Compliance Audit — 2026-04-09
This umbrella issue tracks all findings from the automated compliance audit run on 2026-04-09.
Findings are grouped by remediation category. Address each category together to avoid duplicate agent PRs.
Total findings: 99 across 7 repositories
Remediation Work Breakdown
Repository Settings (21 finding(s))
Remediation: apply-repo-settings.sh
Affected repos: .github, ContentTwin, TalkTerm, bmad-bgreat-suite, broodly, google-app-scripts, markets
| Repo |
Check |
Severity |
.github |
allow_auto_merge |
warning |
.github |
delete_branch_on_merge |
warning |
.github |
has_wiki |
warning |
markets |
allow_auto_merge |
warning |
markets |
delete_branch_on_merge |
warning |
markets |
has_wiki |
warning |
google-app-scripts |
allow_auto_merge |
warning |
google-app-scripts |
delete_branch_on_merge |
warning |
google-app-scripts |
has_wiki |
warning |
ContentTwin |
allow_auto_merge |
warning |
ContentTwin |
delete_branch_on_merge |
warning |
ContentTwin |
has_wiki |
warning |
broodly |
allow_auto_merge |
warning |
broodly |
delete_branch_on_merge |
warning |
broodly |
has_wiki |
warning |
bmad-bgreat-suite |
allow_auto_merge |
warning |
bmad-bgreat-suite |
delete_branch_on_merge |
warning |
bmad-bgreat-suite |
has_wiki |
warning |
TalkTerm |
allow_auto_merge |
warning |
TalkTerm |
delete_branch_on_merge |
warning |
TalkTerm |
has_wiki |
warning |
Repository Rulesets (3 finding(s))
Remediation: apply-rulesets.sh
Affected repos: ContentTwin, TalkTerm, broodly
| Repo |
Check |
Severity |
ContentTwin |
missing-code-quality |
error |
broodly |
missing-code-quality |
error |
TalkTerm |
required-claude-check-broken |
error |
Workflows (18 finding(s))
Remediation: per-repo workflow additions
Affected repos: .github, ContentTwin, TalkTerm, bmad-bgreat-suite, broodly, google-app-scripts, markets
| Repo |
Check |
Severity |
.github |
codeql-default-setup-not-configured |
error |
.github |
missing-permissions-claude-code-reusable.yml |
warning |
.github |
missing-permissions-dependabot-automerge-reusable.yml |
warning |
.github |
missing-permissions-dependabot-rebase-reusable.yml |
warning |
.github |
missing-permissions-feature-ideation-reusable.yml |
warning |
markets |
codeql-default-setup-not-configured |
error |
markets |
stray-codeql-workflow |
error |
google-app-scripts |
codeql-default-setup-not-configured |
error |
google-app-scripts |
stray-codeql-workflow |
error |
ContentTwin |
codeql-default-setup-not-configured |
error |
ContentTwin |
stray-codeql-workflow |
error |
broodly |
codeql-default-setup-not-configured |
error |
broodly |
stray-codeql-workflow |
error |
bmad-bgreat-suite |
codeql-default-setup-not-configured |
error |
bmad-bgreat-suite |
stray-codeql-workflow |
error |
TalkTerm |
missing-ci.yml |
error |
TalkTerm |
codeql-default-setup-not-configured |
error |
TalkTerm |
stray-codeql-workflow |
error |
Action SHA Pinning (36 finding(s))
Remediation: pin actions to SHA in each workflow file
Affected repos: .github, ContentTwin, TalkTerm, bmad-bgreat-suite, broodly, google-app-scripts, markets
| Repo |
Check |
Severity |
.github |
unpinned-actions-agent-shield.yml |
error |
.github |
unpinned-actions-claude.yml |
error |
.github |
unpinned-actions-dependency-audit.yml |
error |
markets |
unpinned-actions-agent-shield.yml |
error |
markets |
unpinned-actions-claude.yml |
error |
markets |
unpinned-actions-dependabot-automerge.yml |
error |
markets |
unpinned-actions-dependabot-rebase.yml |
error |
markets |
unpinned-actions-dependency-audit.yml |
error |
markets |
unpinned-actions-feature-ideation.yml |
error |
google-app-scripts |
unpinned-actions-agent-shield.yml |
error |
google-app-scripts |
