security-review/sweep-targets.txt

27 lines
1.9 KiB
Text
Raw Normal View History

# sweep-targets.txt — one repo path per line for the nightly Path B sweep.
# Lines starting with '#' and blank lines are ignored. ~ is expanded.
# Override at runtime with the TARGETS env var (space-separated paths).
#
feat(scanner): auto-resolve + merge suppressions when --suppressions absent (#4) review.sh only applied suppressions when handed an explicit --suppressions FILE, so only the pre-push hook resolved them. Every other entry point (the Open SWE daily-report automation, nightly sweep, on-demand/CI, agent runs) called review.sh without it and therefore suppressed nothing, re-surfacing every already-adjudicated false positive as HIGH. When --suppressions is not passed, resolve by repo basename and MERGE both suppression locations (machine-level first, wins id collisions): - machine-level: ${SH_SECURITY_SUPPRESSIONS_DIR:-~/.config/sea-haven/security-review}/<basename>/suppressions.json - repo-local: <repo>/.security-review/suppressions.json An explicit --suppressions still overrides, so the hook and existing callers are unaffected. Degrades gracefully off-Mac (repo-local only); fail-safe on an unparseable file (suppresses nothing → blocks). SECURITY (/sh-security-review, 2026-07-13): fan-out + proof-or-kill confirmed one HIGH — the git-tracked repo-local suppressions.json lets anyone who can commit to a scanned repo suppress a real finding and PASS an automated run (verified by an actual exploit run; same posture nightly_sweep already had). ACCEPTED-RISK per Adam on the condition that the automated scanners only ever target trusted repos (no unreviewed untrusted contributions). Documented in the auto-resolve block, README trust-model note, and a hard warning in sweep-targets.txt. Four other candidates downgraded to low/pre-existing. Verified: machine-level and repo-local both auto-resolve and suppress; explicit --suppressions override still blocks; simulated off-Mac host keeps repo-local and correctly re-blocks machine-level-only FPs.
2026-07-13 14:33:27 -04:00
# ┌─ SECURITY — TRUSTED REPOS ONLY (accepted-risk condition, 2026-07-13) ─────────┐
# │ review.sh auto-loads each scanned repo's GIT-TRACKED │
# │ .security-review/suppressions.json. A contributor who can land a commit can │
# │ therefore suppress a real finding (ship the vuln + its own suppression) and │
# │ make the automated run PASS — /sh-security-review confirmed this as HIGH and │
# │ it was ACCEPTED only on the condition that this list (and any target list the │
# │ Open SWE daily-report automation uses) contains ONLY trusted repos. Do NOT │
# │ add a repo that merges untrusted contributions without human review. The same │
# │ rule applies to the Open SWE daily automation's target set — keep it in sync. │
# └───────────────────────────────────────────────────────────────────────────────┘
#
# NOTE: the testbed canary corpus is ALWAYS scanned by nightly_sweep.sh as the
# anti-complacency check; do NOT list it here (it is handled separately).
#
# TODO (Phase 5): add the first real hardened repo here once it is cloned on the
# VM (candidates: payments-dashboard / proposal-system / procurement-ingest).
#
# Deliberately EMPTY by default = canary-only nights. Do NOT scan ~/orchestrator:
# it holds ~/orchestrator/.env with live provider API keys, which the agentic
# detector could surface into sweep reports / Slack. Only add repos with no
# plaintext secrets (or scrub/exclude secret files first).
# ~/orchestrator