{ "suppressions": [ { "id": "npmaudit-vitest", "justification": "Dev/test-only dependency (vitest 3.0.2). vitest never runs in the deployed server/Lambda runtime, so the advisory (<=3.2.5) is not reachable in production. Pin carried over from the Phase 0b scaffold; Dependabot will bump it. Not introduced by this PR." }, { "id": "npmaudit-@vitest/coverage-v8", "justification": "Dev/test-only dependency (coverage reporter). Runs only under `vitest run --coverage` in CI/local, never in production. Advisory (<=3.2.5) not reachable in the deployed runtime. Dependabot will bump alongside vitest." }, { "id": "npmaudit-vite", "justification": "Transitive dev-only dependency of vitest. Not present in the server/Lambda runtime dependency tree (no Vite bundling in production). Resolved when vitest is bumped; tracked for Dependabot." }, { "id": "gitleaks-generic-api-key-480", "justification": "Confirmed false positive. docs/agentforce-plan.md:480 is a Markdown header ('### 1h. Test suite ...'), not a credential. gitleaks' generic-api-key rule matches high-entropy-looking identifier strings in the planning prose. Verified line-by-line: no live key/token/PEM/AKIA/client_secret in the doc. The doc is now on main (merged via PR #1); suppressed repo-wide so it stops blocking pushes." }, { "id": "gitleaks-generic-api-key-616", "justification": "Confirmed false positive. docs/agentforce-plan.md:616 is design prose ('Connections: sh-mcp-finance tier ... External Credential ec-seahaven-finance ...') — Salesforce/Cognito resource names, not secret values. Same generic-api-key FP class as line 480. No live credential in the doc. Suppressed repo-wide (doc is on main via PR #1)." }, { "id": "npmaudit-brace-expansion", "justification": "Bundled transitive of aws-cdk-lib (node_modules/aws-cdk-lib/node_modules/brace-expansion). aws-cdk-lib 2.261.0 is the LATEST release and still ships the vulnerable range; npm cannot override bundled deps, so no fix is available until upstream rebundles (GHSA-3jxr-9vmj-r5cp). Exposure is synth-time only: aws-cdk-lib runs during cdk synth in CI on trusted repo input, never in the deployed server/Lambda runtime, and the ReDoS requires attacker-controlled brace patterns. Revisit/remove on the next aws-cdk-lib bump that clears npm audit." } ] }