From 572ae3ca416c9c315bfdd91a4d4837ec07e01b61 Mon Sep 17 00:00:00 2001 From: Adam Moussa Date: Tue, 16 Jun 2026 15:55:01 -0400 Subject: [PATCH] Move orchestrator gitleaks suppression out of repo history Per the machine-level-suppressions policy, the .env.example FP suppression now lives at ~/.config/sea-haven/security-review/orchestrator/suppressions.json (resolved first by the hooks), not a committed .security-review/suppressions.json. Gate still passes via the machine-level file. --- .security-review/suppressions.json | 8 -------- 1 file changed, 8 deletions(-) delete mode 100644 .security-review/suppressions.json diff --git a/.security-review/suppressions.json b/.security-review/suppressions.json deleted file mode 100644 index 56cee62..0000000 --- a/.security-review/suppressions.json +++ /dev/null @@ -1,8 +0,0 @@ -{ - "suppressions": [ - { - "id": "gitleaks-generic-api-key-2", - "justification": "False positive. .env.example:2 is a documented placeholder token (not a live secret) that exists to show the required env var shape. gitleaks runs in git-mode and scans committed history, so it flags the placeholder even though the working-tree value is inert. No real credential is or was exposed. Reviewed 2026-06-16." - } - ] -}