{ "suppressions": [ { "id": "AUTHZ-SLACK-BOT-DEFAULT-001", "title": "Slack entrypoint lacks a per-user repo-access check; default-bot PR authoring removes the implicit per-user repo boundary", "file": "agent/webapp.py", "severity": "medium", "status": "confirmed", "suppression_justification": "ACCEPTED (Adam, 2026-06-29) while Open SWE has a SINGLE user. The Slack run entrypoint does not call require_repo_access_for_user (dashboard/schedule do), so with the default App installation token a mapped Slack user could act on any repo in the App's installation regardless of their own access. Bounded by the compensating controls: the seahaven-openswe App is installed on open-swe-pilot ONLY and ALLOWED_GITHUB_REPOS is locked, so the bot token cannot reach repos outside the pilot, and the only triggering user is the owner. Tracked as open issue #59 with three remediation options. REVISIT TRIGGER: before expanding the user base OR broadening the App's installation beyond open-swe-pilot — at that point this becomes HIGH and a gate (option (c): per-user check when a token exists) must be added. Verified medium (not high) by /sh-security-review proof-or-kill verifier.", "owner": "adam@seahavenind.com", "added": "2026-06-29" }, { "id": "gitleaks-generic-api-key-89", "title": "Hardcoded credential flagged in encryption-roundtrip test fixture (CWE-798)", "file": "tests/test_team_credentials.py", "line": 89, "rule": "CWE-798", "severity": "low", "status": "false-positive", "justification": "Test fixture, not a real credential. The value \"secret-api-1234\" is a fake Datadog API key used by test_datadog_roundtrip_and_redaction to assert that the plaintext key is recoverable after an encrypt/decrypt round-trip (and that the stored record holds ciphertext, not the plaintext). It is never a live secret and is scoped to the unit test only.", "suppression_justification": "Test fixture, not a real credential. The value \"secret-api-1234\" is a fake Datadog API key used by test_datadog_roundtrip_and_redaction to assert that the plaintext key is recoverable after an encrypt/decrypt round-trip. It is never a live secret and is scoped to the unit test only.", "owner": "adam@seahavenind.com", "added": "2026-06-29" }, { "id": "gitleaks-generic-api-key-79", "title": "Hardcoded credential flagged in encryption-roundtrip test fixture (CWE-798)", "file": "tests/test_team_credentials.py", "line": 79, "rule": "CWE-798", "severity": "low", "status": "false-positive", "justification": "Test fixture, not a real credential. Same fake Datadog API key \"secret-api-1234\" passed into connect_datadog by test_datadog_roundtrip_and_redaction. Never a live secret; scoped to the unit test only.", "suppression_justification": "Test fixture, not a real credential. Same fake Datadog API key \"secret-api-1234\" passed into connect_datadog by test_datadog_roundtrip_and_redaction. Never a live secret; scoped to the unit test only.", "owner": "adam@seahavenind.com", "added": "2026-06-29" }, { "id": "gitleaks-generic-api-key-23", "title": "Hardcoded credential flagged in GitHub-token TTL test fixture (CWE-798)", "file": "tests/test_github_token_ttl.py", "line": 23, "rule": "CWE-798", "severity": "high", "status": "false-positive", "justification": "Test fixture, not a real credential. The literal \"ghp_secret\" is a fake GitHub token used by the cached-token TTL/revocation unit tests. Not a valid 40-char GitHub PAT, never a live secret, scoped to the unit test only.", "suppression_justification": "Test fixture, not a real credential. The literal \"ghp_secret\" is a fake GitHub token used by the cached-token TTL/revocation unit tests. Not a valid 40-char GitHub PAT, never a live secret, scoped to the unit test only.", "owner": "adam@seahavenind.com", "added": "2026-06-29" }, { "id": "gitleaks-generic-api-key-24", "title": "Dev-only CI env value flagged in .env.ci (history-only; file not at HEAD)", "file": ".env.ci", "line": 24, "rule": "gitleaks-generic-api-key", "severity": "high", "status": "false-positive", "justification": "False positive. .env.ci is the e2e CI env file (added in commit 5a52b9b2 'ci: run playwright e2e tests') holding DELIBERATELY-FAKE, dev-only values explicitly marked 'committed intentionally' (e.g. GITHUB_WEBHOOK_SECRET=dev-secret and a dev-only Fernet TOKEN_ENCRYPTION_KEY used solely by the Playwright e2e suite). No production secret: real prod values live in Secrets Manager (open-swe-prod/*). gitleaks scans committed history so it flags this even though the file is not present at HEAD.", "suppression_justification": "Dev-only CI fixture value, intentionally committed for the e2e suite; not a production secret (prod secrets are in Secrets Manager). Flagged from git history; file not present at HEAD.", "owner": "adam@seahavenind.com", "added": "2026-06-29" }, { "id": "gitleaks-generic-api-key-3", "title": "Placeholder flagged in .env.example (history-only; file not at HEAD)", "file": ".env.example", "line": 3, "rule": "gitleaks-generic-api-key", "severity": "high", "status": "false-positive", "justification": "False positive. .env.example contains placeholder/example values only, by definition not real secrets. gitleaks scans committed history so it flags the placeholder even though the file is not present at HEAD.", "suppression_justification": "Example/placeholder value in a committed .env.example; flagged from git history. Not a real secret.", "owner": "adam@seahavenind.com", "added": "2026-06-29" }, { "id": "gitleaks-private-key-1", "title": "Fake CI RSA key flagged in .github/ci/fake_github_app_key.pem (history-only)", "file": ".github/ci/fake_github_app_key.pem", "line": 1, "rule": "gitleaks-private-key", "severity": "high", "status": "false-positive", "justification": "False positive. This is a throwaway test RSA key (the filename is literally 'fake_github_app_key.pem') referenced by .env.ci for the Playwright e2e suite. It is not a production GitHub App key (the real prod key is in Secrets Manager open-swe-prod/GITHUB_APP_PRIVATE_KEY). gitleaks scans committed history; the file is not present at HEAD.", "suppression_justification": "Deliberately-fake CI test key for the e2e suite; not a production GitHub App key. Flagged from git history; file not present at HEAD.", "owner": "adam@seahavenind.com", "added": "2026-06-29" }, { "id": "gitleaks-private-key-185", "title": "Documentation example PEM flagged in INSTALLATION.md (CWE-798)", "file": "INSTALLATION.md", "line": 185, "rule": "gitleaks-private-key", "severity": "high", "status": "false-positive", "justification": "False positive. INSTALLATION.md shows the .env format with an example GITHUB_APP_PRIVATE_KEY=\"-----BEGIN RSA PRIVATE KEY-----...\" block in the setup instructions. It is illustrative documentation, not a real key.", "suppression_justification": "Documentation example of the GITHUB_APP_PRIVATE_KEY .env format in INSTALLATION.md; not a real key.", "owner": "adam@seahavenind.com", "added": "2026-06-29" }, { "id": "gitleaks-generic-api-key-29", "title": "README prose flagged as a generic API key (CWE-798)", "file": "README.md", "line": 29, "rule": "gitleaks-generic-api-key", "severity": "high", "status": "false-positive", "justification": "False positive. README.md line 29 is descriptive project prose (the 'Open SWE is the open-source version...' paragraph / blog link); gitleaks' generic-api-key entropy heuristic mis-matched a token in the text. No secret is present.", "suppression_justification": "README descriptive prose mis-matched by the generic-api-key entropy heuristic; no secret present.", "owner": "adam@seahavenind.com", "added": "2026-06-29" } ] }