Compliance audit: violations found #31
Labels
No labels
app
bug
ci
compliance
dependencies
docker
docs
documentation
duplicate
enhancement
good first issue
help wanted
infra
invalid
javascript
question
wontfix
No milestone
No project
No assignees
1 participant
Due date
No due date set.
Dependencies
No dependencies set.
Reference: adam/seahaven-slack-bot#31
Loading…
Add table
Reference in a new issue
No description provided.
Delete branch "%!s()"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
The weekly compliance audit found violations in this repo.
Audit report
Sea Haven Industries Compliance Audit
Repo:
Sea-Haven-Industries/.github(perremote.origin.url). Stack:seahaven-slack-bot(CDK, TypeScript). SAM rules N/A.Naming — FAIL
.github, stack isseahaven-slack-bot(bin/seahaven-slack-bot.ts:12). Handbook (naming-conventions.md): CFN stack name "must match repo name". Either the CDK project is in the wrong repo (the.githubrepo is for org-shared workflows/community-health files), or the stack must be renamed.seahaven-instead of stack-name prefixseahaven-slack-bot-. Handbook example:expense-approval-bot-process-receipt. Affects:seahaven-slack-processor,seahaven-app-home,seahaven-qbo-oauth,seahaven-qbo-lookup,seahaven-maps-lookup,seahaven-wo-po-lookup,seahaven-notion-sync,seahaven-po-sync,seahaven-workorder-sync,seahaven-conversations,seahaven-unanswered-questions,seahaven-kb-docs-…,seahaven-socket-mode,seahaven-qbo-lambda, and the threeseahaven-…-daily-syncrules.AmazonBedrockExecutionRoleForAgents_seahaven(lib/constructs/bedrock-agent.ts:128) uses PascalCase + snake_case. Handbook: "kebab-case for everything. No exceptions."QBO_Lookup,Google_Maps_Lookup,WO_PO_Lookup(bedrock-agent.ts:225,251,277) use snake_case/SCREAMING. Same rule.seahaven-slack-bot).seahaven-alex) names are all kebab-case (just wrong prefix per the bullet above).Secrets — FAIL
seahaven/…instead ofseahaven-slack-bot/…. Handbook (secrets-and-config.md): format isstack-name/value-name. Affected:seahaven/slack/credentials,seahaven/slack/app-level-token,seahaven/qbo/oauth,seahaven/google/maps-api-key,seahaven/notion/api-key(refs inslack-handler.ts,bedrock-agent.ts,notion-sync.ts,socket-mode.ts).SLACK_SECRET_ARN,QBO_SECRET_ARN), not raw secret material — secrets are fetched at runtime via the SDK withgrantRead.Lambda Defaults — PASS
All nine
NodejsFunctiondefinitions acrosslib/constructs/*.tsuse:NODEJS_22_XARM_64logRetention: logs.RetentionDays.TWO_MONTHS(60 days), explicit in IaCCI/CD — PASS
.github/workflows/ci.yamltriggers on PR tomain, calls reusableSea-Haven-Industries/.github/.github/workflows/ci-typescript-cdk.yaml@main..github/workflows/deploy.yamltriggers on push tomain, calls reusablecd-cdk.yaml@mainwith OIDC role.Git/GitHub — Not fully verifiable (API access declined)
main, repo description, and "Sea-Haven-Industries" org default-branch settings could not be confirmed withoutghaccess. No local-file evidence available.SAM Layout — N/A
Not a SAM project (CDK/TypeScript).
template.yaml/samconfig.toml(.example)correctly absent.Project Hygiene — FAIL
KBDocsBucketName,AgentId, andNotionSecretNameare exported (lib/seahaven-slack-bot-stack.ts:99-107,notion-sync.ts:81). Handbook (aws-infrastructure.md): "Every stack should export Function ARNs" and "Any externally-consumable URLs (API Gateway endpoints, etc.)". No Lambda ARNs are output, and the public API URL (bot.seahaven.comviaslack-handler.tsAPI Gateway + Route53) is not output..gitignorecovers.env/.env.*,node_modules,cdk.out,.cdk.staging, lambda build outputs..aws-sam/__pycache__items are N/A here.Check the latest audit run for details.
Closing - false-positives