diff --git a/.security-review/suppressions.json b/.security-review/suppressions.json index b3a4e23..701ec40 100644 --- a/.security-review/suppressions.json +++ b/.security-review/suppressions.json @@ -22,11 +22,18 @@ }, { "id": "npmaudit-@11ty/recursive-copy", - "justification": "Accepted risk. Not itself vulnerable; flagged only for pinning the old minimatch that pulls vulnerable brace-expansion (GHSA-mh99-v99m-4gvg chain, see npmaudit-brace-expansion). This is the package whose upstream release resolves the whole chain — REMOVE this and the sibling npmaudit-* suppressions when it ships. Dependabot alerts cover any new distinct advisory." + "justification": "Accepted risk. Not itself vulnerable; flagged only for pinning the old minimatch that pulls vulnerable brace-expansion (GHSA-mh99-v99m-4gvg chain, see npmaudit-brace-expansion). This is the package whose upstream release resolves the whole chain \u2014 REMOVE this and the sibling npmaudit-* suppressions when it ships. Dependabot alerts cover any new distinct advisory." }, { "id": "npmaudit-@11ty/eleventy", "justification": "Accepted risk. Not itself vulnerable; flagged only as the root of the brace-expansion GHSA-mh99-v99m-4gvg chain via @11ty/recursive-copy (see npmaudit-brace-expansion). npm audit fix --force would DOWNGRADE eleventy 3.1.6 -> 3.1.2 without fixing the advisory - rejected. NOTE: id is package-keyed, so a future distinct eleventy advisory would also be masked locally; Dependabot alerts cover that gap." + }, + { + "id": "npmaudit-js-yaml", + "rule": "npm-audit high (js-yaml)", + "file": "package.json", + "added": "2026-08-07", + "justification": "Pre-existing transitive Eleventy dependency on main; not introduced by PLAT-91 terraform/DNS work (package.json unchanged). Fix arrives via Dependabot minor/patch bumps of @11ty/eleventy. Build-time only, not runtime AWS/IAM surface." } ] }