mirror of
https://github.com/Sea-Haven-Industries/seahaven-door-unlock-api.git
synced 2026-09-30 07:03:12 +00:00
Some checks are pending
Deploy / deploy (push) Waiting to run
Moves proof-or-kill-verified false positives (CDK synth-time esbuild execSync x4; CDK LogRetention IAM boilerplate; Yealink provisioning-template token placeholders) from machine-level to a tracked repo-local .security-review/suppressions.json so the Open SWE daily-report automation resolves them. Machine-level copy retained until merge. INFRA-105.
36 lines
2.6 KiB
JSON
36 lines
2.6 KiB
JSON
{
|
|
"suppressions": [
|
|
{
|
|
"id": "semgrep-detect-child-process-55",
|
|
"justification": "False positive. CDK local-bundling tryBundle(outputDir) in lib/door-unlock-stack.ts. execSync runs esbuild at cdk-synth time; outputDir is supplied by the CDK framework (staging temp dir) and the other path segments are repo-relative constants. No untrusted input, build-time only on a trusted host, never runs at request time. Verified proof-or-kill 2026-07-13. INFRA-105."
|
|
},
|
|
{
|
|
"id": "semgrep-detect-child-process-84",
|
|
"justification": "False positive. Same as semgrep-detect-child-process-55: CDK local-bundling esbuild execSync with framework-supplied synth-time outputDir. Build-time only. INFRA-105."
|
|
},
|
|
{
|
|
"id": "semgrep-detect-child-process-122",
|
|
"justification": "False positive. Same as semgrep-detect-child-process-55: CDK local-bundling esbuild execSync with framework-supplied synth-time outputDir. Build-time only. INFRA-105."
|
|
},
|
|
{
|
|
"id": "semgrep-detect-child-process-202",
|
|
"justification": "False positive. Same as semgrep-detect-child-process-55: CDK local-bundling esbuild execSync with framework-supplied synth-time outputDir. Build-time only. INFRA-105."
|
|
},
|
|
{
|
|
"id": "checkov-CKV_AWS_111-234",
|
|
"justification": "False positive. CDK-generated LogRetention custom-resource role (cdk.out synth output). logs:PutRetentionPolicy/DeleteRetentionPolicy on Resource:* is inherent to the aws-cdk LogRetention singleton construct (log-group names are not known at synth time). Accepted CDK boilerplate, not hand-written IAM. INFRA-105."
|
|
},
|
|
{
|
|
"id": "gitleaks-generic-api-key-5193",
|
|
"justification": "False positive. A provisioning-template token placeholder (the literal __DOOR_UNLOCK_TOKEN__) in Yealink T54W templates — not a secret. The real token was rotated in SSM (INFRA-105, param v3 2026-07-06) and the historical live token was removed by the git-filter-repo history scrub; only the placeholder remains."
|
|
},
|
|
{
|
|
"id": "gitleaks-generic-api-key-900",
|
|
"justification": "False positive. Historical blob of a Yealink provisioning template. After the INFRA-105 history scrub this line holds the __DOOR_UNLOCK_TOKEN__ placeholder only; the pre-scrub live token was rotated in SSM 2026-07-06 and is invalid."
|
|
},
|
|
{
|
|
"id": "gitleaks-generic-api-key-3097",
|
|
"justification": "False positive. A __DOOR_UNLOCK_TOKEN__ placeholder in a Yealink provisioning template (unlock linekey) — not a secret. Live token rotated in SSM 2026-07-06; history scrubbed via git-filter-repo (INFRA-105)."
|
|
}
|
|
]
|
|
}
|