open-swe/.security-review
Adam Moussa 134963647b
Some checks are pending
Build & publish app artifacts / Publish + deploy (dev) (push) Waiting to run
Build & publish app artifacts / Publish + deploy (prod) (push) Waiting to run
Infra CD / Infra CI (pre-deploy) (push) Waiting to run
Infra CD / Deploy open-swe-dev (push) Blocked by required conditions
Infra CD / Deploy open-swe-prod (push) Blocked by required conditions
CI / Lint (push) Waiting to run
CI / Format check (push) Waiting to run
CI / Unit tests (push) Waiting to run
CI / Playwright E2E (push) Waiting to run
chore(security): suppress pre-existing history scanner false-positives (#56)
Adds repo-local suppressions for 5 verified-FP gitleaks findings that block
pushes (forcing --no-verify), all in committed history / docs / CI fixtures:
- .env.ci (dev-only e2e values, intentionally committed)
- .env.example (placeholders)
- .github/ci/fake_github_app_key.pem (throwaway CI test key)
- INSTALLATION.md (example GITHUB_APP_PRIVATE_KEY .env block)
- README.md (prose mis-matched by the generic-api-key heuristic)
Repo-local (not machine-level) so they load in git worktrees too. Also drops
the now-obsolete OSWE-IAC-AUDIT-01 suppression (B-1, fixed in #55).
2026-06-29 12:54:40 -04:00
..
suppressions.json chore(security): suppress pre-existing history scanner false-positives (#56) 2026-06-29 12:54:40 -04:00