Compliance audit: violations found #52

Closed
opened 2026-06-08 15:26:07 +00:00 by ghost · 1 comment
ghost commented 2026-06-08 15:26:07 +00:00 (Migrated from github.com)

The weekly compliance audit found violations in this repo.

Audit report

Sea Haven Industries Compliance Audit — Sea-Haven-Industries/.github

Context: The repository is the org-level .github repo, but its contents are a full CDK (TypeScript) application named exec-aide (Gmail→Bedrock→Slack assistant). SAM-specific checks are N/A (no template.yaml/samconfig.toml; this is a CDK project). The CDK-layout, Lambda, secrets, CI/CD, and hygiene standards apply.

Verification note: Three GitHub platform checks (branch protection on main, repo description, repo visibility) require read-only gh api calls that were not approved, so they are marked UNVERIFIED.


Naming

  • ✅ PASS — kebab-case for IaC resources. All resources are kebab-case: exec-aide, exec-aide-fetch-classify, exec-aide-daily-digest, exec-aide-conversation, exec-aide-reminder, exec-aide-listener, GSI by-date, roles exec-aide-digest-scheduler/exec-aide-reminder-scheduler.
  • ❌ FAIL — stack name must match repo name. bin/exec-aide.ts sets stackName: 'exec-aide', but the repo is .github. The exec-aide application is committed into the org's .github repo. Root cause: the project lives in the wrong repository (and the org-level reusable workflows the handbook references — ci-typescript-cdk.yaml, cd-cdk.yaml, ci-python-sam.yaml, callable-dependency-review.yaml — are not present in this .github repo, even though every repo's CI calls Sea-Haven-Industries/.github/.github/workflows/...@main).

Secrets

  • ✅ PASS — no secrets in Lambda env vars / SSM. Env vars hold only references (SECRET_GMAIL=exec-aide/gmail-oauth, SECRET_SLACK=exec-aide/slack-credentials, SSM_PREFIX, TABLE_NAME). SSM stores only non-sensitive config (emails, VIP lists, thresholds). No real secret values committed.
  • ✅ PASS — Secrets Manager with stack-name/secret-name naming. exec-aide/gmail-oauth, exec-aide/slack-credentials; IAM secretsmanager:GetSecretValue scoped to those ARNs; values read on cold start and module-cached (src/shared/secrets.py).

Lambda defaults

  • ✅ PASS — runtime. All five PythonFunctions use PYTHON_3_12.
  • ✅ PASS — architecture. All ARM_64 (Fargate task also ARM64 with explicit Platform.LINUX_ARM64 + enable-qemu: true).
  • ✅ PASS — explicit 60-day log retention. Every Lambda sets logRetention: TWO_MONTHS; ECS log group TWO_MONTHS.

CI/CD

  • ✅ PASS — pipeline exists with correct triggers + reusable workflows. ci.yaml on pull_request: [main], deploy.yaml on push: [main], both calling reusable workflows from Sea-Haven-Industries/.github; deploy uses OIDC (id-token: write, AWS_DEPLOY_ROLE_ARN).
  • ❌ FAIL — node-version: "24" not passed explicitly. Handbook (cicd.md, cdk-project-layout.md) mandates passing node-version: "24" to the TS/CDK reusable workflows "to avoid drift." Neither the typescript CI job nor deploy.yaml passes it.
  • ⚠️ MINOR — CI gates weakened. ci.yaml sets run-cdk-synth: false and run-sam-validate: false, disabling synth/validate on PR. Per aws-infrastructure.md, cdk synth in CI is the gate that rejects bad aws-cdk-lib releases; disabling it removes that protection.

Git / GitHub

  • ❌ FAIL — Dependabot missing github-actions ecosystem. .github/dependabot.yml covers npm (/), pip (/src, /listener) but omits github-actions, despite .github/workflows/* files (github-standards.md requires it).
  • ✅ PASS — exact aws-cdk-lib pin. aws-cdk-lib: "2.258.0" (exact, no ^/~); no blanket Dependabot ignore entries.
  • ⚠️ UNVERIFIED — branch protection on main. Not approved to query the API. Indirect evidence (org-required ci / ci status context per ci.yaml and commit 08fd211) suggests a ruleset exists, but PR-requirement / no-force-push / no-deletion could not be confirmed.
  • ⚠️ UNVERIFIED — repo description. Could not query repo metadata.

Project hygiene

  • ❌ FAIL — CloudFormation outputs missing ARNs. lib/exec-aide-stack.ts outputs only TableName. Handbook requires every stack export Function ARNs (none are exported). No externally-consumable URL exists (Slack Socket Mode, outbound-only), so the URL output is correctly N/A.
  • ❌ FAIL — README inaccurate. README.md states "CI/CD: CodePipeline + CodeBuild — auto-deploys on push to main. Pipeline stack: exec-aide-pipeline." The repo actually deploys via GitHub Actions reusable workflows; there is no CodePipeline/CodeBuild or exec-aide-pipeline stack. (Architecture/services sections are otherwise accurate.) Minor: prereqs say "Node.js 22+" vs the org standard Node 24.
  • ✅ PASS — .gitignore coverage. Covers .env, __pycache__/, .aws-sam/, plus cdk.out/, node_modules/, *.js/*.d.ts with !cdk.json negation.