unpinned-actions-claude.yml |
error |
google-app-scripts |
unpinned-actions-dependabot-automerge.yml |
error |
google-app-scripts |
unpinned-actions-dependabot-rebase.yml |
error |
google-app-scripts |
unpinned-actions-dependency-audit.yml |
error |
google-app-scripts |
unpinned-actions-feature-ideation.yml |
error |
ContentTwin |
unpinned-actions-agent-shield.yml |
error |
ContentTwin |
unpinned-actions-claude.yml |
error |
ContentTwin |
unpinned-actions-dependabot-automerge.yml |
error |
ContentTwin |
unpinned-actions-dependabot-rebase.yml |
error |
ContentTwin |
unpinned-actions-dependency-audit.yml |
error |
broodly |
unpinned-actions-agent-shield.yml |
error |
broodly |
unpinned-actions-claude.yml |
error |
broodly |
unpinned-actions-dependabot-automerge.yml |
error |
broodly |
unpinned-actions-dependabot-rebase.yml |
error |
broodly |
unpinned-actions-dependency-audit.yml |
error |
broodly |
unpinned-actions-feature-ideation.yml |
error |
bmad-bgreat-suite |
unpinned-actions-agent-shield.yml |
error |
bmad-bgreat-suite |
unpinned-actions-claude.yml |
error |
bmad-bgreat-suite |
unpinned-actions-dependabot-automerge.yml |
error |
bmad-bgreat-suite |
unpinned-actions-dependency-audit.yml |
error |
TalkTerm |
unpinned-actions-agent-shield.yml |
error |
TalkTerm |
unpinned-actions-claude.yml |
error |
TalkTerm |
unpinned-actions-dependabot-automerge.yml |
error |
TalkTerm |
unpinned-actions-dependabot-rebase.yml |
error |
TalkTerm |
unpinned-actions-dependency-audit.yml |
error |
TalkTerm |
unpinned-actions-feature-ideation.yml |
error |
Dependabot Configuration (3 finding(s))
Remediation: per-repo .github/dependabot.yml
Affected repos: google-app-scripts
| Repo |
Check |
Severity |
google-app-scripts |
missing-github-actions-ecosystem |
error |
google-app-scripts |
missing-security-label |
warning |
google-app-scripts |
missing-dependencies-label |
warning |
CLAUDE.md / AGENTS.md References (2 finding(s))
Remediation: per-repo doc updates
Affected repos: ContentTwin, markets
| Repo |
Check |
Severity |
markets |
agents-md-missing-org-ref |
error |
ContentTwin |
agents-md-missing-org-ref |
error |
Generated by the weekly compliance audit on 2026-04-09 17:16 UTC.
Address each remediation category as a single coordinated PR to avoid duplicate agent work.
Compliance Audit — 2026-04-09
This umbrella issue tracks all findings from the automated compliance audit run on 2026-04-09.
Findings are grouped by remediation category. Address each category together to avoid duplicate agent PRs.
Total findings: 99 across 7 repositories
Remediation Work Breakdown
Repository Settings (21 finding(s))
Remediation:
apply-repo-settings.shAffected repos: .github, ContentTwin, TalkTerm, bmad-bgreat-suite, broodly, google-app-scripts, markets
.githuballow_auto_mergewarning.githubdelete_branch_on_mergewarning.githubhas_wikiwarningmarketsallow_auto_mergewarningmarketsdelete_branch_on_mergewarningmarketshas_wikiwarninggoogle-app-scriptsallow_auto_mergewarninggoogle-app-scriptsdelete_branch_on_mergewarninggoogle-app-scriptshas_wikiwarningContentTwinallow_auto_mergewarningContentTwindelete_branch_on_mergewarningContentTwinhas_wikiwarningbroodlyallow_auto_mergewarningbroodlydelete_branch_on_mergewarningbroodlyhas_wikiwarningbmad-bgreat-suiteallow_auto_mergewarningbmad-bgreat-suitedelete_branch_on_mergewarningbmad-bgreat-suitehas_wikiwarningTalkTermallow_auto_mergewarningTalkTermdelete_branch_on_mergewarningTalkTermhas_wikiwarningRepository Rulesets (3 finding(s))
Remediation:
apply-rulesets.shAffected repos: ContentTwin, TalkTerm, broodly
ContentTwinmissing-code-qualityerrorbroodlymissing-code-qualityerrorTalkTermrequired-claude-check-brokenerrorWorkflows (18 finding(s))
