An unsolicited scanner reported CRITICAL "LLM output written to a persistent memory store" findings against src/lib/notifications.ts:145, src/lib/sdk.ts:392 and src/lib/session-grouping.ts:24. All three are false positives: the cited lines are an in-memory notification dedupe Map, a URLSearchParams limit param, and a bucket push inside a pure grouping helper. The app persists nothing model-derived — sessions and messages live on the server and are held in memory by the stores. Two gates so that stays true and so the one class of report that WAS real for us (credentials in git history) gets caught before a push: - security-scan.yml: gitleaks on push/PR to main, full history fetch. - persisted-keys.test.ts: enumerates every SecureStore write by key. A new persistence sink fails the suite until someone adds the key with a note saying what it holds — which is the moment to notice if it's model output rather than user config. Verified it trips by adding a throwaway "cache the assistant reply" write. Co-authored-by: engineer <engineer@macbookpro.lan> Co-authored-by: Paperclip <noreply@paperclip.ing>
806 B
806 B