Compliance Audit — 2026-06-05
This umbrella issue tracks all findings from the automated compliance audit run on 2026-06-05.
Findings are grouped by remediation category. Address each category together to avoid duplicate agent PRs.
Total findings: 109 across 8 repositories
Remediation Work Breakdown
Repository Settings (26 finding(s))
Remediation: apply-repo-settings.sh
Affected repos: .github, .github-private, ContentTwin, TalkTerm, bmad-bgreat-suite, broodly, google-app-scripts, markets
| Repo |
Check |
Severity |
.github-private |
codeowners-org-leads-not-first |
error |
.github-private |
codeowners-no-catchall |
warning |
.github-private |
check-suite-auto-trigger-1236702 |
error |
.github-private |
check-suite-auto-trigger-347564 |
error |
broodly |
codeowners-org-leads-not-first |
error |
broodly |
codeowners-no-catchall |
warning |
broodly |
check-suite-auto-trigger-1236702 |
error |
broodly |
check-suite-auto-trigger-347564 |
error |
TalkTerm |
codeowners-org-leads-not-first |
error |
TalkTerm |
codeowners-no-catchall |
warning |
TalkTerm |
check-suite-auto-trigger-1236702 |
error |
TalkTerm |
check-suite-auto-trigger-347564 |
error |
ContentTwin |
codeowners-org-leads-not-first |
error |
ContentTwin |
codeowners-no-catchall |
warning |
ContentTwin |
check-suite-auto-trigger-1236702 |
error |
ContentTwin |
check-suite-auto-trigger-347564 |
error |
markets |
check-suite-auto-trigger-1236702 |
error |
markets |
check-suite-auto-trigger-347564 |
error |
google-app-scripts |
check-suite-auto-trigger-1236702 |
error |
google-app-scripts |
check-suite-auto-trigger-347564 |
error |
bmad-bgreat-suite |
check-suite-auto-trigger-1236702 |
error |
bmad-bgreat-suite |
check-suite-auto-trigger-347564 |
error |
.github |
codeowners-org-leads-not-first |
error |
.github |
codeowners-no-catchall |
warning |
.github |
check-suite-auto-trigger-1236702 |
error |
.github |
check-suite-auto-trigger-347564 |
error |
Push Protection & Secret Scanning (18 finding(s))
Remediation: apply-repo-settings.sh (security_and_analysis) + per-repo ci.yml and .gitignore
Affected repos: .github, .github-private, ContentTwin, TalkTerm, bmad-bgreat-suite, broodly, google-app-scripts, markets
| Repo |
Check |
Severity |
.github-private |
secret_scanning_ai_detection |
warning |
.github-private |
secret_scanning_non_provider_patterns |
warning |
broodly |
secret_scanning_ai_detection |
warning |
broodly |
secret_scanning_non_provider_patterns |
warning |
TalkTerm |
secret_scanning_ai_detection |
warning |
TalkTerm |
secret_scanning_non_provider_patterns |
warning |
ContentTwin |
secret_scanning_ai_detection |
warning |
ContentTwin |
secret_scanning_non_provider_patterns |
warning |
ContentTwin |
gitignore_secrets_block |
warning |
markets |
secret_scanning_ai_detection |
warning |
markets |
secret_scanning_non_provider_patterns |
warning |
markets |
secret_scan_ci_job_present |
error |
google-app-scripts |
secret_scanning_ai_detection |
warning |
google-app-scripts |
secret_scanning_non_provider_patterns |
warning |
bmad-bgreat-suite |
secret_scanning_ai_detection |
warning |
bmad-bgreat-suite |
secret_scanning_non_provider_patterns |
warning |
.github |
secret_scanning_ai_detection |
warning |
.github |
secret_scanning_non_provider_patterns |
warning |
Workflows (45 finding(s))
Remediation: per-repo workflow additions
Affected repos: .github-private, ContentTwin, TalkTerm, bmad-bgreat-suite, broodly, google-app-scripts, markets
| Repo |
Check |
Severity |
.github-private |
missing-permissions-issue-triage-runner.yml |
warning |
.github-private |
ci-concurrency-missing-sha |
warning |
.github-private |
non-stub-dev-lead.yml |
error |
.github-private |
non-stub-auto-rebase.yml |
error |
.github-private |
non-stub-dependency-audit.yml |
error |
.github-private |
non-stub-dependabot-automerge.yml |
error |
.github-private |
non-stub-agent-shield.yml |
error |
broodly |
