From af5ce7362e97838c8dcfbd4710ef3d5b9eec36b2 Mon Sep 17 00:00:00 2001 From: Adam Moussa Date: Tue, 16 Jun 2026 15:00:00 -0400 Subject: [PATCH] Suppress orchestrator's own .env.example gitleaks false positive gitleaks git-mode scans committed history, so the .env.example placeholder flags from history and would block the orchestrator's own pre-push gate. Suppress it with a written justification. Also gitignore stray .adf_final*.json left by an unrelated tool. --- .gitignore | 3 +++ .security-review/suppressions.json | 8 ++++++++ 2 files changed, 11 insertions(+) create mode 100644 .security-review/suppressions.json diff --git a/.gitignore b/.gitignore index ce218a5..428cb36 100644 --- a/.gitignore +++ b/.gitignore @@ -7,3 +7,6 @@ __pycache__/ .pytest_cache/ .ruff_cache/ .DS_Store + +# Stray Atlassian Document Format exports left by an unrelated tool — not part of this repo. +.adf_final*.json diff --git a/.security-review/suppressions.json b/.security-review/suppressions.json new file mode 100644 index 0000000..56cee62 --- /dev/null +++ b/.security-review/suppressions.json @@ -0,0 +1,8 @@ +{ + "suppressions": [ + { + "id": "gitleaks-generic-api-key-2", + "justification": "False positive. .env.example:2 is a documented placeholder token (not a live secret) that exists to show the required env var shape. gitleaks runs in git-mode and scans committed history, so it flags the placeholder even though the working-tree value is inert. No real credential is or was exposed. Reviewed 2026-06-16." + } + ] +}