Skip to content

chore: trigger release rebuild - #2165

Merged
Andriy Knysh (aknysh) merged 1 commit into
mainfrom
chore/trigger-release-rebuild-2
Mar 11, 2026
Merged

Andriy Knysh (aknysh) merged 1 commit into
mainfrom
chore/trigger-release-rebuild-2

Conversation

@aknysh

@aknysh Andriy Knysh (aknysh) commented Mar 11, 2026 •

Copy link
Copy Markdown
Member

Summary

  • Trivial comment change to trigger the release pipeline
  • Rebuilds v1.209.0 with fresh binaries from the correct commit
  • Previous release had stale binaries attached from an earlier failed build

Test plan

  • Verify test.yml workflow runs on merge
  • Verify release is created with fresh binaries

Summary by CodeRabbit

  • Documentation
    • Improved clarity in version variable documentation.

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
@aknysh
Andriy Knysh (aknysh) requested a review from a team as a code owner March 11, 2026 00:35
@aknysh Andriy Knysh (aknysh) added the patch A minor, backward compatible change label Mar 11, 2026
@github-actions github-actions Bot added the size/xs Extra small size PR label Mar 11, 2026
@github-actions

Copy link
Copy Markdown

Dependency Review

✅ No vulnerabilities or license issues found.

Scanned Files

None

@aknysh Andriy Knysh (aknysh) self-assigned this Mar 11, 2026
@coderabbitai

coderabbitai Bot commented Mar 11, 2026 •

Copy link
Copy Markdown
Contributor
📝 Walkthrough

Walkthrough

Documentation comment for the Version variable in pkg/version/version.go was updated to clarify that it represents the Atmos CLI binary. This is a comment-only change with no functional impact.

Changes

Cohort / File(s) Summary
Documentation Update
pkg/version/version.go
Updated the documentation comment for the exported Version variable to specify "the Atmos CLI binary" instead of "the Atmos CLI."

Estimated code review effort

🎯 1 (Trivial) | ⏱️ ~2 minutes

Suggested labels

no-release

🚥 Pre-merge checks | ✅ 2 | ❌ 1

❌ Failed checks (1 inconclusive)

Check name Status Explanation Resolution
Title check ❓ Inconclusive The title 'chore: trigger release rebuild' is vague and doesn't clearly convey the actual change: a minor documentation comment update to the Version variable. Consider a more specific title like 'chore: update Version variable documentation' or 'docs: clarify Version variable refers to binary' to better reflect the actual change made.
✅ Passed checks (2 passed)
Check name Status Explanation
Docstring Coverage ✅ Passed No functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check.
Description Check ✅ Passed Check skipped - CodeRabbit’s high-level summary is enabled.

✏️ Tip: You can configure your own custom pre-merge checks in the settings.

✨ Finishing Touches
  • 📝 Generate docstrings (stacked PR)
  • 📝 Generate docstrings (commit on current branch)
🧪 Generate unit tests (beta)
  • Create PR with unit tests
  • Post copyable unit tests in a comment
  • Commit unit tests in branch chore/trigger-release-rebuild-2

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands and usage tips.

@codecov

codecov Bot commented Mar 11, 2026 •

Copy link
Copy Markdown

Codecov Report

✅ All modified and coverable lines are covered by tests.
✅ Project coverage is 77.16%. Comparing base (66ac17c) to head (6172315).
⚠️ Report is 1 commits behind head on main.

Additional details and impacted files

Impacted file tree graph

@@            Coverage Diff             @@
##             main    #2165      +/-   ##
==========================================
- Coverage   77.18%   77.16%   -0.02%     
==========================================
  Files         951      951              
  Lines       90375    90375              
==========================================
- Hits        69755    69740      -15     
- Misses      16540    16554      +14     
- Partials     4080     4081       +1     
Flag Coverage Δ
unittests 77.16% <ø> (-0.02%) ⬇️

Flags with carried forward coverage won't be shown. Click here to find out more.
see 3 files with indirect coverage changes

🚀 New features to boost your workflow:
  • ❄️ Test Analytics: Detect flaky tests, report on failures, and find test suite problems.

