Commit Graph
3 Commits
Author SHA1 Message Date
Lucas BergerandClaude Opus 4.8 7354f3ec4f fix(12): unblock CI security + harness jobs
CI / changes (pull_request) Successful in 3s
CI / fast-checks (pull_request) Successful in 1m56s
CI / api (pull_request) Successful in 1m44s
CI / harness (pull_request) Successful in 6m28s
CI / security (pull_request) Successful in 1m11s
CI / gate (pull_request) Successful in 0s
security/gitleaks: allowlist apps/api/tests/routes/setup.test.ts — synthetic
  VAPID test pair (verified absent from .env), same class as existing fixture
  allowlist entries.
security/audit: waive GHSA-88fw-hqm2-52qc (hono CORS) — not exploitable, the
  app uses no hono cors() middleware; newly-published vs pinned hono 4.12.23.
harness/e2e: seed app_config.setup_complete='true' + a dev-admin credential in
  global-setup so the Phase-12 setup gate no longer redirects every spec to
  /setup (was causing all 95 e2e failures) and no onboarding banner renders.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
2026-06-16 18:24:10 -04:00
Lucas Berger fba22b445b chore(16-04): allowlist crypto.test.ts synthetic AES test key in gitleaks config
- Add 4th [[allowlists]] block for apps/api/tests/broker/crypto.test.ts
- Human-verified: TEST_KEY in Vitest beforeAll is a synthetic AES-256-GCM fixture, not a real credential
- Original 3 allowlists (VAPID fixture, .env.example, .env.spike) intact
2026-06-13 08:14:26 -04:00
Lucas Berger 2f1592cc45 chore(16-04): add gitleaks config with fixture + env allowlists
- Add .gitleaks.toml inheriting default ruleset via [extend] useDefault = true
- Allowlist apps/api/tests/fixtures/vapid.ts (test-only VAPID keypair)
- Allowlist .env.example (intentional placeholder template)
- Allowlist apps/api/.env.spike (dev/spike values)
2026-06-13 05:27:54 -04:00