignees
1 participant
Due date
No due date set.
Dependencies
No dependencies set.
Reference: adam/exec-aide#30
Loading…
Add table
Reference in a new issue
No description provided.
Delete branch "%!s()"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
The weekly compliance audit found violations in this repo.
Audit report
Sea Haven Compliance Audit —
Sea-Haven-Industries/.githubThis audit covers the
exec-aideCDK application that lives in theSea-Haven-Industries/.githubrepository.Naming
bin/exec-aide.ts:11setsstackName: 'exec-aide', but the GitHub repo isSea-Haven-Industries/.github(per.git/config). Pernaming-conventions.md, the CloudFormation stack name must match the repo name. More fundamentally, the application code appears to be in the org's special.githubrepo, which is reserved for org-level configuration (reusable workflows, org profile) —exec-aidebelongs in its ownexec-aiderepo.exec-aide-fetch-classify,exec-aide-daily-digest,exec-aide-conversation,exec-aide-reminder; DynamoDBexec-aide; ECS cluster/service/repoexec-aide-listener; schedules, roles, etc.).Secrets
exec-aide/gmail-oauthandexec-aide/slack-credentials(correctstack-name/secret-nameform).TABLE_NAME, secret/parameter names, ARNs). No secret material in env vars or SSM./exec-aide/*.Lambda defaults
PYTHON_3_12on all four Lambdas (lib/constructs/email-pipeline.ts:80,114,160,185).ARM_64on all four Lambdas.logRetention: logs.RetentionDays.TWO_MONTHS(60 days) set explicitly on every function and on the listener ECS log group.CI/CD
.github/workflows/ci.yaml) calls reusableci-python-sam.yamlandci-typescript-cdk.yamlfromSea-Haven-Industries/.github.main(.github/workflows/deploy.yaml) calls reusablecd-cdk.yaml.exec-aide-pipelineCDK stack exists. The README is inaccurate here, but a working pipeline does exist, so I'm not flagging this as a CI/CD violation — just noting the doc/reality mismatch.Git / GitHub
pull_request).mainand the repo's GitHub-side description cannot be verified from the working tree; skipping.Dependabot (
.github/dependabot.yml)assignees: [amoussa1229]on every entry.github-standards.mdrequires all Dependabot entries assign PRs toamoussa1229; none of the three entries do.github-actionsecosystem. The repo has.github/workflows/*.yaml, so apackage-ecosystem: "github-actions"entry is required per the ecosystem table ingithub-standards.md.SAM project layout
.gitignorestill correctly covers.env,.aws-sam/,__pycache__/, andsamconfig.toml.Project hygiene
.gitignorecovers.env,.aws-sam/,__pycache__/,cdk.out/,node_modules/.lib/exec-aide-stack.ts:17exports onlyTableName.aws-infrastructure.mdrequires every stack to export Function ARNs and externally-consumable URLs. None of the four Lambda ARNs (fetch-classify, daily-digest, conversation, reminder) are emitted asCfnOutputs. (The repo's ownPLAN.mdeven called forFetchClassifyFunctionArnandDailyDigestFunctionArnoutputs that never got implemented.)Check the latest audit run for details.
Closing - false-positives