chore(security): repo-local suppressions for adjudicated FPs #88
No reviewers
Labels
No labels
app
bug
ci
compliance
content
dependencies
docs
documentation
duplicate
enhancement
github_actions
good first issue
help wanted
infra
invalid
javascript
needs-triage
python
question
tests
wontfix
No milestone
No project
No assignees
1 participant
Due date
No due date set.
Dependencies
No dependencies set.
Reference: adam/orchestrator#88
Loading…
Add table
Reference in a new issue
No description provided.
Delete branch "chore/security-review-suppressions"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
Moves proof-or-kill-verified false positives from the machine-level store to a tracked repo-local
.security-review/suppressions.jsonso the Open SWE daily-report automation (which cannot see~/.configon the Mac) resolves them:gitleaks-generic-api-key-2—.env.exampleplaceholder env var (reported in the daily scan)gitleaks-private-key-128/30/34— no-write-token detector + its synthetic fixtures (agent-team, decommissioned; kept for the history scan)Justifications were sanitized so the tracked file reproduces no secret trigger string. Machine-level copy retained until this merges.