sh-mcp/.security-review/suppressions.json
Adam Moussa 47cd0ca230
chore(deps): batch Dependabot updates (#31, #32) (#33)
* chore(deps-dev): bump the minor-and-patch group in /infra with 2 updates

Bumps the minor-and-patch group in /infra with 2 updates: [aws-cdk](https://github.com/aws/aws-cdk-cli/tree/HEAD/packages/aws-cdk) and [constructs](https://github.com/aws/constructs).


Updates `aws-cdk` from 2.1130.0 to 2.1132.0
- [Release notes](https://github.com/aws/aws-cdk-cli/releases)
- [Commits](https://github.com/aws/aws-cdk-cli/commits/aws-cdk@v2.1132.0/packages/aws-cdk)

Updates `constructs` from 10.6.0 to 10.7.1
- [Release notes](https://github.com/aws/constructs/releases)
- [Commits](https://github.com/aws/constructs/compare/v10.6.0...v10.7.1)

---
updated-dependencies:
- dependency-name: aws-cdk
  dependency-version: 2.1132.0
  dependency-type: direct:development
  update-type: version-update:semver-minor
  dependency-group: minor-and-patch
- dependency-name: constructs
  dependency-version: 10.7.1
  dependency-type: direct:development
  update-type: version-update:semver-minor
  dependency-group: minor-and-patch
...

Signed-off-by: dependabot[bot] <support@github.com>

* chore(deps): bump the minor-and-patch group with 10 updates

Bumps the minor-and-patch group with 10 updates:

| Package | From | To |
| --- | --- | --- |
| [@typescript-eslint/eslint-plugin](https://github.com/typescript-eslint/typescript-eslint/tree/HEAD/packages/eslint-plugin) | `8.64.0` | `8.65.0` |
| [@typescript-eslint/parser](https://github.com/typescript-eslint/typescript-eslint/tree/HEAD/packages/parser) | `8.64.0` | `8.65.0` |
| [aws-cdk](https://github.com/aws/aws-cdk-cli/tree/HEAD/packages/aws-cdk) | `2.1130.0` | `2.1132.0` |
| [constructs](https://github.com/aws/constructs) | `10.6.0` | `10.7.1` |
| [prettier](https://github.com/prettier/prettier) | `3.9.5` | `3.9.6` |
| [express-rate-limit](https://github.com/express-rate-limit/express-rate-limit) | `8.5.2` | `8.6.0` |
| [@aws-sdk/client-cognito-identity-provider](https://github.com/aws/aws-sdk-js-v3/tree/HEAD/clients/client-cognito-identity-provider) | `3.1086.0` | `3.1091.0` |
| [@aws-sdk/client-dynamodb](https://github.com/aws/aws-sdk-js-v3/tree/HEAD/clients/client-dynamodb) | `3.1086.0` | `3.1091.0` |
| [@aws-sdk/client-secrets-manager](https://github.com/aws/aws-sdk-js-v3/tree/HEAD/clients/client-secrets-manager) | `3.1086.0` | `3.1091.0` |
| [@aws-sdk/lib-dynamodb](https://github.com/aws/aws-sdk-js-v3/tree/HEAD/lib/lib-dynamodb) | `3.1086.0` | `3.1091.0` |


Updates `@typescript-eslint/eslint-plugin` from 8.64.0 to 8.65.0
- [Release notes](https://github.com/typescript-eslint/typescript-eslint/releases)
- [Changelog](https://github.com/typescript-eslint/typescript-eslint/blob/main/packages/eslint-plugin/CHANGELOG.md)
- [Commits](https://github.com/typescript-eslint/typescript-eslint/commits/v8.65.0/packages/eslint-plugin)

Updates `@typescript-eslint/parser` from 8.64.0 to 8.65.0
- [Release notes](https://github.com/typescript-eslint/typescript-eslint/releases)
- [Changelog](https://github.com/typescript-eslint/typescript-eslint/blob/main/packages/parser/CHANGELOG.md)
- [Commits](https://github.com/typescript-eslint/typescript-eslint/commits/v8.65.0/packages/parser)

Updates `aws-cdk` from 2.1130.0 to 2.1132.0
- [Release notes](https://github.com/aws/aws-cdk-cli/releases)
- [Commits](https://github.com/aws/aws-cdk-cli/commits/aws-cdk@v2.1132.0/packages/aws-cdk)

Updates `constructs` from 10.6.0 to 10.7.1
- [Release notes](https://github.com/aws/constructs/releases)
- [Commits](https://github.com/aws/constructs/compare/v10.6.0...v10.7.1)

Updates `prettier` from 3.9.5 to 3.9.6
- [Release notes](https://github.com/prettier/prettier/releases)
- [Changelog](https://github.com/prettier/prettier/blob/main/CHANGELOG.md)
- [Commits](https://github.com/prettier/prettier/compare/3.9.5...3.9.6)

Updates `express-rate-limit` from 8.5.2 to 8.6.0
- [Release notes](https://github.com/express-rate-limit/express-rate-limit/releases)
- [Commits](https://github.com/express-rate-limit/express-rate-limit/compare/v8.5.2...v8.6.0)

Updates `@aws-sdk/client-cognito-identity-provider` from 3.1086.0 to 3.1091.0
- [Release notes](https://github.com/aws/aws-sdk-js-v3/releases)
- [Changelog](https://github.com/aws/aws-sdk-js-v3/blob/main/clients/client-cognito-identity-provider/CHANGELOG.md)
- [Commits](https://github.com/aws/aws-sdk-js-v3/commits/v3.1091.0/clients/client-cognito-identity-provider)

