# Sobelow Skip Configuration
# This file documents security findings that have been reviewed and mitigated.
# See docs/security-analysis.md for detailed explanations.

# Config.HTTPS is configured in config/runtime.exs, not config/prod.exs
# Sobelow only checks prod.exs, resulting in false positive
Config.HTTPS:0:config/prod.exs

# Vendored SnmpKit library - binary_to_term used for trusted MIB compilation
# MIB files are only loaded from application-controlled directories
Misc.BinToTerm:203:lib/snmpkit/snmp_lib/mib/compiler.ex

# MIB Controller - Directory traversal mitigated with validation
# vendor_dir is constructed from validated vendor name (alphanumeric + hyphen/underscore only)
# No path traversal characters (., /, \, :) allowed
Traversal.FileModule:141:lib/towerops_web/controllers/api/v1/mib_controller.ex

# MIB Controller - File.cp with validated paths
# upload.path is Plug.Upload-controlled (safe)
# target_path uses Path.basename to strip directory components
# Filename validation rejects path traversal sequences
Traversal.FileModule:270:lib/towerops_web/controllers/api/v1/mib_controller.ex

# SQL Query - False positive, uses parameterized queries
# Table names are constants, user input uses $1, $2 binding
Traversal.FileModule:166:lib/towerops_web/controllers/api/v1/mib_controller.ex