Cross-cutting — data exposure (conditional, HIGH if public)

  • ⚠️ CONDITIONAL FAIL — public-repo scrubbing (github-standards.md). Repo contains company-specific data: employee name ("Adam Moussa"), internal email adam@seahavenind.com, internal domains seahavenind.com/seahaven.com, AWS account 328440206208, Google project IDs, and work-orders@ addresses (README, PLAN.md, slack-app-manifest.yaml, scripts/). No real secret values are committed (OAuth client secret is only referenced). If this .github repo is public (org profile repos commonly are), this violates the "scrub all company-specific info before going public" rule. Visibility could not be verified.

Not applicable (skipped)

  • SAM project layout (template.yaml/samconfig.toml/.example) — N/A; this is a CDK project. CDK layout (bin/, lib/, cdk.json, package.json, tsconfig.json) is present and compliant; Lambda source under src/ (vs handbook's lambdas/) is an accepted equivalent per the handbook ("same convention as SAM's src/").

Bottom line: Infrastructure-level conventions (naming, secrets, Lambda defaults, gitignore, CDK pinning, ARM64) are strong. Violations cluster around the repo/stack identity mismatch (app in the wrong repo), missing Function-ARN outputs, an inaccurate README CI/CD section, missing github-actions Dependabot ecosystem, and the omitted explicit node-version: "24". A conditional data-exposure risk exists pending confirmation of repo visibility.

Check the latest audit run for details.