Updates `@aws-sdk/client-dynamodb` from 3.1086.0 to 3.1091.0
- [Release notes](https://github.com/aws/aws-sdk-js-v3/releases)
- [Changelog](https://github.com/aws/aws-sdk-js-v3/blob/main/clients/client-dynamodb/CHANGELOG.md)
- [Commits](https://github.com/aws/aws-sdk-js-v3/commits/v3.1091.0/clients/client-dynamodb)

Updates `@aws-sdk/client-secrets-manager` from 3.1086.0 to 3.1091.0
- [Release notes](https://github.com/aws/aws-sdk-js-v3/releases)
- [Changelog](https://github.com/aws/aws-sdk-js-v3/blob/main/clients/client-secrets-manager/CHANGELOG.md)
- [Commits](https://github.com/aws/aws-sdk-js-v3/commits/v3.1091.0/clients/client-secrets-manager)

Updates `@aws-sdk/lib-dynamodb` from 3.1086.0 to 3.1091.0
- [Release notes](https://github.com/aws/aws-sdk-js-v3/releases)
- [Changelog](https://github.com/aws/aws-sdk-js-v3/blob/main/lib/lib-dynamodb/CHANGELOG.md)
- [Commits](https://github.com/aws/aws-sdk-js-v3/commits/v3.1091.0/lib/lib-dynamodb)

---
updated-dependencies:
- dependency-name: "@typescript-eslint/eslint-plugin"
  dependency-version: 8.65.0
  dependency-type: direct:development
  update-type: version-update:semver-minor
  dependency-group: minor-and-patch
- dependency-name: "@typescript-eslint/parser"
  dependency-version: 8.65.0
  dependency-type: direct:development
  update-type: version-update:semver-minor
  dependency-group: minor-and-patch
- dependency-name: aws-cdk
  dependency-version: 2.1132.0
  dependency-type: direct:development
  update-type: version-update:semver-minor
  dependency-group: minor-and-patch
- dependency-name: constructs
  dependency-version: 10.7.1
  dependency-type: direct:development
  update-type: version-update:semver-minor
  dependency-group: minor-and-patch
- dependency-name: prettier
  dependency-version: 3.9.6
  dependency-type: direct:development
  update-type: version-update:semver-patch
  dependency-group: minor-and-patch
- dependency-name: express-rate-limit
  dependency-version: 8.6.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: minor-and-patch
- dependency-name: "@aws-sdk/client-cognito-identity-provider"
  dependency-version: 3.1091.0
  dependency-type: direct:development
  update-type: version-update:semver-minor
  dependency-group: minor-and-patch
- dependency-name: "@aws-sdk/client-dynamodb"
  dependency-version: 3.1091.0
  dependency-type: direct:development
  update-type: version-update:semver-minor
  dependency-group: minor-and-patch
- dependency-name: "@aws-sdk/client-secrets-manager"
  dependency-version: 3.1091.0
  dependency-type: direct:development
  update-type: version-update:semver-minor
  dependency-group: minor-and-patch
- dependency-name: "@aws-sdk/lib-dynamodb"
  dependency-version: 3.1091.0
  dependency-type: direct:development
  update-type: version-update:semver-minor
  dependency-group: minor-and-patch
...

Signed-off-by: dependabot[bot] <support@github.com>

* chore(security): suppress npmaudit-brace-expansion (bundled in latest aws-cdk-lib, synth-time only)

---------

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-07-21 15:49:13 -04:00

28 lines
2.4 KiB
JSON

{
"suppressions": [
{
"id": "npmaudit-vitest",
"justification": "Dev/test-only dependency (vitest 3.0.2). vitest never runs in the deployed server/Lambda runtime, so the advisory (<=3.2.5) is not reachable in production. Pin carried over from the Phase 0b scaffold; Dependabot will bump it. Not introduced by this PR."
},
{
"id": "npmaudit-@vitest/coverage-v8",
"justification": "Dev/test-only dependency (coverage reporter). Runs only under `vitest run --coverage` in CI/local, never in production. Advisory (<=3.2.5) not reachable in the deployed runtime. Dependabot will bump alongside vitest."
},
{
"id": "npmaudit-vite",
"justification": "Transitive dev-only dependency of vitest. Not present in the server/Lambda runtime dependency tree (no Vite bundling in production). Resolved when vitest is bumped; tracked for Dependabot."
},
{
"id": "gitleaks-generic-api-key-480",
"justification": "Confirmed false positive. docs/agentforce-plan.md:480 is a Markdown header ('### 1h. Test suite ...'), not a credential. gitleaks' generic-api-key rule matches high-entropy-looking identifier strings in the planning prose. Verified line-by-line: no live key/token/PEM/AKIA/client_secret in the doc. The doc is now on main (merged via PR #1); suppressed repo-wide so it stops blocking pushes."
},
{
"id": "gitleaks-generic-api-key-616",
"justification": "Confirmed false positive. docs/agentforce-plan.md:616 is design prose ('Connections: sh-mcp-finance tier ... External Credential ec-seahaven-finance ...') — Salesforce/Cognito resource names, not secret values. Same generic-api-key FP class as line 480. No live credential in the doc. Suppressed repo-wide (doc is on main via PR #1)."
},
{
"id": "npmaudit-brace-expansion",
"justification": "Bundled transitive of aws-cdk-lib (node_modules/aws-cdk-lib/node_modules/brace-expansion). aws-cdk-lib 2.261.0 is the LATEST release and still ships the vulnerable range; npm cannot override bundled deps, so no fix is available until upstream rebundles (GHSA-3jxr-9vmj-r5cp). Exposure is synth-time only: aws-cdk-lib runs during cdk synth in CI on trusted repo input, never in the deployed server/Lambda runtime, and the ReDoS requires attacker-controlled brace patterns. Revisit/remove on the next aws-cdk-lib bump that clears npm audit."
}
]
}