audit-labs/audit-tools

A collection of scripts, queries, and other goodies you can use in an audit. audit automation compliance evidence scripts

Commit 41d4f5879a

41d4f5879a6a4b84011a62c912e20a9009a53a2a

parent: f7f4920e47

Unsigned

cmc <hello@cleberg.net> · 2026-07-29 04:58 UTC

chore: remove ineffective sonar config, add TUI screenshots to docs

- Remove sonar-project.properties. SonarCloud runs in Automatic Analysis
  (Autoscan) mode, which does not honor the issue.ignore rules in that file, so
  it had no effect. Rule suppressions are handled in code where needed.
- Add docs/screenshots/ (platform menu, check selection, live run) and show
  them in the root README and tui/README so the interactive app is visible up
  front.

Layout: unified · split

README.org +11
@@ -7,6 +7,12 @@ automating common audit procedures and analyses.
77This repository includes practical examples that can be used as-is or adapted to
88specific audit environments.
99
10It also ships an interactive terminal UI (=audit_tui.py=) that walks you through
11running an audit against GitHub, GitLab, or AWS — pick a platform, enter
12connection details, choose which checks to run, and watch live progress.
13
14[[./docs/screenshots/menu.png]]
15
1016** Contents
1117
1218| Directory | Description |
@@ -66,6 +72,11 @@ To pick a platform and be walked through an audit interactively:
6672python audit_tui.py
6773#+end_src
6874
75Each run writes the same package the platform's =audit.py= produces — one CSV per
76check plus a summary — with a progress bar and per-check results:
77
78[[./docs/screenshots/run.png]]
79
6980See =tui/README.md= for details. GitHub, GitLab, and AWS are supported.
7081
7182** Contributing
docs/screenshots/checks.png added

Binary file not shown.

docs/screenshots/menu.png added

Binary file not shown.

docs/screenshots/run.png added

Binary file not shown.

sonar-project.properties deleted −15
@@ -1,15 +0,0 @@
1# SonarCloud configuration (Automatic Analysis / Autoscan).
2#
3# projectKey and organization are intentionally omitted — they are bound
4# automatically by the GitHub integration, and setting them here can disable
5# Automatic Analysis.
6
7# Suppress python:S1172 (unused function parameter) on the collector packages.
8# Collectors share a uniform (id, cfg, cache) signature so the audit runner can
9# dispatch every check the same way. Some collectors legitimately use only part
10# of that signature — per-project collectors don't need the org/group, and the
11# pure formatter needs only the cache. This mirrors the existing GitHub
12# collectors (e.g. privileged_access, permission_matrix).
13sonar.issue.ignore.multicriteria=e1
14sonar.issue.ignore.multicriteria.e1.ruleKey=python:S1172
15sonar.issue.ignore.multicriteria.e1.resourcePath=applications/**/collectors/**/*.py
tui/README.md +4
@@ -8,6 +8,10 @@ GitHub, GitLab, and AWS are supported. Adding a platform is a matter of writing
88a runner and a `Platform` descriptor in `tui/platforms.py` — the screens are
99platform-agnostic.
1010
11| Pick a platform | Choose checks | Watch it run |
12|---|---|---|
13| ![Platform menu](../docs/screenshots/menu.png) | ![Check selection](../docs/screenshots/checks.png) | ![Live run](../docs/screenshots/run.png) |
14
1115## Run it
1216
1317```bash