The weekly compliance audit found violations in this repo. ## Audit report ## Sea Haven Industries Compliance Audit — `Sea-Haven-Industries/.github` **Context:** The repository is the org-level `.github` repo, but its contents are a full **CDK (TypeScript) application named `exec-aide`** (Gmail→Bedrock→Slack assistant). SAM-specific checks are **N/A** (no `template.yaml`/`samconfig.toml`; this is a CDK project). The CDK-layout, Lambda, secrets, CI/CD, and hygiene standards apply. > **Verification note:** Three GitHub *platform* checks (branch protection on `main`, repo description, repo visibility) require read-only `gh api` calls that were not approved, so they are marked **UNVERIFIED**. --- ### Naming - ✅ **PASS — kebab-case for IaC resources.** All resources are kebab-case: `exec-aide`, `exec-aide-fetch-classify`, `exec-aide-daily-digest`, `exec-aide-conversation`, `exec-aide-reminder`, `exec-aide-listener`, GSI `by-date`, roles `exec-aide-digest-scheduler`/`exec-aide-reminder-scheduler`. - ❌ **FAIL — stack name must match repo name.** `bin/exec-aide.ts` sets `stackName: 'exec-aide'`, but the repo is `.github`. The `exec-aide` application is committed into the org's `.github` repo. Root cause: the project lives in the wrong repository (and the org-level **reusable workflows** the handbook references — `ci-typescript-cdk.yaml`, `cd-cdk.yaml`, `ci-python-sam.yaml`, `callable-dependency-review.yaml` — are **not present** in this `.github` repo, even though every repo's CI calls `Sea-Haven-Industries/.github/.github/workflows/...@main`). ### Secrets - ✅ **PASS — no secrets in Lambda env vars / SSM.** Env vars hold only references (`SECRET_GMAIL=exec-aide/gmail-oauth`, `SECRET_SLACK=exec-aide/slack-credentials`, `SSM_PREFIX`, `TABLE_NAME`). SSM stores only non-sensitive config (emails, VIP lists, thresholds). No real secret values committed. - ✅ **PASS — Secrets Manager with `stack-name/secret-name` naming.** `exec-aide/gmail-oauth`, `exec-aide/slack-credentials`; IAM `secretsmanager:GetSecretValue` scoped to those ARNs; values read on cold start and module-cached (`src/shared/secrets.py`). ### Lambda defaults - ✅ **PASS — runtime.** All five PythonFunctions use `PYTHON_3_12`. - ✅ **PASS — architecture.** All `ARM_64` (Fargate task also ARM64 with explicit `Platform.LINUX_ARM64` + `enable-qemu: true`). - ✅ **PASS — explicit 60-day log retention.** Every Lambda sets `logRetention: TWO_MONTHS`; ECS log group `TWO_MONTHS`. ### CI/CD - ✅ **PASS — pipeline exists with correct triggers + reusable workflows.** `ci.yaml` on `pull_request: [main]`, `deploy.yaml` on `push: [main]`, both calling reusable workflows from `Sea-Haven-Industries/.github`; deploy uses OIDC (`id-token: write`, `AWS_DEPLOY_ROLE_ARN`). - ❌ **FAIL — `node-version: "24"` not passed explicitly.** Handbook (cicd.md, cdk-project-layout.md) mandates passing `node-version: "24"` to the TS/CDK reusable workflows "to avoid drift." Neither the `typescript` CI job nor `deploy.yaml` passes it. - ⚠️ **MINOR — CI gates weakened.** `ci.yaml` sets `run-cdk-synth: false` and `run-sam-validate: false`, disabling synth/validate on PR. Per aws-infrastructure.md, `cdk synth` in CI is the gate that rejects bad `aws-cdk-lib` releases; disabling it removes that protection. ### Git / GitHub - ❌ **FAIL — Dependabot missing `github-actions` ecosystem.** `.github/dependabot.yml` covers `npm` (`/`), `pip` (`/src`, `/listener`) but omits `github-actions`, despite `.github/workflows/*` files (github-standards.md requires it). - ✅ **PASS — exact `aws-cdk-lib` pin.** `aws-cdk-lib: "2.258.0"` (exact, no `^`/`~`); no blanket Dependabot ignore entries. - ⚠️ **UNVERIFIED — branch protection on `main`.** Not approved to query the API. Indirect evidence (org-required `ci / ci` status context per `ci.yaml` and commit `08fd211`) suggests a ruleset exists, but PR-requirement / no-force-push / no-deletion could not be confirmed. - ⚠️ **UNVERIFIED — repo description.** Could not query repo metadata. ### Project hygiene - ❌ **FAIL — CloudFormation outputs missing ARNs.** `lib/exec-aide-stack.ts` outputs only `TableName`. Handbook requires every stack export **Function ARNs** (none are exported). No externally-consumable URL exists (Slack Socket Mode, outbound-only), so the URL output is correctly N/A. - ❌ **FAIL — README inaccurate.** `README.md` states "**CI/CD:** CodePipeline + CodeBuild — auto-deploys on push to `main`. Pipeline stack: `exec-aide-pipeline`." The repo actually deploys via **GitHub Actions** reusable workflows; there is no CodePipeline/CodeBuild or `exec-aide-pipeline` stack. (Architecture/services sections are otherwise accurate.) Minor: prereqs say "Node.js 22+" vs the org standard Node 24. - ✅ **PASS — `.gitignore` coverage.** Covers `.env`, `__pycache__/`, `.aws-sam/`, plus `cdk.out/`, `node_modules/`, `*.js`/`*.d.ts` with `!cdk.json` negation. ### Cross-cutting — data exposure (conditional, HIGH if public) - ⚠️ **CONDITIONAL FAIL — public-repo scrubbing (github-standards.md).** Repo contains company-specific data: employee name ("Adam Moussa"), internal email `adam@seahavenind.com`, internal domains `seahavenind.com`/`seahaven.com`, AWS account `328440206208`, Google project IDs, and `work-orders@` addresses (README, PLAN.md, slack-app-manifest.yaml, scripts/). **No real secret values are committed** (OAuth client secret is only referenced). If this `.github` repo is **public** (org profile repos commonly are), this violates the "scrub all company-specific info before going public" rule. Visibility could not be verified. ### Not applicable (skipped) - **SAM project layout** (template.yaml/samconfig.toml/.example) — N/A; this is a CDK project. CDK layout (`bin/`, `lib/`, `cdk.json`, `package.json`, `tsconfig.json`) is present and compliant; Lambda source under `src/` (vs handbook's `lambdas/`) is an accepted equivalent per the handbook ("same convention as SAM's `src/`"). --- **Bottom line:** Infrastructure-level conventions (naming, secrets, Lambda defaults, gitignore, CDK pinning, ARM64) are strong. Violations cluster around the repo/stack identity mismatch (app in the wrong repo), missing Function-ARN outputs, an inaccurate README CI/CD section, missing `github-actions` Dependabot ecosystem, and the omitted explicit `node-version: "24"`. A conditional data-exposure risk exists pending confirmation of repo visibility. Check the [latest audit run](https://github.com/Sea-Haven-Industries/.github/actions/workflows/compliance-audit.yaml) for details.
amoussa1229 commented 2026-06-10 22:33:22 +00:00 (Migrated from github.com)

Closing — the weekly Compliance Audit workflow has been deprecated (Sea-Haven-Industries/.github#49; workflow disabled and schedule removed). These auto-filed violation issues are no longer maintained. Compliance now runs via the Claude Code App on PRs + the engineering handbook.

Closing — the weekly Compliance Audit workflow has been deprecated (Sea-Haven-Industries/.github#49; workflow disabled and schedule removed). These auto-filed violation issues are no longer maintained. Compliance now runs via the Claude Code App on PRs + the engineering handbook.
This repo is archived. You cannot comment on issues.
No description provided.