Compliance audit: violations found #47

Closed
opened 2026-06-08 15:12:58 +00:00 by ghost · 1 comment
ghost commented 2026-06-08 15:12:58 +00:00 (Migrated from github.com)

The weekly compliance audit found violations in this repo.

Audit report

Sea Haven Industries Compliance Audit — Sea-Haven-Industries/.github

Project type: TypeScript AWS CDK app (seahaven-slack-bot stack). SAM-specific checks are Not Applicable — the project correctly uses CDK for its multi-service infra (ECS Fargate + VPC + Bedrock + DynamoDB), per cdk-project-layout.md.

Authority note: Where the task's focus summary conflicts with the handbook, I audited against the handbook (as instructed). The summary says "Node 22.x"; the handbook says Node 24.x (aws-infrastructure.md, cdk-project-layout.md, cicd.md). Findings below follow the handbook.


❌ Violations

1. Lambda runtime — Node 22.x, handbook requires Node 24.x
All 9 Lambdas use lambda.Runtime.NODEJS_22_X (slack-handler, bedrock-agent, notion/po/workorder-sync). Handbook Lambda defaults mandate Python 3.12 or Node 24.x. README.md and CI workflows also reflect 22. → Bump to NODEJS_24_X.

2. CloudFormation outputs missing ARNs and URLs
aws-infrastructure.md: "Every stack should export Function ARNs and any externally-consumable URLs." Stack outputs only KBDocsBucketName, AgentId, NotionSecretName. No Lambda ARNs and no URL for the API Gateway / bot.seahaven.com custom domain are exported.

3. Secrets Manager naming does not follow stack-name/secret-name
Stack is seahaven-slack-bot, but secrets use a seahaven/... prefix with extra nesting: seahaven/slack/credentials, seahaven/qbo/oauth, seahaven/google/maps-api-key, seahaven/slack/app-level-token, seahaven/notion/api-key. Convention requires seahaven-slack-bot/<value-name> (single-segment).

4. Resource names not prefixed with the full stack name
naming-conventions.md / lambda-template.md require resource names to start with the stack name. Resources are prefixed seahaven- instead of seahaven-slack-bot-: e.g. seahaven-slack-processor, seahaven-notion-sync, seahaven-conversations, seahaven-socket-mode, seahaven-slack-webhook. (kebab-case itself is correct; the prefix is wrong.)

5. CI/CD workflows omit explicit node-version: "24"
cicd.md and cdk-project-layout.md: "Always pass node-version: "24" explicitly." ci.yaml passes no with: block; deploy.yaml passes only enable-qemu: true. Both omit the required node-version.

6. Dependabot config incomplete
github-standards.md requires one entry per ecosystem/directory. .github/dependabot.yml covers only root npm. Missing: github-actions ecosystem (workflows present) and an npm entry for /services/socket-mode (separate package.json + lockfile).

7. Stack name vs. repo name mismatch (contextual)
Rule: stack name must match repo name. Stack/package.json name is seahaven-slack-bot, but the repo is .github — the org-level special repo (conventionally org defaults + reusable workflows, not a deployable app). Either this app belongs in a seahaven-slack-bot repo, or the naming rule is violated.


✅ Passing

  • Architecture (arm64): Every Lambda + Fargate task is ARM_64. ✓
  • Log retention: Every Lambda sets explicit 60-day retention (RetentionDays.TWO_MONTHS); Fargate logs and API access logs likewise explicit. ✓
  • Secrets — not in env vars / SSM: Lambda env vars carry only secret ARNs and non-sensitive config; no SSM used; all sensitive values live in Secrets Manager and are read at runtime. ✓
  • No hardcoded secrets in handler/service code (verified by scan). ✓
  • CI/CD structure: ci.yaml (PR→main) and deploy.yaml (push→main) both consume reusable workflows from Sea-Haven-Industries/.github via @main, plus dependency-review.yml. ✓ (see violation #5 for the node-version gap)
  • README: Accurately describes architecture, Lambdas/services, data flow, and config/secret requirements. ✓
  • .gitignore: Covers .env/.env.* and build output (cdk.out, node_modules, lambda dist/node_modules). .aws-sam/__pycache__ are N/A (CDK/TypeScript). ✓

⚠️ Could not verify (GitHub API access blocked in this environment)

  • Branch protection on main (require PR, no force-push, no deletion)
  • Repo has a one-line description
  • Repo visibility (private default)

Run when API access is available:
gh api repos/Sea-Haven-Industries/.github/branches/main/protection
gh api repos/Sea-Haven-Industries/.github --jq '{description,visibility}'


ℹ️ Not applicable / minor

  • SAM layout (template.yaml, samconfig.toml + .example): N/A — CDK project.
  • CDK dir nit: handler dir is lambda/ vs. handbook's lambdas/ (singular vs. plural) — cosmetic, not flagged as a hard violation.

Check the latest audit run for details.

