From 68ac0be0d4fad68009031b841f6c78f7b2f55c61 Mon Sep 17 00:00:00 2001 From: Adam Moussa <166072409+amoussa1229@users.noreply.github.com> Date: Wed, 8 Jul 2026 16:21:21 -0400 Subject: [PATCH] INFRA-143: suppress reCAPTCHA site-key gitleaks FP + clear js-yaml DoS advisory (#27) * chore(security): suppress gitleaks FP on public reCAPTCHA site key (INFRA-143) The SITE_KEY in assets/js/form.js is a Google reCAPTCHA v3 site key, public by design (shipped to the browser, passed to grecaptcha.execute). It is not a secret and is not rotated. Add a scoped repo-local gitleaks suppression with justification for the current (line 7) and historical (line 5) hits so the pre-push scanner stops blocking on it. * fix(deps): pin gray-matter js-yaml to 3.15.0 to clear DoS advisory (INFRA-143) gray-matter (transitive via @11ty/eleventy) pulled js-yaml 3.14.2, flagged by GHSA-h67p-54hq-rp68 (quadratic-complexity DoS in merge-key handling, moderate). Add a scoped nested npm override pinning gray-matter's js-yaml to ^3.15.0, the fixed 3.x release, leaving Eleventy's direct js-yaml 4.x untouched. npm audit now reports 0 vulnerabilities and the Eleventy build passes. --- .security-review/suppressions.json | 12 ++++++++++++ package-lock.json | 6 +++--- package.json | 5 +++++ 3 files changed, 20 insertions(+), 3 deletions(-) create mode 100644 .security-review/suppressions.json diff --git a/.security-review/suppressions.json b/.security-review/suppressions.json new file mode 100644 index 0000000..6729f1f --- /dev/null +++ b/.security-review/suppressions.json @@ -0,0 +1,12 @@ +{ + "suppressions": [ + { + "id": "gitleaks-generic-api-key-7", + "justification": "False positive. assets/js/form.js:7 SITE_KEY is a Google reCAPTCHA v3 SITE key, which is public by design: it is shipped to every browser and passed to grecaptcha.execute() client-side (form.js:17,63). It is not a secret and must not be rotated. Pairs with the reCAPTCHA SECRET key held server-side. INFRA-143." + }, + { + "id": "gitleaks-generic-api-key-5", + "justification": "False positive. Same public reCAPTCHA v3 SITE key as gitleaks-generic-api-key-7, flagged at assets/js/form.js:5 from an earlier commit (gitleaks scans git history). Public by design, not a secret. INFRA-143." + } + ] +} diff --git a/package-lock.json b/package-lock.json index 5a9e449..820c13f 100644 --- a/package-lock.json +++ b/package-lock.json @@ -743,9 +743,9 @@ } }, "node_modules/gray-matter/node_modules/js-yaml": { - "version": "3.14.2", - "resolved": "https://registry.npmjs.org/js-yaml/-/js-yaml-3.14.2.tgz", - "integrity": "sha512-PMSmkqxr106Xa156c2M265Z+FTrPl+oxd/rgOQy2tijQeK5TxQ43psO1ZCwhVOSdnn+RzkzlRz/eY4BgJBYVpg==", + "version": "3.15.0", + "resolved": "https://registry.npmjs.org/js-yaml/-/js-yaml-3.15.0.tgz", + "integrity": "sha512-ttBQIIQPDeLjpPOohtUdXuXUVoA2uIB6fEH9HyJ7234s5mBJ5wTx20njxplLZQgLaOfpmPQA7X2t5AX6tIPbog==", "license": "MIT", "dependencies": { "argparse": "^1.0.7", diff --git a/package.json b/package.json index 06f325d..18a7b80 100644 --- a/package.json +++ b/package.json @@ -11,5 +11,10 @@ "license": "UNLICENSED", "dependencies": { "@11ty/eleventy": "3.1.6" + }, + "overrides": { + "gray-matter": { + "js-yaml": "^3.15.0" + } } }