From e2d1b2fce8c072088ee2edc31501d85f717129a9 Mon Sep 17 00:00:00 2001 From: Adam Moussa <166072409+amoussa1229@users.noreply.github.com> Date: Mon, 13 Jul 2026 14:30:43 -0400 Subject: [PATCH] chore(security): add repo-local suppression for test-fixture FP (gitleaks-45) (#48) MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit Moves the false-positive suppression for tests/test_submit_order.py:45 (a dummy test API key, proof-or-kill verified 2026-07-13) from machine-level to a tracked repo-local .security-review/suppressions.json so the Open SWE daily-report automation — which cannot see ~/.config on the Mac — resolves it. Machine-level copy retained until this merges. --- .security-review/suppressions.json | 8 ++++++++ 1 file changed, 8 insertions(+) create mode 100644 .security-review/suppressions.json diff --git a/.security-review/suppressions.json b/.security-review/suppressions.json new file mode 100644 index 0000000..83ea9f9 --- /dev/null +++ b/.security-review/suppressions.json @@ -0,0 +1,8 @@ +{ + "suppressions": [ + { + "id": "gitleaks-generic-api-key-45", + "justification": "False positive. tests/test_submit_order.py:45 defines a low-entropy dummy test constant used as the mocked get_secret return value and injected as the x-api-key header in the test harness (the module makes no real AWS calls). Not a live credential; the real key lives in Secrets Manager (FORM_APIKEY_SM_NAME). Verified proof-or-kill 2026-07-13. Moved from machine-level to repo-local so the Open SWE daily-report automation resolves it." + } + ] +}