From 4a690050ed2e0759bb7a372bc9c6c63ce2c9226e Mon Sep 17 00:00:00 2001 From: Adam Moussa <166072409+amoussa1229@users.noreply.github.com> Date: Mon, 13 Jul 2026 14:30:47 -0400 Subject: [PATCH] chore(security): add repo-local suppressions for adjudicated FPs (#88) Moves proof-or-kill-verified false positives (.env.example placeholder; no-write-token detector fixtures) from machine-level to a tracked repo-local .security-review/suppressions.json so the Open SWE daily-report automation resolves them (it cannot see ~/.config on the Mac). Justifications sanitized to avoid reproducing trigger strings. Machine-level copy retained until merge. --- .security-review/suppressions.json | 20 ++++++++++++++++++++ 1 file changed, 20 insertions(+) create mode 100644 .security-review/suppressions.json diff --git a/.security-review/suppressions.json b/.security-review/suppressions.json new file mode 100644 index 0000000..723f5fc --- /dev/null +++ b/.security-review/suppressions.json @@ -0,0 +1,20 @@ +{ + "suppressions": [ + { + "id": "gitleaks-generic-api-key-2", + "justification": "False positive. .env.example line 2 is a documented placeholder env var (empty/inert value) that exists to show the required variable shape. gitleaks runs in git-mode and scans committed history, so it flags the placeholder even though the working-tree value is not a live secret. No real credential is or was exposed." + }, + { + "id": "gitleaks-private-key-128", + "justification": "False positive. agent-team/scripts/assert_no_write_token.py is the no-write-token DETECTOR: it must reference a PEM begin-marker for a private key in order to find leaked keys. Source assembles the marker at runtime, but gitleaks scans committed history where an earlier contiguous-literal residual flags. Not a live key. (agent-team decommissioned 2026-06-26; entry kept for the history scan.)" + }, + { + "id": "gitleaks-private-key-30", + "justification": "False positive. Synthetic/redacted PEM fixture in agent-team/tests/test_no_write_token.py used to exercise the no-write-token audit; not a live key. Flagged only because gitleaks scans committed history." + }, + { + "id": "gitleaks-private-key-34", + "justification": "False positive. Second synthetic/redacted PEM fixture in agent-team/tests/test_no_write_token.py; not a live key. Flagged only because gitleaks scans committed history." + } + ] +}