IP Library › Granted Patent US 12,748,851
Granted Patent B2
US 12,748,851 · App. 17/811,727 · Granted Sep 29, 2026

Correction of non-compliant files in a code repository

Inventors: Danrisha Young (Davenport, FL); Keshab Budhathoky (Glen Allen, VA); Lydia Yu (Austin, TX); Mohamed Seck (Aubrey, TX)
Assignee: Capital One Services, LLC
G06F21/577G06F8/75
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,748,851
App. No.
17/811,727
Granted
Sep 29, 2026
Kind
B2
Abstract

In some implementations, a device may perform a scan of a content of one or more files in a code repository for violations of one or more compliance rules, where the one or more files indicate a configuration for infrastructure to be provisioned in a cloud computing environment. The device may identify that the content of the one or more files includes at least one violation of the one or more compliance rules. The device may modify the content of the one or more files to correct the at least one violation in accordance with the one or more compliance rules. The device may determine a probability as to whether a build of code of the code repository, using the one or more files with the content modified, is likely to pass. The device may transmit a request to merge the one or more files into the code repository.

Claims (87)

1 . A compliance system for correction of non-compliant files in a code repository, the compliance system comprising:

one or more memories; and

one or more processors, coupled to the one or more memories, configured to:

obtain, from a repository system, first information relating to the code repository that includes one or more files that indicate a configuration for infrastructure that is to be provisioned in a cloud computing environment;

obtain, from a rules system different from the repository system, second information relating to one or more compliance rules for provisioning the infrastructure in the cloud computing environment;

identify, using natural language processing, at least one of a cloud computing provider for the cloud computing environment or a programming language used in the one or more files;

determine, based on the at least one of the cloud computing provider or the programming language, a parsing scheme;

perform, using the parsing scheme, a scan of a content of the one or more files for one or more violations of the one or more compliance rules;

identify, in connection with the scan of the content of the one or more files and based on the at least one of the cloud computing provider or the programming language, that the content of the one or more files includes at least one violation of the one or more violations;

modify the content of the one or more files to correct the at least one violation in accordance with the one or more compliance rules,

wherein modifying the content of the one or more files includes at least one of deleting, rearranging, or editing a portion of the content of the one or more files associated with the at least one violation;

transmit, to the repository system and after modifying the content of the one or more files, a request to merge modified content of the one or more files into the code repository;

determine, using a machine learning model and based on the at least one violation, a severity of the at least one violation; and

transmit, to a user device different from the repository system and associated with a user of the code repository, a notification indicating the severity of the at least one violation.

2 . The compliance system of claim 1 ,

wherein the machine learning model is trained to determine the severity of the at least one violation based on data indicating historical time lengths for implementing corrections of the one or more violations of the one or more compliance rules.

3 . The compliance system of claim 1 ,

wherein the first information is obtained responsive to detecting creation of the code repository.

4 . The compliance system of claim 1 ,

wherein the one or more processors, to modify the content of the one or more files, are configured to:

delete the portion of the content of the one or more files associated with the at least one violation.

5 . The compliance system of claim 1 ,

wherein the one or more processors, to modify the content of the one or more files, are configured to:

determine a change, to the portion of the content of the one or more files associated with the at least one violation, that corrects the at least one violation in accordance with the one or more compliance rules, wherein the change includes the at least one of deleting, rearranging, or editing the portion of the content of the one or more files; and

modify the portion of the content of the one or more files associated with the at least one violation in accordance with the change.

6 . The compliance system of claim 1 ,

wherein the infrastructure is a server, a serverless computing function, a load balancer, a volume, or a database.

7 . The compliance system of claim 1 ,

wherein the one or more files include at least a first file and a second file, and

wherein a file type of the first file is different from a file type of the second file.

8 . The compliance system of claim 1 ,

wherein the one or more processors are further configured to:

determine, based on the severity of the at least one violation, a recommendation of a deadline by which the request to merge the one or more files is to be acted upon,

wherein the notification indicating the severity of the at least one violation further indicates the recommendation of the deadline.

9 . The compliance system of claim 1 , wherein the request to merge the modified content includes a pull request to merge a clone of the code repository that includes the modified content into the code repository.

10 . A method of correction of non-compliant files in a code repository, comprising:

obtaining, by a device and from a repository system, first information relating to the code repository that includes one or more files that indicate a configuration for infrastructure that is to be provisioned in a cloud computing environment;

obtaining, by the device and from a rules system different from the repository system, second information relating to one or more compliance rules for provisioning the infrastructure in the cloud computing environment;

identifying, by the device and using natural language processing, at least one of a cloud computing provider for the cloud computing environment or a programming language used in the one or more files;

determining, by the device and based on the at least one of the cloud computing provider or the programming language, a parsing scheme;

performing, by the device and using the parsing scheme, a scan of a content of the one or more files for one or more violations of the one or more compliance rules;

identifying, by the device in connection with the scan of the content of the one or more files and based on the at least one of the cloud computing provider or the programming language, that the content of the one or more files includes at least one violation of the one or more violations;

modifying, by the device, the content of the one or more files to correct the at least one violation in accordance with the one or more compliance rules,

wherein modifying the content of the one or more files includes at least one of deleting, rearranging, or editing a portion of the content of the one or more files associated with the at least one violation;

determining, by the device using a machine learning model, a probability as to whether a build of code of the code repository, using the one or more files with the content of the one or more files that is modified, is likely to pass; and

transmitting, by the device, to the repository system, based on the probability that the build of code of the code repository is likely to pass, a request to merge the one or more files into the code repository.

