Skip to content

[功能建议] 支持误报抑制规则文件 #58

@nnn228085-star

Description

@nnn228085-star

问题描述
目前无法抑制已知安全的 finding(如测试夹具中的 dummy key、内部监控 webhook)。用户需要类似 .eslintrc.agentguard-suppress.yaml 文件来标注已知例外。

期望格式

rules:
  - id: PRIVATE_KEY_PATTERN
    paths:
      - "**/test-fixtures/**"
    reason: "测试用 dummy key"
  - id: WEBHOOK_EXFIL
    domains:
      - "discord.com/api/webhooks/our-internal-monitor/**"
    reason: "公司内部监控 webhook"

Metadata

Metadata

Assignees

No one assigned

    Labels

    enhancementNew feature or request

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions