mirror of
https://github.com/Sea-Haven-Industries/seahaven-site.git
synced 2026-09-30 06:33:16 +00:00
* chore(security): suppress gitleaks FP on public reCAPTCHA site key (INFRA-143) The SITE_KEY in assets/js/form.js is a Google reCAPTCHA v3 site key, public by design (shipped to the browser, passed to grecaptcha.execute). It is not a secret and is not rotated. Add a scoped repo-local gitleaks suppression with justification for the current (line 7) and historical (line 5) hits so the pre-push scanner stops blocking on it. * fix(deps): pin gray-matter js-yaml to 3.15.0 to clear DoS advisory (INFRA-143) gray-matter (transitive via @11ty/eleventy) pulled js-yaml 3.14.2, flagged by GHSA-h67p-54hq-rp68 (quadratic-complexity DoS in merge-key handling, moderate). Add a scoped nested npm override pinning gray-matter's js-yaml to ^3.15.0, the fixed 3.x release, leaving Eleventy's direct js-yaml 4.x untouched. npm audit now reports 0 vulnerabilities and the Eleventy build passes.
12 lines
706 B
JSON
12 lines
706 B
JSON
{
|
|
"suppressions": [
|
|
{
|
|
"id": "gitleaks-generic-api-key-7",
|
|
"justification": "False positive. assets/js/form.js:7 SITE_KEY is a Google reCAPTCHA v3 SITE key, which is public by design: it is shipped to every browser and passed to grecaptcha.execute() client-side (form.js:17,63). It is not a secret and must not be rotated. Pairs with the reCAPTCHA SECRET key held server-side. INFRA-143."
|
|
},
|
|
{
|
|
"id": "gitleaks-generic-api-key-5",
|
|
"justification": "False positive. Same public reCAPTCHA v3 SITE key as gitleaks-generic-api-key-7, flagged at assets/js/form.js:5 from an earlier commit (gitleaks scans git history). Public by design, not a secret. INFRA-143."
|
|
}
|
|
]
|
|
}
|