chore(security): add repo-local suppressions for adjudicated FPs (#56)
Some checks are pending
Deploy / deploy (push) Waiting to run

Moves proof-or-kill-verified false positives (CDK synth-time esbuild execSync x4;
CDK LogRetention IAM boilerplate; Yealink provisioning-template token placeholders)
from machine-level to a tracked repo-local .security-review/suppressions.json so
the Open SWE daily-report automation resolves them. Machine-level copy retained
until merge. INFRA-105.
This commit is contained in:
Adam Moussa 2026-07-13 14:30:55 -04:00 • committed by GitHub
parent 07247d4044
commit f2bc576dfd
No known key found for this signature in database
GPG key ID: B5690EEEBB952194

View file

@ -0,0 +1,36 @@
{
"suppressions": [
{
"id": "semgrep-detect-child-process-55",
"justification": "False positive. CDK local-bundling tryBundle(outputDir) in lib/door-unlock-stack.ts. execSync runs esbuild at cdk-synth time; outputDir is supplied by the CDK framework (staging temp dir) and the other path segments are repo-relative constants. No untrusted input, build-time only on a trusted host, never runs at request time. Verified proof-or-kill 2026-07-13. INFRA-105."
},
{
"id": "semgrep-detect-child-process-84",
"justification": "False positive. Same as semgrep-detect-child-process-55: CDK local-bundling esbuild execSync with framework-supplied synth-time outputDir. Build-time only. INFRA-105."
},
{
"id": "semgrep-detect-child-process-122",
"justification": "False positive. Same as semgrep-detect-child-process-55: CDK local-bundling esbuild execSync with framework-supplied synth-time outputDir. Build-time only. INFRA-105."
},
{
"id": "semgrep-detect-child-process-202",
"justification": "False positive. Same as semgrep-detect-child-process-55: CDK local-bundling esbuild execSync with framework-supplied synth-time outputDir. Build-time only. INFRA-105."
},
{
"id": "checkov-CKV_AWS_111-234",
"justification": "False positive. CDK-generated LogRetention custom-resource role (cdk.out synth output). logs:PutRetentionPolicy/DeleteRetentionPolicy on Resource:* is inherent to the aws-cdk LogRetention singleton construct (log-group names are not known at synth time). Accepted CDK boilerplate, not hand-written IAM. INFRA-105."
},
{
"id": "gitleaks-generic-api-key-5193",
"justification": "False positive. A provisioning-template token placeholder (the literal __DOOR_UNLOCK_TOKEN__) in Yealink T54W templates — not a secret. The real token was rotated in SSM (INFRA-105, param v3 2026-07-06) and the historical live token was removed by the git-filter-repo history scrub; only the placeholder remains."
},
{
"id": "gitleaks-generic-api-key-900",
"justification": "False positive. Historical blob of a Yealink provisioning template. After the INFRA-105 history scrub this line holds the __DOOR_UNLOCK_TOKEN__ placeholder only; the pre-scrub live token was rotated in SSM 2026-07-06 and is invalid."
},
{
"id": "gitleaks-generic-api-key-3097",
"justification": "False positive. A __DOOR_UNLOCK_TOKEN__ placeholder in a Yealink provisioning template (unlock linekey) — not a secret. Live token rotated in SSM 2026-07-06; history scrubbed via git-filter-repo (INFRA-105)."
}
]
}