mirror of
https://github.com/Sea-Haven-Industries/seahaven-site.git
synced 2026-09-30 04:13:15 +00:00
Some checks are pending
Deploy / deploy (push) Waiting to run
* build(deps): resolve npm audit advisories via in-range bumps npm audit fix bumps js-yaml 4.3.0, linkify-it 5.0.2, liquidjs 10.27.2, and brace-expansion 1.1.16 to clear four high DoS advisories. Eleventy build verified passing at 3.1.6. The remaining brace-expansion advisory (GHSA-mh99-v99m-4gvg) has no in-range fix: the patch exists only in 5.0.8, and @11ty/recursive-copy pins an older minimatch. Exposure is build-time only (glob patterns from our own config, never untrusted input), so it is suppressed with justification in .security-review/suppressions.json rather than forcing the eleventy downgrade npm audit fix --force proposes. Remove the npmaudit-* suppressions when recursive-copy ships a minimatch >=10.0.3 bump. * ci: add least-privilege permissions blocks to workflow callers Resolves code scanning alert #3 (actions/missing-workflow-permissions). Callable workflow only needs contents: read; the dependency-review callable already declares it internally, this caps the caller token to match. * ci(dependency-review): allow adjudicated brace-expansion GHSA Re-pins the callable to 07ce007 (adds the allow-ghsas input, org PR #89) and allows GHSA-mh99-v99m-4gvg, which the review check flags on the bumped-but-still-in-range brace-expansion 1.1.16. The advisory has no in-range fix and is an accepted risk with written justification in .security-review/suppressions.json; remove the allowance together with those suppressions when @11ty/recursive-copy ships a minimatch >=10.0.3 bump.
32 lines
3.1 KiB
JSON
32 lines
3.1 KiB
JSON
{
|
|
"suppressions": [
|
|
{
|
|
"id": "gitleaks-generic-api-key-7",
|
|
"justification": "False positive. assets/js/form.js:7 SITE_KEY is a Google reCAPTCHA v3 SITE key, which is public by design: it is shipped to every browser and passed to grecaptcha.execute() client-side (form.js:17,63). It is not a secret and must not be rotated. Pairs with the reCAPTCHA SECRET key held server-side. INFRA-143."
|
|
},
|
|
{
|
|
"id": "gitleaks-generic-api-key-5",
|
|
"justification": "False positive. Same public reCAPTCHA v3 SITE key as gitleaks-generic-api-key-7, flagged at assets/js/form.js:5 from an earlier commit (gitleaks scans git history). Public by design, not a secret. INFRA-143."
|
|
},
|
|
{
|
|
"id": "gitleaks-generic-api-key-2464",
|
|
"justification": "False positive. gitleaks flags a high-entropy string at wp-content/plugins/elementor-pro/assets/js/notes/vendors-...-e4587e.js:2464 (a minified radix-ui vendor bundle: the token is a bundler variable, not a credential). This legacy WordPress/Elementor bundle was removed from the repo and survives only in git history, which gitleaks scans. Not a live secret, nothing to rotate. INFRA-181."
|
|
},
|
|
{
|
|
"id": "npmaudit-brace-expansion",
|
|
"justification": "Accepted risk. GHSA-mh99-v99m-4gvg (OOM DoS in glob brace expansion) has no in-range fix: the patch exists only in brace-expansion 5.0.8, and @11ty/recursive-copy@4.0.4 pins minimatch <10.0.3, which requires brace-expansion 1.x. Exposure is build-time only: Eleventy expands glob patterns from our own config, never untrusted input, so the DoS is not reachable by an attacker. REMOVE when @11ty/recursive-copy ships a minimatch >=10.0.3 bump (npm audit will go clean). GitHub Dependabot alerts remain active as the independent detector for any NEW advisory on this package."
|
|
},
|
|
{
|
|
"id": "npmaudit-minimatch",
|
|
"justification": "Accepted risk. Not itself vulnerable; flagged only for depending on the vulnerable brace-expansion 1.x range (GHSA-mh99-v99m-4gvg, see npmaudit-brace-expansion). Same chain, same build-time-only exposure, same removal trigger. NOTE: id is package-keyed, so a future distinct minimatch advisory would also be masked locally; Dependabot alerts cover that gap."
|
|
},
|
|
{
|
|
"id": "npmaudit-@11ty/recursive-copy",
|
|
"justification": "Accepted risk. Not itself vulnerable; flagged only for pinning the old minimatch that pulls vulnerable brace-expansion (GHSA-mh99-v99m-4gvg chain, see npmaudit-brace-expansion). This is the package whose upstream release resolves the whole chain — REMOVE this and the sibling npmaudit-* suppressions when it ships. Dependabot alerts cover any new distinct advisory."
|
|
},
|
|
{
|
|
"id": "npmaudit-@11ty/eleventy",
|
|
"justification": "Accepted risk. Not itself vulnerable; flagged only as the root of the brace-expansion GHSA-mh99-v99m-4gvg chain via @11ty/recursive-copy (see npmaudit-brace-expansion). npm audit fix --force would DOWNGRADE eleventy 3.1.6 -> 3.1.2 without fixing the advisory - rejected. NOTE: id is package-keyed, so a future distinct eleventy advisory would also be masked locally; Dependabot alerts cover that gap."
|
|
}
|
|
]
|
|
}
|