non-stub-dev-lead.yml |
error |
broodly |
non-stub-auto-rebase.yml |
error |
broodly |
non-stub-dependency-audit.yml |
error |
broodly |
non-stub-dependabot-automerge.yml |
error |
broodly |
non-stub-dependabot-rebase.yml |
error |
broodly |
non-stub-agent-shield.yml |
error |
broodly |
non-stub-feature-ideation.yml |
error |
TalkTerm |
non-stub-dev-lead.yml |
error |
TalkTerm |
non-stub-auto-rebase.yml |
error |
TalkTerm |
non-stub-dependabot-rebase.yml |
error |
TalkTerm |
non-stub-feature-ideation.yml |
error |
ContentTwin |
non-stub-dev-lead.yml |
error |
ContentTwin |
non-stub-auto-rebase.yml |
error |
ContentTwin |
non-stub-dependency-audit.yml |
error |
ContentTwin |
non-stub-dependabot-automerge.yml |
error |
ContentTwin |
non-stub-dependabot-rebase.yml |
error |
ContentTwin |
non-stub-agent-shield.yml |
error |
markets |
non-stub-dev-lead.yml |
error |
markets |
non-stub-auto-rebase.yml |
error |
markets |
non-stub-dependency-audit.yml |
error |
markets |
non-stub-dependabot-automerge.yml |
error |
markets |
non-stub-dependabot-rebase.yml |
error |
markets |
non-stub-agent-shield.yml |
error |
markets |
non-stub-feature-ideation.yml |
error |
markets |
non-stub-pr-review-mention.yml |
error |
google-app-scripts |
non-stub-dev-lead.yml |
error |
google-app-scripts |
non-stub-auto-rebase.yml |
error |
google-app-scripts |
non-stub-dependency-audit.yml |
error |
google-app-scripts |
non-stub-dependabot-automerge.yml |
error |
google-app-scripts |
non-stub-dependabot-rebase.yml |
error |
google-app-scripts |
non-stub-agent-shield.yml |
error |
google-app-scripts |
non-stub-feature-ideation.yml |
error |
google-app-scripts |
non-stub-pr-review-mention.yml |
error |
bmad-bgreat-suite |
non-stub-dev-lead.yml |
error |
bmad-bgreat-suite |
non-stub-dependency-audit.yml |
error |
bmad-bgreat-suite |
non-stub-dependabot-automerge.yml |
error |
bmad-bgreat-suite |
non-stub-dependabot-rebase.yml |
error |
bmad-bgreat-suite |
non-stub-agent-shield.yml |
error |
Action SHA Pinning (2 finding(s))
Remediation: pin actions to SHA in each workflow file
Affected repos: .github-private
| Repo |
Check |
Severity |
.github-private |
unpinned-actions-deploy-pr-review.yml |
error |
.github-private |
unpinned-actions-force-deploy-pr-review.yml |
error |
Dependabot Configuration (3 finding(s))
Remediation: per-repo .github/dependabot.yml
Affected repos: .github-private
| Repo |
Check |
Severity |
.github-private |
missing-github-actions-ecosystem |
error |
.github-private |
missing-security-label |
warning |
.github-private |
missing-dependencies-label |
warning |
Agent Standards (CLAUDE.md / AGENTS.md / copilot-setup-steps.yml) (15 finding(s))
Remediation: per-repo doc and workflow additions
Affected repos: .github, .github-private, ContentTwin, TalkTerm, bmad-bgreat-suite, broodly, google-app-scripts, markets
| Repo |
Check |
Severity |
.github-private |
claude-md-missing-agents-ref |
error |
.github-private |
copilot-setup-steps-invalid-job-name |
error |
broodly |
copilot-setup-steps-invalid-job-name |
error |
broodly |
copilot-instructions-missing-tech-stack |
warning |
broodly |
copilot-instructions-missing-local-dev-commands |
warning |
TalkTerm |
copilot-setup-steps-invalid-job-name |
error |
TalkTerm |
copilot-instructions-missing-tech-stack |
warning |
TalkTerm |
copilot-instructions-missing-local-dev-commands |
warning |
ContentTwin |
copilot-setup-steps-invalid-job-name |
error |
markets |
copilot-setup-steps-invalid-job-name |
error |
google-app-scripts |
copilot-setup-steps-invalid-job-name |
error |
google-app-scripts |
copilot-instructions-missing-tech-stack |
warning |
google-app-scripts |
copilot-instructions-missing-local-dev-commands |
warning |
bmad-bgreat-suite |
copilot-setup-steps-invalid-job-name |
error |
.github |
copilot-setup-steps-invalid-job-name |
error |
Generated by the weekly compliance audit on 2026-06-05 15:13 UTC.
Address each remediation category as a single coordinated PR to avoid duplicate agent work.
Compliance Audit — 2026-06-05
This umbrella issue tracks all findings from the automated compliance audit run on 2026-06-05.
Findings are grouped by remediation category. Address each category together to avoid duplicate agent PRs.
Total findings: 109 across 8 repositories
Remediation Work Breakdown
Repository Settings (26 finding(s))
Remediation:
apply-repo-settings.shAffected repos: .github, .github-private, ContentTwin, TalkTerm, bmad-bgreat-suite, broodly, google-app-scripts, markets
.github-privatecodeowners-org-leads-not-firsterror.github-privatecodeowners-no-catchallwarning.github-privatecheck-suite-auto-trigger-1236702error.github-privatecheck-suite-auto-trigger-347564errorbroodlycodeowners-org-leads-not-firsterrorbroodlycodeowners-no-catchallwarningbroodlycheck-suite-auto-trigger-1236702errorbroodlycheck-suite-auto-trigger-347564errorTalkTermcodeowners-org-leads-not-firsterrorTalkTermcodeowners-no-catchallwarningTalkTermcheck-suite-auto-trigger-1236702errorTalkTermcheck-suite-auto-trigger-347564errorContentTwincodeowners-org-leads-not-firsterrorContentTwincodeowners-no-catchallwarningContentTwincheck-suite-auto-trigger-1236702errorContentTwincheck-suite-auto-trigger-347564errormarketscheck-suite-auto-trigger-1236702errormarketscheck-suite-auto-trigger-347564errorgoogle-app-scriptscheck-suite-auto-trigger-1236702errorgoogle-app-scriptscheck-suite-auto-trigger-347564errorbmad-bgreat-suitecheck-suite-auto-trigger-1236702errorbmad-bgreat-suitecheck-suite-auto-trigger-347564error.githubcodeowners-org-leads-not-firsterror.githubcodeowners-no-catchallwarning.githubcheck-suite-auto-trigger-1236702error.githubcheck-suite-auto-trigger-347564errorPush Protection & Secret Scanning (18 finding(s))
Remediation:
apply-repo-settings.sh (security_and_analysis) + per-repo ci.yml and .gitignoreAffected repos: .github, .github-private, ContentTwin, TalkTerm, bmad-bgreat-suite, broodly, google-app-scripts, markets
.github-privatesecret_scanning_ai_detectionwarning.github-privatesecret_scanning_non_provider_patternswarningbroodlysecret_scanning_ai_detectionwarningbroodlysecret_scanning_non_provider_patternswarningTalkTermsecret_scanning_ai_detectionwarningTalkTermsecret_scanning_non_provider_patternswarningContentTwinsecret_scanning_ai_detectionwarningContentTwinsecret_scanning_non_provider_patternswarningContentTwingitignore_secrets_blockwarningmarketssecret_scanning_ai_detectionwarningmarketssecret_scanning_non_provider_patternswarningmarketssecret_scan_ci_job_presenterrorgoogle-app-scriptssecret_scanning_ai_detectionwarninggoogle-app-scriptssecret_scanning_non_provider_patternswarningbmad-bgreat-suitesecret_scanning_ai_detectionwarningbmad-bgreat-suitesecret_scanning_non_provider_patternswarning.githubsecret_scanning_ai_detectionwarning.githubsecret_scanning_non_provider_patternswarningWorkflows (45 finding(s))
Remediation:
per-repo workflow additionsAffected repos: .github-private, ContentTwin, TalkTerm, bmad-bgreat-suite, broodly, google-app-scripts, markets