@aknysh
Andriy Knysh (aknysh) merged commit ab2481a into main Mar 11, 2026
99 of 100 checks passed
@aknysh
Andriy Knysh (aknysh) deleted the chore/trigger-release-rebuild-2 branch March 11, 2026 02:27
@github-actions

Copy link
Copy Markdown

These changes were released in v1.209.0.

@github-actions

Copy link
Copy Markdown

These changes were released in v1.210.0-test.8.

@github-actions

Copy link
Copy Markdown

These changes were released in v1.210.0-test.10.

Andriy Knysh (aknysh) added a commit that referenced this pull request Mar 22, 2026
Co-authored-by: Claude Opus 4.6 <noreply@anthropic.com>
Andriy Knysh (aknysh) added a commit that referenced this pull request Apr 7, 2026
…ediation (#2282)

* updates

* updates

* Implement AI security & compliance commands with AWS Security Hub integration

Add `atmos ai security` and `atmos ai compliance` CLI commands with full AWS
Security Hub integration, dual-path finding-to-component mapping (tag-based
and heuristic), and multi-format report rendering (markdown/json/yaml/csv).

Phase 1: Schema, CLI commands, report renderers, sentinel errors.
Phase 2: AWS SDK clients (Security Hub, Resource Groups Tagging API),
paginated finding fetcher with filters, batch tag-based mapping (Path A),
naming convention and resource type heuristics (Path B), unit tests.

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>

* Register security AI tools: list_findings, describe_finding, compliance_report

Phase 3: Register three new AI tools for the agent to use:
- atmos_list_findings: Query Security Hub findings with severity/source/stack filters
- atmos_describe_finding: Get detailed info about a specific finding by ID
- atmos_compliance_report: Generate compliance posture reports for CIS/PCI/SOC2/HIPAA/NIST

Tools are registered as read-only core tools in the AI tool registry, available
in both chat and MCP modes.

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>

* Phase 4: Add caching, docs, tests, and multi-provider PRD update

- Add findings cache with configurable TTL to reduce AWS API calls
- Add report renderer tests (17 tests covering all formats)
- Add Docusaurus docs for atmos ai security and compliance commands
- Increase test coverage from 71% to 91%
- Update PRD to support all 7 Atmos AI providers (not just Bedrock)
- Position Bedrock for enterprise customers needing data residency

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>

* Add AI-powered finding analysis with multi-provider support

- Implement FindingAnalyzer that sends findings + component source to
  configured AI provider for root cause analysis and remediation
- Parse AI response into structured Remediation (root cause, deploy
  command, risk level)
- Integrate analyzer into security command (runs unless --no-ai is set)
- Add ErrAISecurityAnalysisFailed sentinel error
- Tests for analyzer, prompt building, response parsing (91.8% coverage)

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>

* Add atmos_analyze_finding AI tool for deep finding analysis

- Register atmos_analyze_finding tool in AI tool system
- Fetches finding by ID, maps to component, runs AI analysis
- Returns root cause, remediation, deploy command, and risk level
- Accepts optional component_source and stack_config for richer context

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>

* Refactor security/compliance from atmos ai to atmos aws namespace

Move security and compliance commands from `atmos ai` to `atmos aws` since
they are AWS-specific and work without AI. AI analysis is now opt-in via
the `--ai` flag (default: off) instead of opt-out via `--no-ai`.

Key changes:
- Move cmd/ai/security.go → cmd/aws/security.go
- Move cmd/ai/compliance.go → cmd/aws/compliance.go
- Move pkg/ai/security/ → pkg/aws/security/
- Move schema from ai.security → aws.security (AWSSecuritySettings)
- Flip --no-ai flag to --ai (opt-in, default false)
- Use error builder pattern for all error handling
- Replace errors.Join with fmt.Errorf for order preservation
- Add tests for parseOutputFormat, parseSource, parseSeverities, etc.
- Add Docusaurus docs under cli/commands/aws/ and cli/configuration/aws/
- Update PRD to v0.3 with aws namespace and --ai flag
- Update depguard to allow AWS SDK in pkg/aws/security/

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>

* Make --ai a global persistent flag and update PRD with implementation status

Move --ai from a command-local flag on `atmos aws security` to a global
persistent flag available to all commands. Register via GlobalOptionsBuilder
with ATMOS_AI env var support. Update PRD to v0.4 with detailed completion
status for all phases. Update global-flags.mdx documentation.

