Compliance audit: violations found #31

Closed
opened 2026-05-11 21:00:09 +00:00 by ghost · 1 comment
ghost commented 2026-05-11 21:00:09 +00:00 (Migrated from github.com)

The weekly compliance audit found violations in this repo.

Audit report

Sea Haven Industries Compliance Audit

Repo: Sea-Haven-Industries/.github (per remote.origin.url). Stack: seahaven-slack-bot (CDK, TypeScript). SAM rules N/A.

Naming — FAIL

  • ❌ Stack name does not match repo name. Repo is .github, stack is seahaven-slack-bot (bin/seahaven-slack-bot.ts:12). Handbook (naming-conventions.md): CFN stack name "must match repo name". Either the CDK project is in the wrong repo (the .github repo is for org-shared workflows/community-health files), or the stack must be renamed.
  • ❌ Lambda / DynamoDB / S3 / ECS / EventBridge / SG names use org prefix seahaven- instead of stack-name prefix seahaven-slack-bot-. Handbook example: expense-approval-bot-process-receipt. Affects: seahaven-slack-processor, seahaven-app-home, seahaven-qbo-oauth, seahaven-qbo-lookup, seahaven-maps-lookup, seahaven-wo-po-lookup, seahaven-notion-sync, seahaven-po-sync, seahaven-workorder-sync, seahaven-conversations, seahaven-unanswered-questions, seahaven-kb-docs-…, seahaven-socket-mode, seahaven-qbo-lambda, and the three seahaven-…-daily-sync rules.
  • ❌ IAM role AmazonBedrockExecutionRoleForAgents_seahaven (lib/constructs/bedrock-agent.ts:128) uses PascalCase + snake_case. Handbook: "kebab-case for everything. No exceptions."
  • ❌ Bedrock action group names QBO_Lookup, Google_Maps_Lookup, WO_PO_Lookup (bedrock-agent.ts:225,251,277) use snake_case/SCREAMING. Same rule.
  • ✅ Stack name itself is kebab-case (seahaven-slack-bot).
  • ✅ Lambda / DynamoDB / S3 / cluster / SG / agent (seahaven-alex) names are all kebab-case (just wrong prefix per the bullet above).

Secrets — FAIL

  • ❌ Secret names use seahaven/… instead of seahaven-slack-bot/…. Handbook (secrets-and-config.md): format is stack-name/value-name. Affected: seahaven/slack/credentials, seahaven/slack/app-level-token, seahaven/qbo/oauth, seahaven/google/maps-api-key, seahaven/notion/api-key (refs in slack-handler.ts, bedrock-agent.ts, notion-sync.ts, socket-mode.ts).
  • ✅ All sensitive values are in Secrets Manager, not Lambda env vars or SSM.
  • ✅ Lambda env vars carry only ARNs/IDs (e.g. SLACK_SECRET_ARN, QBO_SECRET_ARN), not raw secret material — secrets are fetched at runtime via the SDK with grantRead.

Lambda Defaults — PASS

All nine NodejsFunction definitions across lib/constructs/*.ts use:

  • ✅ Runtime: NODEJS_22_X
  • ✅ Architecture: ARM_64
  • ✅ logRetention: logs.RetentionDays.TWO_MONTHS (60 days), explicit in IaC

CI/CD — PASS

  • ✅ .github/workflows/ci.yaml triggers on PR to main, calls reusable Sea-Haven-Industries/.github/.github/workflows/ci-typescript-cdk.yaml@main.
  • ✅ .github/workflows/deploy.yaml triggers on push to main, calls reusable cd-cdk.yaml@main with OIDC role.

Git/GitHub — Not fully verifiable (API access declined)

  • ⚠️ Branch protection on main, repo description, and "Sea-Haven-Industries" org default-branch settings could not be confirmed without gh access. No local-file evidence available.
  • ✅ CI gate on PR plus reusable CD workflow on push-to-main is consistent with a PR-based workflow.

SAM Layout — N/A

Not a SAM project (CDK/TypeScript). template.yaml / samconfig.toml(.example) correctly absent.

Project Hygiene — FAIL

  • ❌ CloudFormation outputs missing required items. Only KBDocsBucketName, AgentId, and NotionSecretName are exported (lib/seahaven-slack-bot-stack.ts:99-107, notion-sync.ts:81). Handbook (aws-infrastructure.md): "Every stack should export Function ARNs" and "Any externally-consumable URLs (API Gateway endpoints, etc.)". No Lambda ARNs are output, and the public API URL (bot.seahaven.com via slack-handler.ts API Gateway + Route53) is not output.
  • ✅ README describes architecture, data flow, stack, prerequisites, and project structure.
  • ✅ .gitignore covers .env / .env.*, node_modules, cdk.out, .cdk.staging, lambda build outputs. .aws-sam / __pycache__ items are N/A here.

Check the latest audit run for details.