11 . The method of claim 10 ,

wherein the at least one violation is a reference to a security group using an outdated release version.

12 . The method of claim 10 , further comprising:

determining, using an additional machine learning model and based on the at least one violation, a severity of the at least one violation; and

transmitting, to a user device associated with a user of the code repository, a notification indicating the severity of the at least one violation.

13 . The method of claim 10 ,

wherein modifying the content of the one or more files comprises:

deleting the portion of the content of the one or more files associated with the at least one violation.

14 . The method of claim 10 ,

wherein modifying the content of the one or more files comprises:

determining a change, to the portion of the content of the one or more files associated with the at least one violation, that corrects the at least one violation in accordance with the one or more compliance rules, wherein the change includes the at least one of deleting, rearranging, or editing the portion of the content of the one or more files associated with the at least one violation; and

modifying the portion of the content of the one or more files associated with the at least one violation in accordance with the change.

15 . The method of claim 10 ,

wherein the one or more files are multiple files across multiple code repositories associated with an entity, and

wherein the scan is of the content of the multiple files across the multiple code repositories.

16 . A non-transitory computer-readable medium storing a set of instructions for correction of non-compliant files in a code repository, the set of instructions comprising:

one or more instructions that, when executed by one or more processors of a device, cause the device to:

obtain, from a repository system, first information relating to the code repository that includes one or more files that indicate a configuration for infrastructure that is to be provisioned in a cloud computing environment;

obtain, from a rules system different from the repository system, second information relating to one or more compliance rules for provisioning the infrastructure in the cloud computing environment;

identify, using natural language processing, at least one of a cloud computing provider for the cloud computing environment or a programming language used in the one or more files;

determine, based on the at least one of the cloud computing provider or the programming language, a parsing scheme;

perform, using the parsing scheme, a scan of a content of the one or more files for one or more violations of the one or more compliance rules;

identify, in connection with the scan of the content of the one or more files and based on the at least one of the cloud computing provider or the programming language, that the content of the one or more files includes at least one violation of the one or more violations;

modify the content of the one or more files to correct the at least one violation in accordance with the one or more compliance rules,

wherein modifying the content of the one or more files includes at least one of deleting, rearranging, or editing a portion of the content of the one or more files associated with the at least one violation; and

transmit, to the repository system, a request to merge the one or more files into the code repository.

17 . The non-transitory computer-readable medium of claim 16 ,

wherein the one or more instructions, when executed by the one or more processors, further cause the device to:

determine, using a machine learning model, a recommendation of a modification to the content of the one or more files,

wherein the machine learning model is trained to determine the modification based on data indicating whether previous builds of code have passed or failed; and

transmit, to a user device associated with a user of the code repository, an additional notification indicating the recommendation of the modification.

18 . The non-transitory computer-readable medium of claim 16 ,

wherein the one or more instructions, when executed by the one or more processors, further cause the device to:

cause provisioning of the infrastructure in the cloud computing environment using the one or more files with the content of the one or more files that is modified.

19 . The non-transitory computer-readable medium of claim 16 ,

wherein the one or more instructions, that cause the device to modify the content of the one or more files, cause the device to:

delete the portion of the content of the one or more files associated with the at least one violation.

20 . The non-transitory computer-readable medium of claim 16 ,

wherein the one or more instructions, that cause the device to modify the content of the one or more files, cause the device to:

determine a change, to the portion of the content of the one or more files associated with the at least one violation, that corrects the at least one violation in accordance with the one or more compliance rules, wherein the change includes the at least one of deleting, rearranging, or editing the portion of the content of the one or more files associated with the at least one violation; and

modify the portion of the content of the one or more files associated with the at least one violation in accordance with the change.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jul 11, 2022
From: YOUNG, DANRISHA; BUDHATHOKY, KESHAB; YU, LYDIA; SECK, MOHAMED
To: CAPITAL ONE SERVICES, LLC
Reel/Frame 060475/0396 →
Continuity (1)
Related Publication 20240012909A1 · Jan 11, 2024
References Cited (9)
US 10255370B2 · Carpenter et al. · 2019 [cited by applicant]
US 10872029B1 · Bawcom · 2020 [cited by applicant]
US 11586437B1 · Tripp · 2023 [cited by examiner]
US 20170026416A1 · Carpenter · 2017 [cited by examiner]
US 20190347424A1 · Bezzi et al. · 2019 [cited by applicant]
US 20200301672A1 · Li · 2020 [cited by examiner]
US 20220198044A1 · Madhavan · 2022 [cited by examiner]
Dai, T., et al., “Automatically Detecting Risky Scripts in Infrastructure Code,” Proceedings of the 11th ACM Symposium on Cloud Computing, Oct. 12, 2020, pp. 358-371. [cited by applicant]
International Search Report and Written Opinion for Application No. PCT/US2023/068881, mailed on Oct. 13, 2023, 13 Pages. [cited by applicant]