Remediation:
per-repo workflow additionsAffected repos: .github, ContentTwin, TalkTerm, bmad-bgreat-suite, broodly, google-app-scripts, markets
.githubcodeql-default-setup-not-configurederror.githubmissing-permissions-claude-code-reusable.ymlwarning.githubmissing-permissions-dependabot-automerge-reusable.ymlwarning.githubmissing-permissions-dependabot-rebase-reusable.ymlwarning.githubmissing-permissions-feature-ideation-reusable.ymlwarningmarketscodeql-default-setup-not-configurederrormarketsstray-codeql-workflowerrorgoogle-app-scriptscodeql-default-setup-not-configurederrorgoogle-app-scriptsstray-codeql-workflowerrorContentTwincodeql-default-setup-not-configurederrorContentTwinstray-codeql-workflowerrorbroodlycodeql-default-setup-not-configurederrorbroodlystray-codeql-workflowerrorbmad-bgreat-suitecodeql-default-setup-not-configurederrorbmad-bgreat-suitestray-codeql-workflowerrorTalkTermmissing-ci.ymlerrorTalkTermcodeql-default-setup-not-configurederrorTalkTermstray-codeql-workflowerrorAction SHA Pinning (36 finding(s))
Remediation:
pin actions to SHA in each workflow fileAffected repos: .github, ContentTwin, TalkTerm, bmad-bgreat-suite, broodly, google-app-scripts, markets
.githubunpinned-actions-agent-shield.ymlerror.githubunpinned-actions-claude.ymlerror.githubunpinned-actions-dependency-audit.ymlerrormarketsunpinned-actions-agent-shield.ymlerrormarketsunpinned-actions-claude.ymlerrormarketsunpinned-actions-dependabot-automerge.ymlerrormarketsunpinned-actions-dependabot-rebase.ymlerrormarketsunpinned-actions-dependency-audit.ymlerrormarketsunpinned-actions-feature-ideation.ymlerrorgoogle-app-scriptsunpinned-actions-agent-shield.ymlerrorgoogle-app-scriptsunpinned-actions-claude.ymlerrorgoogle-app-scriptsunpinned-actions-dependabot-automerge.ymlerrorgoogle-app-scriptsunpinned-actions-dependabot-rebase.ymlerrorgoogle-app-scriptsunpinned-actions-dependency-audit.ymlerrorgoogle-app-scriptsunpinned-actions-feature-ideation.ymlerrorContentTwinunpinned-actions-agent-shield.ymlerrorContentTwinunpinned-actions-claude.ymlerrorContentTwinunpinned-actions-dependabot-automerge.ymlerrorContentTwinunpinned-actions-dependabot-rebase.ymlerrorContentTwinunpinned-actions-dependency-audit.ymlerrorbroodlyunpinned-actions-agent-shield.ymlerrorbroodlyunpinned-actions-claude.ymlerrorbroodlyunpinned-actions-dependabot-automerge.ymlerrorbroodlyunpinned-actions-dependabot-rebase.ymlerrorbroodlyunpinned-actions-dependency-audit.ymlerrorbroodlyunpinned-actions-feature-ideation.ymlerrorbmad-bgreat-suiteunpinned-actions-agent-shield.ymlerrorbmad-bgreat-suiteunpinned-actions-claude.ymlerrorbmad-bgreat-suiteunpinned-actions-dependabot-automerge.ymlerrorbmad-bgreat-suiteunpinned-actions-dependency-audit.ymlerrorTalkTermunpinned-actions-agent-shield.ymlerrorTalkTermunpinned-actions-claude.ymlerrorTalkTermunpinned-actions-dependabot-automerge.ymlerrorTalkTermunpinned-actions-dependabot-rebase.ymlerrorTalkTermunpinned-actions-dependency-audit.ymlerrorTalkTermunpinned-actions-feature-ideation.ymlerrorDependabot Configuration (3 finding(s))
Remediation:
per-repo .github/dependabot.ymlAffected repos: google-app-scripts
google-app-scriptsmissing-github-actions-ecosystemerrorgoogle-app-scriptsmissing-security-labelwarninggoogle-app-scriptsmissing-dependencies-labelwarningCLAUDE.md / AGENTS.md References (2 finding(s))
Remediation:
per-repo doc updatesAffected repos: ContentTwin, markets
marketsagents-md-missing-org-referrorContentTwinagents-md-missing-org-referrorGenerated by the weekly compliance audit on 2026-04-09 17:16 UTC.
Address each remediation category as a single coordinated PR to avoid duplicate agent work.