Skip to content

[功能建议] 支持误报抑制规则文件 #58

@nnn228085-star

Description

@nnn228085-star

问题描述
目前无法抑制已知安全的 finding(如测试夹具中的 dummy key、内部监控 webhook)。用户需要类似 .eslintrc.agentguard-suppress.yaml 文件来标注已知例外。

期望格式

rules:
  - id: PRIVATE_KEY_PATTERN
    paths:
      - "**/test-fixtures/**"
    reason: "测试用 dummy key"
  - id: WEBHOOK_EXFIL
    domains:
      - "discord.com/api/webhooks/our-internal-monitor/**"
    reason: "公司内部监控 webhook"

Metadata

Metadata

Assignees

No one assigned

    Labels

    enhancementNew feature or request

    Type

    No type
    No fields configured for issues without a type.

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions