Finalize security-review: repo-sourced hooks, two-tier nightly auto-discovery #6
2 changed files with 11 additions and 0 deletions
3
.gitignore
vendored
3
.gitignore
vendored
|
|
@ -7,3 +7,6 @@ __pycache__/
|
|||
.pytest_cache/
|
||||
.ruff_cache/
|
||||
.DS_Store
|
||||
|
||||
# Stray Atlassian Document Format exports left by an unrelated tool — not part of this repo.
|
||||
.adf_final*.json
|
||||
|
|
|
|||
8
.security-review/suppressions.json
Normal file
8
.security-review/suppressions.json
Normal file
|
|
@ -0,0 +1,8 @@
|
|||
{
|
||||
"suppressions": [
|
||||
{
|
||||
"id": "gitleaks-generic-api-key-2",
|
||||
"justification": "False positive. .env.example:2 is a documented placeholder token (not a live secret) that exists to show the required env var shape. gitleaks runs in git-mode and scans committed history, so it flags the placeholder even though the working-tree value is inert. No real credential is or was exposed. Reviewed 2026-06-16."
|
||||
}
|
||||
]
|
||||
}
|
||||
Reference in a new issue