chore(security): add repo-local suppression for test-fixture FP (gitleaks-45) (#48)
Some checks failed
Deploy / deploy (push) Has been cancelled

Moves the false-positive suppression for tests/test_submit_order.py:45 (a dummy
test API key, proof-or-kill verified 2026-07-13) from machine-level to a tracked
repo-local .security-review/suppressions.json so the Open SWE daily-report
automation — which cannot see ~/.config on the Mac — resolves it. Machine-level
copy retained until this merges.
This commit is contained in:
Adam Moussa 2026-07-13 14:30:43 -04:00 • committed by GitHub
parent 65bbe6f8b5
commit e2d1b2fce8
No known key found for this signature in database
GPG key ID: B5690EEEBB952194

View file

@ -0,0 +1,8 @@
{
"suppressions": [
{
"id": "gitleaks-generic-api-key-45",
"justification": "False positive. tests/test_submit_order.py:45 defines a low-entropy dummy test constant used as the mocked get_secret return value and injected as the x-api-key header in the test harness (the module makes no real AWS calls). Not a live credential; the real key lives in Secrets Manager (FORM_APIKEY_SM_NAME). Verified proof-or-kill 2026-07-13. Moved from machine-level to repo-local so the Open SWE daily-report automation resolves it."
}
]
}