The weekly compliance audit found violations in this repo. ## Audit report # Sea Haven Industries Compliance Audit Repo: `Sea-Haven-Industries/.github` (per `remote.origin.url`). Stack: `seahaven-slack-bot` (CDK, TypeScript). SAM rules N/A. ## Naming — FAIL - ❌ **Stack name does not match repo name.** Repo is `.github`, stack is `seahaven-slack-bot` (`bin/seahaven-slack-bot.ts:12`). Handbook (`naming-conventions.md`): CFN stack name "must match repo name". Either the CDK project is in the wrong repo (the `.github` repo is for org-shared workflows/community-health files), or the stack must be renamed. - ❌ **Lambda / DynamoDB / S3 / ECS / EventBridge / SG names use org prefix `seahaven-` instead of stack-name prefix `seahaven-slack-bot-`.** Handbook example: `expense-approval-bot-process-receipt`. Affects: `seahaven-slack-processor`, `seahaven-app-home`, `seahaven-qbo-oauth`, `seahaven-qbo-lookup`, `seahaven-maps-lookup`, `seahaven-wo-po-lookup`, `seahaven-notion-sync`, `seahaven-po-sync`, `seahaven-workorder-sync`, `seahaven-conversations`, `seahaven-unanswered-questions`, `seahaven-kb-docs-…`, `seahaven-socket-mode`, `seahaven-qbo-lambda`, and the three `seahaven-…-daily-sync` rules. - ❌ **IAM role `AmazonBedrockExecutionRoleForAgents_seahaven`** (`lib/constructs/bedrock-agent.ts:128`) uses PascalCase + snake_case. Handbook: "kebab-case for everything. No exceptions." - ❌ **Bedrock action group names `QBO_Lookup`, `Google_Maps_Lookup`, `WO_PO_Lookup`** (`bedrock-agent.ts:225,251,277`) use snake_case/SCREAMING. Same rule. - ✅ Stack name itself is kebab-case (`seahaven-slack-bot`). - ✅ Lambda / DynamoDB / S3 / cluster / SG / agent (`seahaven-alex`) names are all kebab-case (just wrong prefix per the bullet above). ## Secrets — FAIL - ❌ **Secret names use `seahaven/…` instead of `seahaven-slack-bot/…`.** Handbook (`secrets-and-config.md`): format is `stack-name/value-name`. Affected: `seahaven/slack/credentials`, `seahaven/slack/app-level-token`, `seahaven/qbo/oauth`, `seahaven/google/maps-api-key`, `seahaven/notion/api-key` (refs in `slack-handler.ts`, `bedrock-agent.ts`, `notion-sync.ts`, `socket-mode.ts`). - ✅ All sensitive values are in Secrets Manager, not Lambda env vars or SSM. - ✅ Lambda env vars carry only ARNs/IDs (e.g. `SLACK_SECRET_ARN`, `QBO_SECRET_ARN`), not raw secret material — secrets are fetched at runtime via the SDK with `grantRead`. ## Lambda Defaults — PASS All nine `NodejsFunction` definitions across `lib/constructs/*.ts` use: - ✅ Runtime: `NODEJS_22_X` - ✅ Architecture: `ARM_64` - ✅ `logRetention: logs.RetentionDays.TWO_MONTHS` (60 days), explicit in IaC ## CI/CD — PASS - ✅ `.github/workflows/ci.yaml` triggers on PR to `main`, calls reusable `Sea-Haven-Industries/.github/.github/workflows/ci-typescript-cdk.yaml@main`. - ✅ `.github/workflows/deploy.yaml` triggers on push to `main`, calls reusable `cd-cdk.yaml@main` with OIDC role. ## Git/GitHub — Not fully verifiable (API access declined) - ⚠️ Branch protection on `main`, repo description, and "Sea-Haven-Industries" org default-branch settings could not be confirmed without `gh` access. No local-file evidence available. - ✅ CI gate on PR plus reusable CD workflow on push-to-main is consistent with a PR-based workflow. ## SAM Layout — N/A Not a SAM project (CDK/TypeScript). `template.yaml` / `samconfig.toml(.example)` correctly absent. ## Project Hygiene — FAIL - ❌ **CloudFormation outputs missing required items.** Only `KBDocsBucketName`, `AgentId`, and `NotionSecretName` are exported (`lib/seahaven-slack-bot-stack.ts:99-107`, `notion-sync.ts:81`). Handbook (`aws-infrastructure.md`): "Every stack should export Function ARNs" and "Any externally-consumable URLs (API Gateway endpoints, etc.)". No Lambda ARNs are output, and the public API URL (`bot.seahaven.com` via `slack-handler.ts` API Gateway + Route53) is not output. - ✅ README describes architecture, data flow, stack, prerequisites, and project structure. - ✅ `.gitignore` covers `.env` / `.env.*`, `node_modules`, `cdk.out`, `.cdk.staging`, lambda build outputs. `.aws-sam` / `__pycache__` items are N/A here. Check the [latest audit run](https://github.com/Sea-Haven-Industries/.github/actions/workflows/compliance-audit.yaml) for details.
amoussa1229 commented 2026-06-03 00:10:28 +00:00 (Migrated from github.com)

Closing - false-positives

Closing - false-positives
This repo is archived. You cannot comment on issues.
No description provided.