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>

* updates

* updates

* updates

* updates

* updates

* updates

* updates

* chore: trigger release rebuild (#2165)

Co-authored-by: Claude Opus 4.6 <noreply@anthropic.com>

* updates

* updates

* fix: AWS security compliance — controls flag, total_controls, credential validation, tests

1. Wire up --controls flag in compliance command — parses comma-separated
   control IDs, filters report, recalculates score.

2. Fix compliance total_controls — was set to failing count (score always 0%).
   Now uses DescribeStandardsControls API with graceful fallback.

3. Add AWS credential validation — early STS GetCallerIdentity check before
   pipeline starts. Clear error with actionable hints.

4. Add 30+ new tests — all testable functions at 100% coverage.
   Covers: flag parsing, error sentinels, validation, report building,
   control filtering, shorthand aliases.

Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>

* feat: add Atmos Auth identity integration to AWS security commands

Add `identity` field to `AWSSecuritySettings` schema and `--identity`/`-i`
CLI flag to both `atmos aws security analyze` and `atmos aws compliance report`.

When set, credentials are resolved through the Atmos Auth provider chain
(SSO → role assumption → isolated credentials), targeting the delegated
admin account where Security Hub aggregates all findings.

Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>

* test: add coverage for auth context, client cache, and identity field

- AWS client cache: newAWSClientCache, WithAuthContext, empty maps
- resolveAuthContext: empty identity (nil), non-empty with no auth config (error)
- Schema: identity field read/write, empty default
- Coverage: WithAuthContext 100%, resolveAuthContext 73%, pkg/aws/security 90.1%

Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>

* feat: add default region to AWS security config

Add `region` field to AWSSecuritySettings for Security Hub aggregation
region. Precedence: --region CLI flag > config region > default (us-east-1).

Combined with `identity`, users configure once in atmos.yaml:
  aws:
    security:
      identity: "security-readonly"  # Which account
      region: "us-east-2"            # Which region

No extra flags needed for subsequent queries.

Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>

* docs: update PRD config example and flags table with identity and region

Add identity and region fields to the main Configuration section example.
Add --identity flag to CLI flags table.

Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>

* feat: structured remediation schema and AI skill for consistent output

Two changes ensuring consistent, reproducible AI analysis across all providers:

1. Formalized Remediation schema — added Steps, References fields, changed
   StackChanges to string. Every output follows the same structure.

2. Created atmos-aws-security agent skill — embedded as system prompt via
   go:embed. Instructs AI to use exact section headers that map directly
   to Remediation struct fields. Parser handles both structured and legacy
   formats via extractFirstMatch fallback.

Refactored for complexity compliance:
- parseRemediationResponse uses extractFirstMatch helper (17 → 8 complexity)
- parseListItems/extractListItem replace parseNumberedList/parseReferenceList
- Named constants for magic numbers

New tests: skill prompt embedding, parseListItems (6 cases),
structured format parsing, fallback format parsing, JSON round-trip.

Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>

* docs: add data pipeline and schema diagram to security PRD

Shows the complete flow: AWS APIs → Finding → ComponentMapping → Remediation
→ Report → ReportRenderer (4 formats). Explains behavior with and without
--ai flag, and how the skill prompt ensures consistent AI output.

Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>

* feat: render all Remediation schema fields in Markdown and CSV output

Markdown now renders: root cause, numbered steps, code changes (diff format),
stack changes, deploy command, risk level, and references. Falls back to
Description when no structured fields are populated.

CSV now includes root_cause, deploy_command, risk_level columns.

Refactored for complexity: extracted renderSteps, renderCodeChanges,
renderReferences helpers.

Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>

* feat: multi-turn tool-aware AI analysis for security findings

API providers now use SendMessageWithSystemPromptAndTools with the full
Atmos tool registry. The AI can call atmos_describe_component,
read_component_file, read_stack_file, etc. to gather context before
generating remediation. Tool loop runs up to 10 iterations.

CLI providers automatically fall back to single-prompt mode when
SendMessageWithSystemPromptAndTools returns ErrCLIProviderToolsNotSupported.

Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>

* docs: add aws-security-compliance example

Minimal example showing atmos aws security analyze and compliance report
configuration with Atmos Auth, tag mapping, and optional AI remediation.

Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>

* docs: add identity and region to AWS security website docs

Updated 3 files:
- cli/configuration/aws/security.mdx: identity and region in Quick Start,
  Full Configuration, and Settings Reference
- cli/commands/aws/security/analyze.mdx: --identity flag, updated config example
- cli/commands/aws/compliance/report.mdx: --identity flag, updated config example

Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>

* docs: add blog post and roadmap for AWS security & compliance

Blog post covers: finding analysis, code mapping, AI remediation,
compliance reports, auth integration, output formats.

Roadmap: 5 shipped milestones added to aws-security initiative (84% progress).

Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>

* fix: remove duplicate ai flag registration causing panic

registerAIFlags was called twice in NewGlobalOptionsBuilder — once at
line 41 and again at line 44 (copy-paste error). Both ai and skill
flags were registered twice, causing a panic on startup.

Removed the first duplicate call, keeping the single registration
in its logical position after performance flags.

Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>

* fix: render security/compliance Markdown output with colors

When format is Markdown and output is stdout, pipe through ui.Markdown()
for themed rendering with colors. File output remains raw Markdown.

Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>

* fix: use configured tag names in unmapped findings message, colored Markdown

- Unmapped findings message now uses tag names from aws.security.tag_mapping
  config instead of hardcoded "atmos:*"
- Markdown output to stdout rendered with colors via ui.Markdown()
- File output remains raw Markdown

Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>

* fix: add Mapped By field, lower naming convention confidence to low

- Add "Mapped By" field to Markdown output showing how the mapping was
  determined (tag, naming-convention, resource-type)
- Lower naming convention confidence from medium to low — the heuristic
  of taking the last hyphen-separated segment as the component name is
  unreliable for multi-word components (e.g., "origin" from
  "example-static-app-origin")
- Note: 0 exact (tag-based) mappings suggests the tag API is queried
  in the wrong account (security account vs resource account). This is
  a known limitation to fix in a follow-up.

Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>

* docs: update PRD with production testing findings and known limitations

Items 27-31: colored output, Mapped By field, configurable tag names,
naming convention confidence fix, duplicate flag fix.

Known limitations from InSpatial production testing:
- Cross-account tag lookup (0 exact matches)
- Naming convention unreliable for multi-word components
- --ai flag not working from security command context

Updated remaining work with specific fixes needed.

Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>

* feat: extract resource tags from Security Hub findings, show in reports

Security Hub ASFF findings include Resources[].Tags with all resource tags.
This eliminates the need for cross-account Tagging API calls.

Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>

* feat: context tags mapping strategy for reliable component extraction

New heuristic (confidence: high, method: "context-tags") that uses
Cloud Posse context tags (Namespace, Tenant, Environment, Stage, Name)
to reconstruct the naming prefix and extract the component name.

Example: Name=ins-plat-use2-dev-example-static-app-origin with context
tags → component=example-static-app-origin, stack=plat-use2-dev.

Mapping priority: finding-tag (exact) → tag-api (exact) →
context-tags (high) → naming-convention (low) → resource-type (low).

Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>

* feat: account mapping, ECR repo extraction, duplicate grouping

1. Account-level findings (AWS::::Account:ID) map to account names
   via configurable account_map in aws.security config.

2. ECR repository findings extract repo/image name as component.

3. Duplicate findings (same title) grouped in Markdown output with
   affected resources table instead of repeated entries.

Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>

* fix: show tags in grouped findings, add Mapped By column

Grouped findings now show:
- Mapped By column in the resource table
- Collapsible Resource Tags section (<details>) for findings with tags
- AI analysis only processes mapped findings (unmapped skipped)

Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>

* feat: add --no-group flag to disable finding grouping

By default, duplicate findings (same title) are grouped in Markdown
output. Use --no-group to show each finding individually with full
details and tags — useful for AI pipelines and detailed analysis.

Usage:
  atmos aws security analyze --no-group
  atmos aws security analyze --no-group --format json --file findings.json

Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>

* docs: add --no-group flag, account_map to example and website docs

- Example: add account_map, --no-group usage
- Security analyze docs: add --no-group flag, account_map in config
- Security config reference: add account_map to settings and config example

Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>

* fix: exclude display-only fields from JSON/YAML output

TagMapping and GroupFindings are display-only settings used by the
Markdown renderer. Changed to json:"-" yaml:"-" to prevent leaking.

Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>

* fix: filter by stack/component AFTER mapping, not at AWS API level

Security Hub has no concept of Atmos stacks. The --stack and --component
flags now filter findings after mapping via tags or heuristics.

Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>

* fix: increase default max-findings from 50 to 500

50 was too low for multi-account orgs — with post-mapping filtering,
we need to fetch enough findings to cover all accounts before filtering
by stack/component. AI cost is controlled separately (only mapped
findings are sent to AI). Users can still override with --max-findings.

Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>

* fix: ECR repo mapper resolves stack from account map

ECR findings had empty stack because mapByECRRepo only extracted the
component name. Now uses the account_map to resolve the finding's
account ID to an account/stack name.

Before: component=monitor-nats, stack="" (395 findings)
After:  component=monitor-nats, stack="core-artifacts"

Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>

* fix: resource-type mapper resolves stack from account map

Same fix as ECR repo mapper — use account_map to set the stack name
from the finding's account ID. Fixes the last empty-stack finding
(AwsEc2Instance in core-auto).

Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>

* fix: always show message when no findings match filters

Previously the "no findings" message only showed for Markdown format.
Now shows for all formats (JSON, YAML, CSV) so the user knows no
report was written.

Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>

* fix: use ui.Info/Success/Warning instead of hardcoded icons

Replace all hardcoded emoji icons (🔍, ✅, 🗺️, 🤖, 📊) with the
ui layer functions that handle theming automatically:
- ui.Info() for status messages
- ui.Success() for completion messages
- ui.Warning() for warnings
- ui.Successf()/ui.Infof() for formatted messages

Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>

* docs: update PRD with production testing results and mapping accuracy

Items 40-42: max-findings 500, account map for ECR/resource-type, themed UI.

Production results: 97.2% mapping accuracy (486/500), 5 mapping methods,
stack/component filtering verified across multiple stacks.

Replaced Known Limitations with Production Testing Results table
showing exact counts per method and verified filter scenarios.

Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>

* feat: AI analysis improvements — dedup, retry, color fix, docs

- Deduplicate findings before AI analysis: same title+component+stack
  share remediation (4 identical findings → 1 API call)
- Retry with exponential backoff on transient AI errors (529/429/5xx)
  using pkg/retry: 3 attempts, 2s initial delay, 15s max, 30% jitter
- Increase default timeout to 300s when --ai is used (multi-turn tool
  analysis with retries needs more time)
- Fix glamour color profile: add explicit WithColorProfile to
  renderMarkdown() for consistent colored output
- Update PRD to v0.8 with items 43-47 and production AI test results
- Update blog post and example README with full AI analysis showcase
  (findings breakdown, anomaly detection, remediation, risk assessment)

Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>

* fix: broken links to eks update-kubeconfig command

Fix 3 broken links pointing to /cli/commands/aws/eks-update-kubeconfig
(flat path) → /cli/commands/aws/eks/update-kubeconfig (correct nested path).

Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>

* fix: compliance report framework filter, control counting, and table

- Fix framework filter: use PREFIX with full standard ID paths including
  type prefix (ruleset/ or standards/) since CONTAINS is not supported
- Replace deprecated DescribeStandardsControls with
  ListSecurityControlDefinitions (works in delegated admin mode)
- Remove empty Component/Remediation columns from compliance table
- Extract repeated framework name strings to constants (linter fix)
- Add compliance report examples (with and without --ai) to docs

Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>

* fix: docs consistency — max_findings default, source values, severity format

- Fix max_findings default from 50 to 500 in config docs and example YAML
- Add missing source values (macie, access-analyzer, all) to analyze docs
- Clarify severity is case-insensitive with default critical,high
- Fix PRD tag names from underscores to colons (atmos:stack, atmos:component)
- Simplify PRD to v1.0 (problem/solution/implementation/results structure)

Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>

* fix: add language tag to unlabeled code fence in agent skill

Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>

* [autofix.ci] apply automated fixes

* fix: address CodeRabbit review — compliance dedup, cache safety, global flags

- Fix compliance dedup: use SecurityControlID (e.g., EC2.18) instead of
  ComplianceStandard (framework ID) as dedup key
- Fix cache key: add Framework, Stack, Component; add nil guard
- Fix cache safety: copy slices on get/set to prevent mutation
- Fix global flags: parse BasePath in security and compliance commands
- Fix --framework flag: wire into QueryOptions for security analyze
- Fix CSV flush: check cw.Error() after Flush() in both renderers
- Fix auth region fallback: check authContext.Region before us-east-1
- Fix resolveAuthContext: nil guard, Profile validation, extract helper
- Fix INFORMATIONAL: include in summary table severity loops
- Fix Bedrock PRD: qualify data residency and compliance claims
- Fix PRD: strategy count 5→7, tag names use colons
- Fix roadmap: add pr:2282 to milestones, remove duplicate entries
- Fix CLI markdown: use $ prompt style per convention
- Document --ai flag for compliance report with examples
- Improve tests: table-driven auth, assert element contents, tool calls
- Update compliance examples with 35/42 (83%) production results

Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>

* fix: CodeRabbit review round 2 — coverage, global flags, rendering fixes

- Fix global config flags: pass Config, ConfigPath, Profile to InitCliConfig
  (not just BasePath) in both security and compliance commands
- Fix resolveAuthContext: check empty identity before nil config
- Fix AI analyzer warning: show visible ui.Warning instead of silent debug log
- Fix reportTarget: handle component-only case ("All Stacks / vpc")
- Fix grouped markdown: render remediation for grouped findings
- Fix NIST description: "NIST 800-53" not "NIST CSF" in compliance docs
- Improve test coverage: 45 new tests across credentials, renderer,
  fetcher, and mapper — pkg/aws/security/ coverage 85.5% → 91.8%

Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>

* test: consolidate reportTarget component-only case into table-driven test

Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>

* updates

* refactor: move security/compliance to subpackages, inline auth, Organizations API

Code organization:
- Move cmd/aws/security.go → cmd/aws/security/ subpackage (EKS/ECR pattern)
- Move cmd/aws/compliance.go → cmd/aws/compliance/ subpackage
- Delete cmd/aws/credentials.go — inline auth directly in each command
- Delete cmd/aws/common/ — no shared cmd-level packages needed
- Move skill_prompt.md → pkg/aws/security/markdown/
- Move ParseOutputFormat to pkg/aws/security/types.go (next to OutputFormat type)

Authentication:
- Inline authenticateAndResolveAWS() in each command — calls
  auth.CreateAndAuthenticateManagerWithAtmosConfig() directly, reads
  AuthContext.AWS (same pattern as S3 backend)
- Move ValidateAWSCredentials to pkg/aws/identity/identity.go
  (next to GetCallerIdentity)
- Use narrow stackInfoProvider interface for extractAWSAuthContext

AWS Organizations API:
- Add OrganizationsAPI interface and client for account name lookup
- resolveAccountName checks config account_map first (no API call),
  then falls back to DescribeAccount API, caches results
- Update example atmos.yaml and config docs — account_map is now optional

Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>

* fix: CodeRabbit review — ErrorIs, context threading, perf.Track, tests

- Use require.ErrorIs instead of assert.True(errors.Is(...)) in types_test
- Thread context.Context through resolveAccountName → lookupAccountName
  and all caller methods (mapByAccountID, mapByECRRepo, mapByResourceType)
- Add perf.Track to MapFinding public method
- Strengthen Args test to actually invoke Args() validator
- Add analyzer tests: direct tool call loop, error path, CLI fallback,
  nil tool result handling

Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>

* fix: friendly errors for missing AWS services, reduce example README

- Add wrapAWSServiceError() that detects Security Hub not enabled,
  access denied, and connection errors — provides actionable hints
  instead of raw AWS SDK error messages
- Add ValidateAWSCredentials tests via mockable getCallerIdentityFn
- Reduce example README from 302 to 119 lines — condensed output
  examples while keeping all 4 scenarios
- Add wrapAWSServiceError tests for all error patterns

Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>

* fix: rename ErrAISecurity → ErrAWSSecurity, remove AWS from error message

Address Erik's review:
- Remove "AWS" from ErrAWSSecurityNotEnabled message text
- Rename all ErrAISecurity* → ErrAWSSecurity* error sentinels (45 refs
  across 14 files) since these are AWS-specific errors

Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>

---------

Co-authored-by: Claude Opus 4.6 <noreply@anthropic.com>
Co-authored-by: autofix-ci[bot] <114827586+autofix-ci[bot]@users.noreply.github.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

patch A minor, backward compatible change size/xs Extra small size PR

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants