Initial public release
GeoIntel release gates / Compile, test, contracts and builds (push) Successful in 1m49s
GeoIntel release gates / Python and npm vulnerability policy (push) Successful in 21s
GeoIntel release gates / Production AI image, SBOM and container scan (push) Successful in 5m39s
GeoIntel release gates / Deploy exact gated revision to Unraid (push) Failing after 58m43s

This commit is contained in:
Jens
2026-08-31 21:56:53 +02:00
commit faeb58ef6d
1386 changed files with 263203 additions and 0 deletions
@@ -0,0 +1,26 @@
# Security and Secret Handling
## Secrets
Never commit API keys, tokens, model credentials, STAC credentials, database passwords, or private URLs.
## Environment Variables
All secrets must be loaded from `.env` or deployment environment.
## File Upload Safety
- limit accepted extensions;
- validate MIME/type where possible;
- store uploads outside source directories;
- generate server-side filenames;
- never execute uploaded files;
- reject path traversal.
## External Connectors
- log endpoint names but not credentials;
- timeout external requests;
- cache responses where appropriate;
- show connector status in UI.
## AI/Model Safety
- model files must be treated as artifacts;
- do not auto-download arbitrary executable code;
- keep model registry metadata separate from weights.