chore(security): repo-local suppressions for adjudicated FPs #88

Merged
amoussa1229 merged 1 commit from chore/security-review-suppressions into main 2026-07-13 18:30:47 +00:00
amoussa1229 commented 2026-07-13 18:21:51 +00:00 (Migrated from github.com)

Moves proof-or-kill-verified false positives from the machine-level store to a tracked repo-local .security-review/suppressions.json so the Open SWE daily-report automation (which cannot see ~/.config on the Mac) resolves them:

  • gitleaks-generic-api-key-2 — .env.example placeholder env var (reported in the daily scan)
  • gitleaks-private-key-128/30/34 — no-write-token detector + its synthetic fixtures (agent-team, decommissioned; kept for the history scan)

Justifications were sanitized so the tracked file reproduces no secret trigger string. Machine-level copy retained until this merges.

Moves proof-or-kill-verified false positives from the machine-level store to a tracked repo-local `.security-review/suppressions.json` so the Open SWE daily-report automation (which cannot see `~/.config` on the Mac) resolves them: - `gitleaks-generic-api-key-2` — `.env.example` placeholder env var (reported in the daily scan) - `gitleaks-private-key-128/30/34` — no-write-token detector + its synthetic fixtures (agent-team, decommissioned; kept for the history scan) Justifications were **sanitized** so the tracked file reproduces no secret trigger string. Machine-level copy retained until this merges.
This repo is archived. You cannot comment on pull requests.
No description provided.