Skip to content

Self-audit

The repository dogfoods gitlab-project-audit against its own GitLab project using the exact same public CLI path available to every user.

There is no self-audit special case in the audit engine.

Files

The self-audit is defined by:

.gitlab-project-audit.self.yml
.gitlab-project-audit.self-baseline.json
scripts/self_audit.py

Policy

The self-audit uses the versioned minimal preset: seven essential project, governance, and CI rules.

Two current repository conditions are accepted temporarily and remain visible as explicit suppressions:

Rule Reason
project.description-present Project description is deferred until public release copy is finalized.
governance.pipeline-required Merge gating is deferred while the local-runner workflow is stabilized.

Both suppressions have an expiry date. They are not disabled rules and they remain visible in audit reports.

Run locally

Set a GitLab token with permission to inspect the repository:

export GITLAB_TOKEN="..."

Then run:

poetry run python scripts/self_audit.py

The script invokes the normal command equivalent to:

gitlab-project-audit audit DiogoRibeiro7/gitlab-project-audit \
  --config .gitlab-project-audit.self.yml \
  --baseline .gitlab-project-audit.self-baseline.json \
  --fail-on-new

Baseline behavior

The committed baseline represents the current seven-rule policy.

  • unchanged accepted findings do not fail the command
  • resolved findings remain visible
  • new or worsened unsuppressed findings return exit code 1
  • rule execution errors return exit code 3

When the repository intentionally changes policy or resolves an accepted exception, regenerate the baseline with the normal public CLI rather than editing the audit engine.

CI integration

Self-audit is intentionally a local developer command for now. It is not a required CI job, so it does not consume runner capacity or require a long-lived GitLab API token in CI.