mirror of
https://github.com/Sea-Haven-Industries/seahaven-site.git
synced 2026-09-30 06:33:16 +00:00
Some checks are pending
Deploy / deploy (push) Waiting to run
* feat(infra): add HCP Terraform for prod static hosting Greenfield S3+CloudFront+ACM+OIDC content-deploy role under /tf-managed/, with OOB mgmt DNS helper for ACM validation and apex alias cutover. * chore(security): suppress pre-existing js-yaml npm audit * feat(ci): retarget content deploy to seahaven-prod origin Point OIDC, S3 sync, and CloudFront invalidation at the HCP-managed prod hosting stack so GHA remains the content publish path after cutover.
39 lines
3.5 KiB
JSON
39 lines
3.5 KiB
JSON
{
|
|
"suppressions": [
|
|
{
|
|
"id": "gitleaks-generic-api-key-7",
|
|
"justification": "False positive. assets/js/form.js:7 SITE_KEY is a Google reCAPTCHA v3 SITE key, which is public by design: it is shipped to every browser and passed to grecaptcha.execute() client-side (form.js:17,63). It is not a secret and must not be rotated. Pairs with the reCAPTCHA SECRET key held server-side. INFRA-143."
|
|
},
|
|
{
|
|
"id": "gitleaks-generic-api-key-5",
|
|
"justification": "False positive. Same public reCAPTCHA v3 SITE key as gitleaks-generic-api-key-7, flagged at assets/js/form.js:5 from an earlier commit (gitleaks scans git history). Public by design, not a secret. INFRA-143."
|
|
},
|
|
{
|
|
"id": "gitleaks-generic-api-key-2464",
|
|
"justification": "False positive. gitleaks flags a high-entropy string at wp-content/plugins/elementor-pro/assets/js/notes/vendors-...-e4587e.js:2464 (a minified radix-ui vendor bundle: the token is a bundler variable, not a credential). This legacy WordPress/Elementor bundle was removed from the repo and survives only in git history, which gitleaks scans. Not a live secret, nothing to rotate. INFRA-181."
|
|
},
|
|
{
|
|
"id": "npmaudit-brace-expansion",
|
|
"justification": "Accepted risk. GHSA-mh99-v99m-4gvg (OOM DoS in glob brace expansion) has no in-range fix: the patch exists only in brace-expansion 5.0.8, and @11ty/recursive-copy@4.0.4 pins minimatch <10.0.3, which requires brace-expansion 1.x. Exposure is build-time only: Eleventy expands glob patterns from our own config, never untrusted input, so the DoS is not reachable by an attacker. REMOVE when @11ty/recursive-copy ships a minimatch >=10.0.3 bump (npm audit will go clean). GitHub Dependabot alerts remain active as the independent detector for any NEW advisory on this package."
|
|
},
|
|
{
|
|
"id": "npmaudit-minimatch",
|
|
"justification": "Accepted risk. Not itself vulnerable; flagged only for depending on the vulnerable brace-expansion 1.x range (GHSA-mh99-v99m-4gvg, see npmaudit-brace-expansion). Same chain, same build-time-only exposure, same removal trigger. NOTE: id is package-keyed, so a future distinct minimatch advisory would also be masked locally; Dependabot alerts cover that gap."
|
|
},
|
|
{
|
|
"id": "npmaudit-@11ty/recursive-copy",
|
|
"justification": "Accepted risk. Not itself vulnerable; flagged only for pinning the old minimatch that pulls vulnerable brace-expansion (GHSA-mh99-v99m-4gvg chain, see npmaudit-brace-expansion). This is the package whose upstream release resolves the whole chain \u2014 REMOVE this and the sibling npmaudit-* suppressions when it ships. Dependabot alerts cover any new distinct advisory."
|
|
},
|
|
{
|
|
"id": "npmaudit-@11ty/eleventy",
|
|
"justification": "Accepted risk. Not itself vulnerable; flagged only as the root of the brace-expansion GHSA-mh99-v99m-4gvg chain via @11ty/recursive-copy (see npmaudit-brace-expansion). npm audit fix --force would DOWNGRADE eleventy 3.1.6 -> 3.1.2 without fixing the advisory - rejected. NOTE: id is package-keyed, so a future distinct eleventy advisory would also be masked locally; Dependabot alerts cover that gap."
|
|
},
|
|
{
|
|
"id": "npmaudit-js-yaml",
|
|
"rule": "npm-audit high (js-yaml)",
|
|
"file": "package.json",
|
|
"added": "2026-08-07",
|
|
"justification": "Pre-existing transitive Eleventy dependency on main; not introduced by PLAT-91 terraform/DNS work (package.json unchanged). Fix arrives via Dependabot minor/patch bumps of @11ty/eleventy. Build-time only, not runtime AWS/IAM surface."
|
|
}
|
|
]
|
|
}
|