Compliance audit: violations found #52
Labels
No labels
app
bug
ci
compliance
dependencies
docs
documentation
duplicate
enhancement
good first issue
help wanted
infra
invalid
javascript
python
question
wontfix
No milestone
No project
No assignees
1 participant
Due date
No due date set.
Dependencies
No dependencies set.
Reference: adam/exec-aide#52
Loading…
Add table
Reference in a new issue
No description provided.
Delete branch "%!s()"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
The weekly compliance audit found violations in this repo.
Audit report
Sea Haven Industries Compliance Audit —
Sea-Haven-Industries/.githubContext: The repository is the org-level
.githubrepo, but its contents are a full CDK (TypeScript) application namedexec-aide(Gmail→Bedrock→Slack assistant). SAM-specific checks are N/A (notemplate.yaml/samconfig.toml; this is a CDK project). The CDK-layout, Lambda, secrets, CI/CD, and hygiene standards apply.Naming
exec-aide,exec-aide-fetch-classify,exec-aide-daily-digest,exec-aide-conversation,exec-aide-reminder,exec-aide-listener, GSIby-date, rolesexec-aide-digest-scheduler/exec-aide-reminder-scheduler.bin/exec-aide.tssetsstackName: 'exec-aide', but the repo is.github. Theexec-aideapplication is committed into the org's.githubrepo. Root cause: the project lives in the wrong repository (and the org-level reusable workflows the handbook references —ci-typescript-cdk.yaml,cd-cdk.yaml,ci-python-sam.yaml,callable-dependency-review.yaml— are not present in this.githubrepo, even though every repo's CI callsSea-Haven-Industries/.github/.github/workflows/...@main).Secrets
SECRET_GMAIL=exec-aide/gmail-oauth,SECRET_SLACK=exec-aide/slack-credentials,SSM_PREFIX,TABLE_NAME). SSM stores only non-sensitive config (emails, VIP lists, thresholds). No real secret values committed.stack-name/secret-namenaming.exec-aide/gmail-oauth,exec-aide/slack-credentials; IAMsecretsmanager:GetSecretValuescoped to those ARNs; values read on cold start and module-cached (src/shared/secrets.py).Lambda defaults
PYTHON_3_12.ARM_64(Fargate task also ARM64 with explicitPlatform.LINUX_ARM64+enable-qemu: true).logRetention: TWO_MONTHS; ECS log groupTWO_MONTHS.CI/CD
ci.yamlonpull_request: [main],deploy.yamlonpush: [main], both calling reusable workflows fromSea-Haven-Industries/.github; deploy uses OIDC (id-token: write,AWS_DEPLOY_ROLE_ARN).node-version: "24"not passed explicitly. Handbook (cicd.md, cdk-project-layout.md) mandates passingnode-version: "24"to the TS/CDK reusable workflows "to avoid drift." Neither thetypescriptCI job nordeploy.yamlpasses it.ci.yamlsetsrun-cdk-synth: falseandrun-sam-validate: false, disabling synth/validate on PR. Per aws-infrastructure.md,cdk synthin CI is the gate that rejects badaws-cdk-libreleases; disabling it removes that protection.Git / GitHub
github-actionsecosystem..github/dependabot.ymlcoversnpm(/),pip(/src,/listener) but omitsgithub-actions, despite.github/workflows/*files (github-standards.md requires it).aws-cdk-libpin.aws-cdk-lib: "2.258.0"(exact, no^/~); no blanket Dependabot ignore entries.main. Not approved to query the API. Indirect evidence (org-requiredci / cistatus context perci.yamland commit08fd211) suggests a ruleset exists, but PR-requirement / no-force-push / no-deletion could not be confirmed.Project hygiene
lib/exec-aide-stack.tsoutputs onlyTableName. Handbook requires every stack export Function ARNs (none are exported). No externally-consumable URL exists (Slack Socket Mode, outbound-only), so the URL output is correctly N/A.README.mdstates "CI/CD: CodePipeline + CodeBuild — auto-deploys on push tomain. Pipeline stack:exec-aide-pipeline." The repo actually deploys via GitHub Actions reusable workflows; there is no CodePipeline/CodeBuild orexec-aide-pipelinestack. (Architecture/services sections are otherwise accurate.) Minor: prereqs say "Node.js 22+" vs the org standard Node 24..gitignorecoverage. Covers.env,__pycache__/,.aws-sam/, pluscdk.out/,node_modules/,*.js/*.d.tswith!cdk.jsonnegation.Cross-cutting — data exposure (conditional, HIGH if public)
adam@seahavenind.com, internal domainsseahavenind.com/seahaven.com, AWS account328440206208, Google project IDs, andwork-orders@addresses (README, PLAN.md, slack-app-manifest.yaml, scripts/). No real secret values are committed (OAuth client secret is only referenced). If this.githubrepo is public (org profile repos commonly are), this violates the "scrub all company-specific info before going public" rule. Visibility could not be verified.Not applicable (skipped)
bin/,lib/,cdk.json,package.json,tsconfig.json) is present and compliant; Lambda source undersrc/(vs handbook'slambdas/) is an accepted equivalent per the handbook ("same convention as SAM'ssrc/").Bottom line: Infrastructure-level conventions (naming, secrets, Lambda defaults, gitignore, CDK pinning, ARM64) are strong. Violations cluster around the repo/stack identity mismatch (app in the wrong repo), missing Function-ARN outputs, an inaccurate README CI/CD section, missing
github-actionsDependabot ecosystem, and the omitted explicitnode-version: "24". A conditional data-exposure risk exists pending confirmation of repo visibility.Check the latest audit run for details.
Closing — the weekly Compliance Audit workflow has been deprecated (Sea-Haven-Industries/.github#49; workflow disabled and schedule removed). These auto-filed violation issues are no longer maintained. Compliance now runs via the Claude Code App on PRs + the engineering handbook.