seahaven-site/package.json
Adam Moussa 68ac0be0d4
INFRA-143: suppress reCAPTCHA site-key gitleaks FP + clear js-yaml DoS advisory (#27)
* chore(security): suppress gitleaks FP on public reCAPTCHA site key (INFRA-143)

The SITE_KEY in assets/js/form.js is a Google reCAPTCHA v3 site key, public
by design (shipped to the browser, passed to grecaptcha.execute). It is not a
secret and is not rotated. Add a scoped repo-local gitleaks suppression with
justification for the current (line 7) and historical (line 5) hits so the
pre-push scanner stops blocking on it.

* fix(deps): pin gray-matter js-yaml to 3.15.0 to clear DoS advisory (INFRA-143)

gray-matter (transitive via @11ty/eleventy) pulled js-yaml 3.14.2, flagged by
GHSA-h67p-54hq-rp68 (quadratic-complexity DoS in merge-key handling, moderate).
Add a scoped nested npm override pinning gray-matter's js-yaml to ^3.15.0, the
fixed 3.x release, leaving Eleventy's direct js-yaml 4.x untouched. npm audit
now reports 0 vulnerabilities and the Eleventy build passes.
2026-07-08 16:21:21 -04:00

20 lines
457 B
JSON

{
"name": "seahaven-site",
"version": "1.0.0",
"private": true,
"description": "Sea Haven Industries marketing site — static HTML built with Eleventy, served from S3 + CloudFront.",
"scripts": {
"build": "eleventy",
"serve": "eleventy --serve",
"clean": "rm -rf _site"
},
"license": "UNLICENSED",
"dependencies": {
"@11ty/eleventy": "3.1.6"
},
"overrides": {
"gray-matter": {
"js-yaml": "^3.15.0"
}
}
}