.github-privatemissing-permissions-issue-triage-runner.ymlwarning.github-privateci-concurrency-missing-shawarning.github-privatenon-stub-dev-lead.ymlerror.github-privatenon-stub-auto-rebase.ymlerror.github-privatenon-stub-dependency-audit.ymlerror.github-privatenon-stub-dependabot-automerge.ymlerror.github-privatenon-stub-agent-shield.ymlerrorbroodlynon-stub-dev-lead.ymlerrorbroodlynon-stub-auto-rebase.ymlerrorbroodlynon-stub-dependency-audit.ymlerrorbroodlynon-stub-dependabot-automerge.ymlerrorbroodlynon-stub-dependabot-rebase.ymlerrorbroodlynon-stub-agent-shield.ymlerrorbroodlynon-stub-feature-ideation.ymlerrorTalkTermnon-stub-dev-lead.ymlerrorTalkTermnon-stub-auto-rebase.ymlerrorTalkTermnon-stub-dependabot-rebase.ymlerrorTalkTermnon-stub-feature-ideation.ymlerrorContentTwinnon-stub-dev-lead.ymlerrorContentTwinnon-stub-auto-rebase.ymlerrorContentTwinnon-stub-dependency-audit.ymlerrorContentTwinnon-stub-dependabot-automerge.ymlerrorContentTwinnon-stub-dependabot-rebase.ymlerrorContentTwinnon-stub-agent-shield.ymlerrormarketsnon-stub-dev-lead.ymlerrormarketsnon-stub-auto-rebase.ymlerrormarketsnon-stub-dependency-audit.ymlerrormarketsnon-stub-dependabot-automerge.ymlerrormarketsnon-stub-dependabot-rebase.ymlerrormarketsnon-stub-agent-shield.ymlerrormarketsnon-stub-feature-ideation.ymlerrormarketsnon-stub-pr-review-mention.ymlerrorgoogle-app-scriptsnon-stub-dev-lead.ymlerrorgoogle-app-scriptsnon-stub-auto-rebase.ymlerrorgoogle-app-scriptsnon-stub-dependency-audit.ymlerrorgoogle-app-scriptsnon-stub-dependabot-automerge.ymlerrorgoogle-app-scriptsnon-stub-dependabot-rebase.ymlerrorgoogle-app-scriptsnon-stub-agent-shield.ymlerrorgoogle-app-scriptsnon-stub-feature-ideation.ymlerrorgoogle-app-scriptsnon-stub-pr-review-mention.ymlerrorbmad-bgreat-suitenon-stub-dev-lead.ymlerrorbmad-bgreat-suitenon-stub-dependency-audit.ymlerrorbmad-bgreat-suitenon-stub-dependabot-automerge.ymlerrorbmad-bgreat-suitenon-stub-dependabot-rebase.ymlerrorbmad-bgreat-suitenon-stub-agent-shield.ymlerrorAction SHA Pinning (2 finding(s))
Remediation:
pin actions to SHA in each workflow fileAffected repos: .github-private
.github-privateunpinned-actions-deploy-pr-review.ymlerror.github-privateunpinned-actions-force-deploy-pr-review.ymlerrorDependabot Configuration (3 finding(s))
Remediation:
per-repo .github/dependabot.ymlAffected repos: .github-private
.github-privatemissing-github-actions-ecosystemerror.github-privatemissing-security-labelwarning.github-privatemissing-dependencies-labelwarningAgent Standards (CLAUDE.md / AGENTS.md / copilot-setup-steps.yml) (15 finding(s))
Remediation:
per-repo doc and workflow additionsAffected repos: .github, .github-private, ContentTwin, TalkTerm, bmad-bgreat-suite, broodly, google-app-scripts, markets
.github-privateclaude-md-missing-agents-referror.github-privatecopilot-setup-steps-invalid-job-nameerrorbroodlycopilot-setup-steps-invalid-job-nameerrorbroodlycopilot-instructions-missing-tech-stackwarningbroodlycopilot-instructions-missing-local-dev-commandswarningTalkTermcopilot-setup-steps-invalid-job-nameerrorTalkTermcopilot-instructions-missing-tech-stackwarningTalkTermcopilot-instructions-missing-local-dev-commandswarningContentTwincopilot-setup-steps-invalid-job-nameerrormarketscopilot-setup-steps-invalid-job-nameerrorgoogle-app-scriptscopilot-setup-steps-invalid-job-nameerrorgoogle-app-scriptscopilot-instructions-missing-tech-stackwarninggoogle-app-scriptscopilot-instructions-missing-local-dev-commandswarningbmad-bgreat-suitecopilot-setup-steps-invalid-job-nameerror.githubcopilot-setup-steps-invalid-job-nameerrorGenerated by the weekly compliance audit on 2026-06-05 15:13 UTC.
Address each remediation category as a single coordinated PR to avoid duplicate agent work.