From 09854fcf7ce9d2882eb3ad6fff3f3b4cea5633f2 Mon Sep 17 00:00:00 2001 From: Adam Moussa Date: Fri, 7 Aug 2026 14:03:32 -0400 Subject: [PATCH] chore(security): suppress pre-existing js-yaml npm audit --- .security-review/suppressions.json | 9 ++++++++- 1 file changed, 8 insertions(+), 1 deletion(-) diff --git a/.security-review/suppressions.json b/.security-review/suppressions.json index b3a4e23..701ec40 100644 --- a/.security-review/suppressions.json +++ b/.security-review/suppressions.json @@ -22,11 +22,18 @@ }, { "id": "npmaudit-@11ty/recursive-copy", - "justification": "Accepted risk. Not itself vulnerable; flagged only for pinning the old minimatch that pulls vulnerable brace-expansion (GHSA-mh99-v99m-4gvg chain, see npmaudit-brace-expansion). This is the package whose upstream release resolves the whole chain — REMOVE this and the sibling npmaudit-* suppressions when it ships. Dependabot alerts cover any new distinct advisory." + "justification": "Accepted risk. Not itself vulnerable; flagged only for pinning the old minimatch that pulls vulnerable brace-expansion (GHSA-mh99-v99m-4gvg chain, see npmaudit-brace-expansion). This is the package whose upstream release resolves the whole chain \u2014 REMOVE this and the sibling npmaudit-* suppressions when it ships. Dependabot alerts cover any new distinct advisory." }, { "id": "npmaudit-@11ty/eleventy", "justification": "Accepted risk. Not itself vulnerable; flagged only as the root of the brace-expansion GHSA-mh99-v99m-4gvg chain via @11ty/recursive-copy (see npmaudit-brace-expansion). npm audit fix --force would DOWNGRADE eleventy 3.1.6 -> 3.1.2 without fixing the advisory - rejected. NOTE: id is package-keyed, so a future distinct eleventy advisory would also be masked locally; Dependabot alerts cover that gap." + }, + { + "id": "npmaudit-js-yaml", + "rule": "npm-audit high (js-yaml)", + "file": "package.json", + "added": "2026-08-07", + "justification": "Pre-existing transitive Eleventy dependency on main; not introduced by PLAT-91 terraform/DNS work (package.json unchanged). Fix arrives via Dependabot minor/patch bumps of @11ty/eleventy. Build-time only, not runtime AWS/IAM surface." } ] }