The weekly compliance audit found violations in this repo. ## Audit report ## Sea Haven Industries Compliance Audit — `Sea-Haven-Industries/.github` **Project type:** TypeScript AWS CDK app (`seahaven-slack-bot` stack). SAM-specific checks are **Not Applicable** — the project correctly uses CDK for its multi-service infra (ECS Fargate + VPC + Bedrock + DynamoDB), per `cdk-project-layout.md`. > **Authority note:** Where the task's focus summary conflicts with the handbook, I audited against the **handbook** (as instructed). The summary says "Node 22.x"; the handbook says **Node 24.x** (`aws-infrastructure.md`, `cdk-project-layout.md`, `cicd.md`). Findings below follow the handbook. --- ### ❌ Violations **1. Lambda runtime — Node 22.x, handbook requires Node 24.x** All 9 Lambdas use `lambda.Runtime.NODEJS_22_X` (slack-handler, bedrock-agent, notion/po/workorder-sync). Handbook Lambda defaults mandate **Python 3.12 or Node 24.x**. `README.md` and CI workflows also reflect 22. → Bump to `NODEJS_24_X`. **2. CloudFormation outputs missing ARNs and URLs** `aws-infrastructure.md`: "Every stack should export Function ARNs and any externally-consumable URLs." Stack outputs only `KBDocsBucketName`, `AgentId`, `NotionSecretName`. **No Lambda ARNs** and **no URL** for the API Gateway / `bot.seahaven.com` custom domain are exported. **3. Secrets Manager naming does not follow `stack-name/secret-name`** Stack is `seahaven-slack-bot`, but secrets use a `seahaven/...` prefix with extra nesting: `seahaven/slack/credentials`, `seahaven/qbo/oauth`, `seahaven/google/maps-api-key`, `seahaven/slack/app-level-token`, `seahaven/notion/api-key`. Convention requires `seahaven-slack-bot/<value-name>` (single-segment). **4. Resource names not prefixed with the full stack name** `naming-conventions.md` / `lambda-template.md` require resource names to **start with the stack name**. Resources are prefixed `seahaven-` instead of `seahaven-slack-bot-`: e.g. `seahaven-slack-processor`, `seahaven-notion-sync`, `seahaven-conversations`, `seahaven-socket-mode`, `seahaven-slack-webhook`. (kebab-case itself is correct; the prefix is wrong.) **5. CI/CD workflows omit explicit `node-version: "24"`** `cicd.md` and `cdk-project-layout.md`: "Always pass `node-version: "24"` explicitly." `ci.yaml` passes no `with:` block; `deploy.yaml` passes only `enable-qemu: true`. Both omit the required `node-version`. **6. Dependabot config incomplete** `github-standards.md` requires one entry per ecosystem/directory. `.github/dependabot.yml` covers only root `npm`. Missing: **`github-actions`** ecosystem (workflows present) and an **npm entry for `/services/socket-mode`** (separate `package.json` + lockfile). **7. Stack name vs. repo name mismatch (contextual)** Rule: stack name must match repo name. Stack/`package.json` name is `seahaven-slack-bot`, but the repo is `.github` — the org-level special repo (conventionally org defaults + reusable workflows, not a deployable app). Either this app belongs in a `seahaven-slack-bot` repo, or the naming rule is violated. --- ### ✅ Passing - **Architecture (arm64):** Every Lambda + Fargate task is `ARM_64`. ✓ - **Log retention:** Every Lambda sets explicit 60-day retention (`RetentionDays.TWO_MONTHS`); Fargate logs and API access logs likewise explicit. ✓ - **Secrets — not in env vars / SSM:** Lambda env vars carry only secret **ARNs** and non-sensitive config; no SSM used; all sensitive values live in Secrets Manager and are read at runtime. ✓ - **No hardcoded secrets** in handler/service code (verified by scan). ✓ - **CI/CD structure:** `ci.yaml` (PR→main) and `deploy.yaml` (push→main) both consume reusable workflows from `Sea-Haven-Industries/.github` via `@main`, plus `dependency-review.yml`. ✓ (see violation #5 for the node-version gap) - **README:** Accurately describes architecture, Lambdas/services, data flow, and config/secret requirements. ✓ - **.gitignore:** Covers `.env`/`.env.*` and build output (`cdk.out`, `node_modules`, lambda `dist`/`node_modules`). `.aws-sam`/`__pycache__` are N/A (CDK/TypeScript). ✓ --- ### ⚠️ Could not verify (GitHub API access blocked in this environment) - **Branch protection on `main`** (require PR, no force-push, no deletion) - **Repo has a one-line description** - **Repo visibility** (`private` default) Run when API access is available: `gh api repos/Sea-Haven-Industries/.github/branches/main/protection` `gh api repos/Sea-Haven-Industries/.github --jq '{description,visibility}'` --- ### ℹ️ Not applicable / minor - **SAM layout** (template.yaml, samconfig.toml + .example): N/A — CDK project. - **CDK dir nit:** handler dir is `lambda/` vs. handbook's `lambdas/` (singular vs. plural) — cosmetic, not flagged as a hard violation. Check the [latest audit run](https://github.com/Sea-Haven-Industries/.github/actions/workflows/compliance-audit.yaml) for details.
amoussa1229 commented 2026-06-10 22:33:04 +00:00 (Migrated from github.com)

Closing — the weekly Compliance Audit workflow has been deprecated (Sea-Haven-Industries/.github#49; workflow disabled and schedule removed). These auto-filed violation issues are no longer maintained. Compliance now runs via the Claude Code App on PRs + the engineering handbook.

Closing — the weekly Compliance Audit workflow has been deprecated (Sea-Haven-Industries/.github#49; workflow disabled and schedule removed). These auto-filed violation issues are no longer maintained. Compliance now runs via the Claude Code App on PRs + the engineering handbook.
This repo is archived. You cannot comment on issues.
No description provided.