mirror of
https://github.com/Sea-Haven-Industries/open-swe.git
synced 2026-10-03 02:13:28 +00:00
* chore: decommission self-hosted AWS LangGraph stack Removes the now-dead self-host IaC and AWS-only CI/CD after destroying the dev + prod CloudFormation stacks (open-swe-dev, open-swe-prod, open-swe-iam, and the dev-exclusive CDKToolkit-oswedev bootstrap) in account 328440206208, us-east-1. The deployment is now managed (LangGraph Cloud + Vercel). - remove infra/ (CDK app: app + IAM stacks, constructs, aspects, tests) - remove deploy/ami (Packer AMI build) and deploy/seahaven (boot/config scripts, DEPLOYMENT/ROTATION runbooks) - remove AWS-only workflows: cd-infra, ci-infra, build-artifacts, rollback - README: rewrite the Deployment section to the managed LangGraph Cloud + Vercel view; drop dead links to infra/ and deploy/seahaven Preserved: the shared default CDKToolkit bootstrap and promote-dev-to-prod.yml. The RETAIN'd Secrets Manager shells and open-swe-<env>-assets S3 buckets survive cdk destroy by design (orphaned) and need a separate deliberate cleanup. * chore: clean up dangling references left by the AWS decommission Folds in the FIX-level items from the #64 review gates (GPT-4.1 cross-review + /sh-security-review), none of which were blockers: - delete orphaned .github/scripts/{package-artifacts,publish-and-deploy,roll-box, rollback}.sh — their only callers were the removed AWS deploy workflows - drop the deleted /infra dir from dependabot.yml npm directories (was producing a recurring Dependabot config error) - remove the stale OSWE-IAC-SECRETS-LIST-01 suppression (referenced the deleted infra/lib/constructs/instance-role.ts) - repoint the README promotion link to promote-to-main.yml (renamed in #63) The promote-dev-to-prod.yml comment in check-dev-green.sh is intentionally left to #63, which rewrites that same line.
118 lines
8.1 KiB
JSON
118 lines
8.1 KiB
JSON
{
|
|
"suppressions": [
|
|
{
|
|
"id": "AUTHZ-SLACK-BOT-DEFAULT-001",
|
|
"title": "Slack entrypoint lacks a per-user repo-access check; default-bot PR authoring removes the implicit per-user repo boundary",
|
|
"file": "agent/webapp.py",
|
|
"severity": "medium",
|
|
"status": "confirmed",
|
|
"suppression_justification": "ACCEPTED (Adam, 2026-06-29) while Open SWE has a SINGLE user. The Slack run entrypoint does not call require_repo_access_for_user (dashboard/schedule do), so with the default App installation token a mapped Slack user could act on any repo in the App's installation regardless of their own access. Bounded by the compensating controls: the seahaven-openswe App is installed on open-swe-pilot ONLY and ALLOWED_GITHUB_REPOS is locked, so the bot token cannot reach repos outside the pilot, and the only triggering user is the owner. Tracked as open issue #59 with three remediation options. REVISIT TRIGGER: before expanding the user base OR broadening the App's installation beyond open-swe-pilot — at that point this becomes HIGH and a gate (option (c): per-user check when a token exists) must be added. Verified medium (not high) by /sh-security-review proof-or-kill verifier.",
|
|
"owner": "adam@seahavenind.com",
|
|
"added": "2026-06-29"
|
|
},
|
|
{
|
|
"id": "gitleaks-generic-api-key-89",
|
|
"title": "Hardcoded credential flagged in encryption-roundtrip test fixture (CWE-798)",
|
|
"file": "tests/test_team_credentials.py",
|
|
"line": 89,
|
|
"rule": "CWE-798",
|
|
"severity": "low",
|
|
"status": "false-positive",
|
|
"justification": "Test fixture, not a real credential. The value \"secret-api-1234\" is a fake Datadog API key used by test_datadog_roundtrip_and_redaction to assert that the plaintext key is recoverable after an encrypt/decrypt round-trip (and that the stored record holds ciphertext, not the plaintext). It is never a live secret and is scoped to the unit test only.",
|
|
"suppression_justification": "Test fixture, not a real credential. The value \"secret-api-1234\" is a fake Datadog API key used by test_datadog_roundtrip_and_redaction to assert that the plaintext key is recoverable after an encrypt/decrypt round-trip. It is never a live secret and is scoped to the unit test only.",
|
|
"owner": "adam@seahavenind.com",
|
|
"added": "2026-06-29"
|
|
},
|
|
{
|
|
"id": "gitleaks-generic-api-key-79",
|
|
"title": "Hardcoded credential flagged in encryption-roundtrip test fixture (CWE-798)",
|
|
"file": "tests/test_team_credentials.py",
|
|
"line": 79,
|
|
"rule": "CWE-798",
|
|
"severity": "low",
|
|
"status": "false-positive",
|
|
"justification": "Test fixture, not a real credential. Same fake Datadog API key \"secret-api-1234\" passed into connect_datadog by test_datadog_roundtrip_and_redaction. Never a live secret; scoped to the unit test only.",
|
|
"suppression_justification": "Test fixture, not a real credential. Same fake Datadog API key \"secret-api-1234\" passed into connect_datadog by test_datadog_roundtrip_and_redaction. Never a live secret; scoped to the unit test only.",
|
|
"owner": "adam@seahavenind.com",
|
|
"added": "2026-06-29"
|
|
},
|
|
{
|
|
"id": "gitleaks-generic-api-key-23",
|
|
"title": "Hardcoded credential flagged in GitHub-token TTL test fixture (CWE-798)",
|
|
"file": "tests/test_github_token_ttl.py",
|
|
"line": 23,
|
|
"rule": "CWE-798",
|
|
"severity": "high",
|
|
"status": "false-positive",
|
|
"justification": "Test fixture, not a real credential. The literal \"ghp_secret\" is a fake GitHub token used by the cached-token TTL/revocation unit tests. Not a valid 40-char GitHub PAT, never a live secret, scoped to the unit test only.",
|
|
"suppression_justification": "Test fixture, not a real credential. The literal \"ghp_secret\" is a fake GitHub token used by the cached-token TTL/revocation unit tests. Not a valid 40-char GitHub PAT, never a live secret, scoped to the unit test only.",
|
|
"owner": "adam@seahavenind.com",
|
|
"added": "2026-06-29"
|
|
},
|
|
{
|
|
"id": "gitleaks-generic-api-key-24",
|
|
"title": "Dev-only CI env value flagged in .env.ci (history-only; file not at HEAD)",
|
|
"file": ".env.ci",
|
|
"line": 24,
|
|
"rule": "gitleaks-generic-api-key",
|
|
"severity": "high",
|
|
"status": "false-positive",
|
|
"justification": "False positive. .env.ci is the e2e CI env file (added in commit 5a52b9b2 'ci: run playwright e2e tests') holding DELIBERATELY-FAKE, dev-only values explicitly marked 'committed intentionally' (e.g. GITHUB_WEBHOOK_SECRET=dev-secret and a dev-only Fernet TOKEN_ENCRYPTION_KEY used solely by the Playwright e2e suite). No production secret: real prod values live in Secrets Manager (open-swe-prod/*). gitleaks scans committed history so it flags this even though the file is not present at HEAD.",
|
|
"suppression_justification": "Dev-only CI fixture value, intentionally committed for the e2e suite; not a production secret (prod secrets are in Secrets Manager). Flagged from git history; file not present at HEAD.",
|
|
"owner": "adam@seahavenind.com",
|
|
"added": "2026-06-29"
|
|
},
|
|
{
|
|
"id": "gitleaks-generic-api-key-3",
|
|
"title": "Placeholder flagged in .env.example (history-only; file not at HEAD)",
|
|
"file": ".env.example",
|
|
"line": 3,
|
|
"rule": "gitleaks-generic-api-key",
|
|
"severity": "high",
|
|
"status": "false-positive",
|
|
"justification": "False positive. .env.example contains placeholder/example values only, by definition not real secrets. gitleaks scans committed history so it flags the placeholder even though the file is not present at HEAD.",
|
|
"suppression_justification": "Example/placeholder value in a committed .env.example; flagged from git history. Not a real secret.",
|
|
"owner": "adam@seahavenind.com",
|
|
"added": "2026-06-29"
|
|
},
|
|
{
|
|
"id": "gitleaks-private-key-1",
|
|
"title": "Fake CI RSA key flagged in .github/ci/fake_github_app_key.pem (history-only)",
|
|
"file": ".github/ci/fake_github_app_key.pem",
|
|
"line": 1,
|
|
"rule": "gitleaks-private-key",
|
|
"severity": "high",
|
|
"status": "false-positive",
|
|
"justification": "False positive. This is a throwaway test RSA key (the filename is literally 'fake_github_app_key.pem') referenced by .env.ci for the Playwright e2e suite. It is not a production GitHub App key (the real prod key is in Secrets Manager open-swe-prod/GITHUB_APP_PRIVATE_KEY). gitleaks scans committed history; the file is not present at HEAD.",
|
|
"suppression_justification": "Deliberately-fake CI test key for the e2e suite; not a production GitHub App key. Flagged from git history; file not present at HEAD.",
|
|
"owner": "adam@seahavenind.com",
|
|
"added": "2026-06-29"
|
|
},
|
|
{
|
|
"id": "gitleaks-private-key-185",
|
|
"title": "Documentation example PEM flagged in INSTALLATION.md (CWE-798)",
|
|
"file": "INSTALLATION.md",
|
|
"line": 185,
|
|
"rule": "gitleaks-private-key",
|
|
"severity": "high",
|
|
"status": "false-positive",
|
|
"justification": "False positive. INSTALLATION.md shows the .env format with an example GITHUB_APP_PRIVATE_KEY=\"-----BEGIN RSA PRIVATE KEY-----...\" block in the setup instructions. It is illustrative documentation, not a real key.",
|
|
"suppression_justification": "Documentation example of the GITHUB_APP_PRIVATE_KEY .env format in INSTALLATION.md; not a real key.",
|
|
"owner": "adam@seahavenind.com",
|
|
"added": "2026-06-29"
|
|
},
|
|
{
|
|
"id": "gitleaks-generic-api-key-29",
|
|
"title": "README prose flagged as a generic API key (CWE-798)",
|
|
"file": "README.md",
|
|
"line": 29,
|
|
"rule": "gitleaks-generic-api-key",
|
|
"severity": "high",
|
|
"status": "false-positive",
|
|
"justification": "False positive. README.md line 29 is descriptive project prose (the 'Open SWE is the open-source version...' paragraph / blog link); gitleaks' generic-api-key entropy heuristic mis-matched a token in the text. No secret is present.",
|
|
"suppression_justification": "README descriptive prose mis-matched by the generic-api-key entropy heuristic; no secret present.",
|
|
"owner": "adam@seahavenind.com",
|
|
"added": "2026-06-29"
|
|
}
|
|
]
|
|
}
|