Move orchestrator gitleaks suppression out of repo history
Per the machine-level-suppressions policy, the .env.example FP suppression now lives at ~/.config/sea-haven/security-review/orchestrator/suppressions.json (resolved first by the hooks), not a committed .security-review/suppressions.json. Gate still passes via the machine-level file.
This commit is contained in:
parent
80d5391785
commit
572ae3ca41
1 changed files with 0 additions and 8 deletions
|
|
@ -1,8 +0,0 @@
|
|||
{
|
||||
"suppressions": [
|
||||
{
|
||||
"id": "gitleaks-generic-api-key-2",
|
||||
"justification": "False positive. .env.example:2 is a documented placeholder token (not a live secret) that exists to show the required env var shape. gitleaks runs in git-mode and scans committed history, so it flags the placeholder even though the working-tree value is inert. No real credential is or was exposed. Reviewed 2026-06-16."
|
||||
}
|
||||
]
|
||||
}
|
||||
Reference in a new issue