diff --git a/README.md b/README.md index 803df8e..fa9d888 100644 --- a/README.md +++ b/README.md @@ -55,6 +55,33 @@ After cloning, run `setup.sh` once. It will: - Send a test Telegram message confirming the VM is active - Create a `logs/` folder — logs are kept for 60 days then auto-deleted +## Whitelisting Known-Safe Findings + +If a script flags something you know is safe, add it to `whitelist.conf` on that VM to suppress it in future scans. This file is VM-specific and never committed to git. + +Add a package name: +```bash +echo "ua-parser-js" >> ~/security-tools/whitelist.conf +``` + +Add a file path: +```bash +echo "/tmp/my-known-script.sh" >> ~/security-tools/whitelist.conf +``` + +View or edit the whitelist: +```bash +nano ~/security-tools/whitelist.conf +``` + +## Checking Script Versions + +To see which version of a script is running on a VM: +```bash +head -2 ~/security-tools/npm-security-check.sh +head -2 ~/security-tools/check-nextjs-rce.sh +``` + ## Updating an Existing VM When changes are pushed to this repo, update any VM by running: