Compliance audit: violations found #47
Labels
No labels
app
bug
ci
compliance
dependencies
docker
docs
documentation
duplicate
enhancement
good first issue
help wanted
infra
invalid
javascript
question
wontfix
No milestone
No project
No assignees
1 participant
Due date
No due date set.
Dependencies
No dependencies set.
Reference: adam/seahaven-slack-bot#47
Loading…
Add table
Reference in a new issue
No description provided.
Delete branch "%!s()"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
The weekly compliance audit found violations in this repo.
Audit report
Sea Haven Industries Compliance Audit —
Sea-Haven-Industries/.githubProject type: TypeScript AWS CDK app (
seahaven-slack-botstack). SAM-specific checks are Not Applicable — the project correctly uses CDK for its multi-service infra (ECS Fargate + VPC + Bedrock + DynamoDB), percdk-project-layout.md.❌ Violations
1. Lambda runtime — Node 22.x, handbook requires Node 24.x
All 9 Lambdas use
lambda.Runtime.NODEJS_22_X(slack-handler, bedrock-agent, notion/po/workorder-sync). Handbook Lambda defaults mandate Python 3.12 or Node 24.x.README.mdand CI workflows also reflect 22. → Bump toNODEJS_24_X.2. CloudFormation outputs missing ARNs and URLs
aws-infrastructure.md: "Every stack should export Function ARNs and any externally-consumable URLs." Stack outputs onlyKBDocsBucketName,AgentId,NotionSecretName. No Lambda ARNs and no URL for the API Gateway /bot.seahaven.comcustom domain are exported.3. Secrets Manager naming does not follow
stack-name/secret-nameStack is
seahaven-slack-bot, but secrets use aseahaven/...prefix with extra nesting:seahaven/slack/credentials,seahaven/qbo/oauth,seahaven/google/maps-api-key,seahaven/slack/app-level-token,seahaven/notion/api-key. Convention requiresseahaven-slack-bot/<value-name>(single-segment).4. Resource names not prefixed with the full stack name
naming-conventions.md/lambda-template.mdrequire resource names to start with the stack name. Resources are prefixedseahaven-instead ofseahaven-slack-bot-: e.g.seahaven-slack-processor,seahaven-notion-sync,seahaven-conversations,seahaven-socket-mode,seahaven-slack-webhook. (kebab-case itself is correct; the prefix is wrong.)5. CI/CD workflows omit explicit
node-version: "24"cicd.mdandcdk-project-layout.md: "Always passnode-version: "24"explicitly."ci.yamlpasses nowith:block;deploy.yamlpasses onlyenable-qemu: true. Both omit the requirednode-version.6. Dependabot config incomplete
github-standards.mdrequires one entry per ecosystem/directory..github/dependabot.ymlcovers only rootnpm. Missing:github-actionsecosystem (workflows present) and an npm entry for/services/socket-mode(separatepackage.json+ lockfile).7. Stack name vs. repo name mismatch (contextual)
Rule: stack name must match repo name. Stack/
package.jsonname isseahaven-slack-bot, but the repo is.github— the org-level special repo (conventionally org defaults + reusable workflows, not a deployable app). Either this app belongs in aseahaven-slack-botrepo, or the naming rule is violated.✅ Passing
ARM_64. ✓RetentionDays.TWO_MONTHS); Fargate logs and API access logs likewise explicit. ✓ci.yaml(PR→main) anddeploy.yaml(push→main) both consume reusable workflows fromSea-Haven-Industries/.githubvia@main, plusdependency-review.yml. ✓ (see violation #5 for the node-version gap).env/.env.*and build output (cdk.out,node_modules, lambdadist/node_modules)..aws-sam/__pycache__are N/A (CDK/TypeScript). ✓⚠️ Could not verify (GitHub API access blocked in this environment)
main(require PR, no force-push, no deletion)privatedefault)Run when API access is available:
gh api repos/Sea-Haven-Industries/.github/branches/main/protectiongh api repos/Sea-Haven-Industries/.github --jq '{description,visibility}'ℹ️ Not applicable / minor
lambda/vs. handbook'slambdas/(singular vs. plural) — cosmetic, not flagged as a hard violation.Check the latest audit run for details.
Closing — the weekly Compliance Audit workflow has been deprecated (Sea-Haven-Industries/.github#49; workflow disabled and schedule removed). These auto-filed violation issues are no longer maintained. Compliance now runs via the Claude Code App on PRs + the engineering handbook.