From 73b525a685fc9dba5fe1a780908865510b013955 Mon Sep 17 00:00:00 2001 From: Alexandre Brandizzi Date: Mon, 27 Jul 2026 19:29:37 -0300 Subject: [PATCH] ci: document CDK advisory exception --- .github/workflows/dependency-review.yml | 2 ++ .security-review/suppressions.json | 13 +++++++++++++ 2 files changed, 15 insertions(+) create mode 100644 .security-review/suppressions.json diff --git a/.github/workflows/dependency-review.yml b/.github/workflows/dependency-review.yml index 2c5d47c..13650e5 100644 --- a/.github/workflows/dependency-review.yml +++ b/.github/workflows/dependency-review.yml @@ -4,3 +4,5 @@ on: jobs: review: uses: Sea-Haven-Industries/.github/.github/workflows/callable-dependency-review.yaml@main + with: + allow-ghsas: GHSA-mh99-v99m-4gvg diff --git a/.security-review/suppressions.json b/.security-review/suppressions.json new file mode 100644 index 0000000..d5e6120 --- /dev/null +++ b/.security-review/suppressions.json @@ -0,0 +1,13 @@ +{ + "suppressions": [ + { + "advisory": "GHSA-mh99-v99m-4gvg", + "package": "brace-expansion", + "introducedBy": "aws-cdk-lib@2.262.1", + "scope": "Build-time CDK synthesis only; no untrusted pattern input or runtime deployment artifact.", + "reason": "The vulnerable copy is bundled by the latest aws-cdk-lib release and cannot be overridden or updated independently. Dependabot monitors the pinned CDK dependency.", + "reviewBy": "2026-08-10", + "tracking": "SH-133" + } + ] +}