From 536d440282d81f4ff0e7c3ab195428abc5b2b5ce Mon Sep 17 00:00:00 2001 From: Adam Moussa <166072409+amoussa1229@users.noreply.github.com> Date: Mon, 13 Jul 2026 14:30:51 -0400 Subject: [PATCH] chore(security): add repo-local suppressions for adjudicated FPs (#219) Moves proof-or-kill-verified false positives (Fastfile runtime PEM-assembly boilerplate; Podfile.lock CocoaPods SPEC CHECKSUMs) from machine-level to a tracked repo-local .security-review/suppressions.json so the Open SWE daily-report automation resolves them. Justifications sanitized to avoid reproducing the begin-marker literal. Machine-level copy retained until merge. --- .security-review/suppressions.json | 28 ++++++++++++++++++++++++++++ 1 file changed, 28 insertions(+) create mode 100644 .security-review/suppressions.json diff --git a/.security-review/suppressions.json b/.security-review/suppressions.json new file mode 100644 index 0000000..1e06ab0 --- /dev/null +++ b/.security-review/suppressions.json @@ -0,0 +1,28 @@ +{ + "suppressions": [ + { + "id": "gitleaks-private-key-26", + "justification": "False positive. mobile/fastlane/Fastfile:26 is Ruby that ASSEMBLES a PEM wrapper (a begin/end private-key marker plus an interpolated base64 body) to normalize an App Store Connect signing key supplied at runtime via CI secret. No key material is committed; the begin-marker literal in source is what trips gitleaks. Known detector-FP pattern. Verified proof-or-kill 2026-07-13." + }, + { + "id": "gitleaks-private-key-46", + "justification": "False positive. mobile/fastlane/Fastfile:46 — same runtime PEM-assembly boilerplate as line 26 (base64->DER->PEM candidate construction). No committed key material." + }, + { + "id": "gitleaks-private-key-58", + "justification": "False positive. mobile/fastlane/Fastfile:58 — same runtime PEM-assembly boilerplate (double-base64->DER->PEM candidate construction). No committed key material." + }, + { + "id": "gitleaks-generic-api-key-2243", + "justification": "False positive. mobile/ios/Podfile.lock:2243 is a CocoaPods SPEC CHECKSUM (a deterministic pod-source integrity hash), not an API key. Podfile.lock checksums are public integrity digests, not secrets." + }, + { + "id": "gitleaks-generic-api-key-2319", + "justification": "False positive. mobile/ios/Podfile.lock:2319 is a CocoaPods SPEC CHECKSUM (pod integrity digest), not an API key." + }, + { + "id": "gitleaks-generic-api-key-2445", + "justification": "False positive. mobile/ios/Podfile.lock:2445 is a CocoaPods SPEC CHECKSUM (pod integrity digest, react-native-keychain pod), not an API key." + } + ] +}