seahaven-site/.security-review/suppressions.json
Adam Moussa e9b121ecfa
Some checks failed
Deploy / deploy (push) Has been cancelled
chore(security): suppress historical elementor gitleaks FP (INFRA-181) (#29)
Adds a scoped suppression for gitleaks-generic-api-key-2464, a high-entropy
false positive in a removed Elementor/WordPress minified vendor bundle that
survives only in git history. Not a live secret. With INFRA-143's two
reCAPTCHA suppressions, the pre-push scanner now passes cleanly on this repo
(0 confirmed high, 3 suppressed) with no --no-verify needed.
2026-07-08 16:53:55 -04:00

16 lines
1.2 KiB
JSON

{
"suppressions": [
{
"id": "gitleaks-generic-api-key-7",
"justification": "False positive. assets/js/form.js:7 SITE_KEY is a Google reCAPTCHA v3 SITE key, which is public by design: it is shipped to every browser and passed to grecaptcha.execute() client-side (form.js:17,63). It is not a secret and must not be rotated. Pairs with the reCAPTCHA SECRET key held server-side. INFRA-143."
},
{
"id": "gitleaks-generic-api-key-5",
"justification": "False positive. Same public reCAPTCHA v3 SITE key as gitleaks-generic-api-key-7, flagged at assets/js/form.js:5 from an earlier commit (gitleaks scans git history). Public by design, not a secret. INFRA-143."
},
{
"id": "gitleaks-generic-api-key-2464",
"justification": "False positive. gitleaks flags a high-entropy string at wp-content/plugins/elementor-pro/assets/js/notes/vendors-...-e4587e.js:2464 (a minified radix-ui vendor bundle: the token is a bundler variable, not a credential). This legacy WordPress/Elementor bundle was removed from the repo and survives only in git history, which gitleaks scans. Not a live secret, nothing to rotate. INFRA-181."
}
]
}