From f2bc576dfd61392c7e1b6e420d2fffeb2ecf4a7a Mon Sep 17 00:00:00 2001 From: Adam Moussa <166072409+amoussa1229@users.noreply.github.com> Date: Mon, 13 Jul 2026 14:30:55 -0400 Subject: [PATCH] chore(security): add repo-local suppressions for adjudicated FPs (#56) Moves proof-or-kill-verified false positives (CDK synth-time esbuild execSync x4; CDK LogRetention IAM boilerplate; Yealink provisioning-template token placeholders) from machine-level to a tracked repo-local .security-review/suppressions.json so the Open SWE daily-report automation resolves them. Machine-level copy retained until merge. INFRA-105. --- .security-review/suppressions.json | 36 ++++++++++++++++++++++++++++++ 1 file changed, 36 insertions(+) create mode 100644 .security-review/suppressions.json diff --git a/.security-review/suppressions.json b/.security-review/suppressions.json new file mode 100644 index 0000000..ed6bb5f --- /dev/null +++ b/.security-review/suppressions.json @@ -0,0 +1,36 @@ +{ + "suppressions": [ + { + "id": "semgrep-detect-child-process-55", + "justification": "False positive. CDK local-bundling tryBundle(outputDir) in lib/door-unlock-stack.ts. execSync runs esbuild at cdk-synth time; outputDir is supplied by the CDK framework (staging temp dir) and the other path segments are repo-relative constants. No untrusted input, build-time only on a trusted host, never runs at request time. Verified proof-or-kill 2026-07-13. INFRA-105." + }, + { + "id": "semgrep-detect-child-process-84", + "justification": "False positive. Same as semgrep-detect-child-process-55: CDK local-bundling esbuild execSync with framework-supplied synth-time outputDir. Build-time only. INFRA-105." + }, + { + "id": "semgrep-detect-child-process-122", + "justification": "False positive. Same as semgrep-detect-child-process-55: CDK local-bundling esbuild execSync with framework-supplied synth-time outputDir. Build-time only. INFRA-105." + }, + { + "id": "semgrep-detect-child-process-202", + "justification": "False positive. Same as semgrep-detect-child-process-55: CDK local-bundling esbuild execSync with framework-supplied synth-time outputDir. Build-time only. INFRA-105." + }, + { + "id": "checkov-CKV_AWS_111-234", + "justification": "False positive. CDK-generated LogRetention custom-resource role (cdk.out synth output). logs:PutRetentionPolicy/DeleteRetentionPolicy on Resource:* is inherent to the aws-cdk LogRetention singleton construct (log-group names are not known at synth time). Accepted CDK boilerplate, not hand-written IAM. INFRA-105." + }, + { + "id": "gitleaks-generic-api-key-5193", + "justification": "False positive. A provisioning-template token placeholder (the literal __DOOR_UNLOCK_TOKEN__) in Yealink T54W templates — not a secret. The real token was rotated in SSM (INFRA-105, param v3 2026-07-06) and the historical live token was removed by the git-filter-repo history scrub; only the placeholder remains." + }, + { + "id": "gitleaks-generic-api-key-900", + "justification": "False positive. Historical blob of a Yealink provisioning template. After the INFRA-105 history scrub this line holds the __DOOR_UNLOCK_TOKEN__ placeholder only; the pre-scrub live token was rotated in SSM 2026-07-06 and is invalid." + }, + { + "id": "gitleaks-generic-api-key-3097", + "justification": "False positive. A __DOOR_UNLOCK_TOKEN__ placeholder in a Yealink provisioning template (unlock linekey) — not a secret. Live token rotated in SSM 2026-07-06; history scrubbed via git-filter-repo (INFRA-105)." + } + ] +}