diff --git a/.github/workflows/dependency-review.yml b/.github/workflows/dependency-review.yml index 2c5d47c..13650e5 100644 --- a/.github/workflows/dependency-review.yml +++ b/.github/workflows/dependency-review.yml @@ -4,3 +4,5 @@ on: jobs: review: uses: Sea-Haven-Industries/.github/.github/workflows/callable-dependency-review.yaml@main + with: + allow-ghsas: GHSA-mh99-v99m-4gvg diff --git a/.security-review/suppressions.json b/.security-review/suppressions.json new file mode 100644 index 0000000..d5e6120 --- /dev/null +++ b/.security-review/suppressions.json @@ -0,0 +1,13 @@ +{ + "suppressions": [ + { + "advisory": "GHSA-mh99-v99m-4gvg", + "package": "brace-expansion", + "introducedBy": "aws-cdk-lib@2.262.1", + "scope": "Build-time CDK synthesis only; no untrusted pattern input or runtime deployment artifact.", + "reason": "The vulnerable copy is bundled by the latest aws-cdk-lib release and cannot be overridden or updated independently. Dependabot monitors the pinned CDK dependency.", + "reviewBy": "2026-08-10", + "tracking": "SH-133" + } + ] +}