2026-06-29 11:41:41 -04:00
|
|
|
# sweep-targets.txt — one repo path per line for the nightly Path B sweep.
|
|
|
|
|
# Lines starting with '#' and blank lines are ignored. ~ is expanded.
|
|
|
|
|
# Override at runtime with the TARGETS env var (space-separated paths).
|
|
|
|
|
#
|
feat(scanner): auto-resolve + merge suppressions when --suppressions absent (#4)
review.sh only applied suppressions when handed an explicit --suppressions
FILE, so only the pre-push hook resolved them. Every other entry point (the
Open SWE daily-report automation, nightly sweep, on-demand/CI, agent runs)
called review.sh without it and therefore suppressed nothing, re-surfacing
every already-adjudicated false positive as HIGH.
When --suppressions is not passed, resolve by repo basename and MERGE both
suppression locations (machine-level first, wins id collisions):
- machine-level: ${SH_SECURITY_SUPPRESSIONS_DIR:-~/.config/sea-haven/security-review}/<basename>/suppressions.json
- repo-local: <repo>/.security-review/suppressions.json
An explicit --suppressions still overrides, so the hook and existing callers
are unaffected. Degrades gracefully off-Mac (repo-local only); fail-safe on an
unparseable file (suppresses nothing → blocks).
SECURITY (/sh-security-review, 2026-07-13): fan-out + proof-or-kill confirmed
one HIGH — the git-tracked repo-local suppressions.json lets anyone who can
commit to a scanned repo suppress a real finding and PASS an automated run
(verified by an actual exploit run; same posture nightly_sweep already had).
ACCEPTED-RISK per Adam on the condition that the automated scanners only ever
target trusted repos (no unreviewed untrusted contributions). Documented in the
auto-resolve block, README trust-model note, and a hard warning in
sweep-targets.txt. Four other candidates downgraded to low/pre-existing.
Verified: machine-level and repo-local both auto-resolve and suppress; explicit
--suppressions override still blocks; simulated off-Mac host keeps repo-local
and correctly re-blocks machine-level-only FPs.
2026-07-13 14:33:27 -04:00
|
|
|
# ┌─ SECURITY — TRUSTED REPOS ONLY (accepted-risk condition, 2026-07-13) ─────────┐
|
|
|
|
|
# │ review.sh auto-loads each scanned repo's GIT-TRACKED │
|
|
|
|
|
# │ .security-review/suppressions.json. A contributor who can land a commit can │
|
|
|
|
|
# │ therefore suppress a real finding (ship the vuln + its own suppression) and │
|
|
|
|
|
# │ make the automated run PASS — /sh-security-review confirmed this as HIGH and │
|
|
|
|
|
# │ it was ACCEPTED only on the condition that this list (and any target list the │
|
|
|
|
|
# │ Open SWE daily-report automation uses) contains ONLY trusted repos. Do NOT │
|
|
|
|
|
# │ add a repo that merges untrusted contributions without human review. The same │
|
|
|
|
|
# │ rule applies to the Open SWE daily automation's target set — keep it in sync. │
|
|
|
|
|
# └───────────────────────────────────────────────────────────────────────────────┘
|
|
|
|
|
#
|
2026-06-29 11:41:41 -04:00
|
|
|
# NOTE: the testbed canary corpus is ALWAYS scanned by nightly_sweep.sh as the
|
|
|
|
|
# anti-complacency check; do NOT list it here (it is handled separately).
|
|
|
|
|
#
|
|
|
|
|
# TODO (Phase 5): add the first real hardened repo here once it is cloned on the
|
|
|
|
|
# VM (candidates: payments-dashboard / proposal-system / procurement-ingest).
|
|
|
|
|
#
|
2026-07-14 19:24:01 -04:00
|
|
|
# Deliberately EMPTY by default = canary-only nights. Only add repos with no
|
2026-06-29 11:41:41 -04:00
|
|
|
# plaintext secrets (or scrub/exclude secret files first).
|