Author SHA1 Message Date
Jens ac977bcd4b Merge pull request 'hygiene: finalize GeoIntel public release' (#11) from chore/public-release-finalization-20260902 into main
GeoIntel release gates / Python and npm vulnerability policy (push) Successful in 26s
GeoIntel release gates / Compile, test, contracts and builds (push) Successful in 2m33s
GeoIntel release gates / Production AI image, SBOM and container scan (push) Successful in 14m10s
GeoIntel release gates / Deploy exact gated revision to Unraid (push) Failing after 21s
2026-09-03 02:01:19 +00:00
NuklearRabbit 50dc6692a0 security: upgrade expat in release image
GeoIntel release gates / Production AI image, SBOM and container scan (pull_request) Successful in 15m25s
Managed validation / Managed repository validation (pull_request) Successful in 2m0s
GeoIntel release gates / Python and npm vulnerability policy (pull_request) Successful in 23s
GeoIntel release gates / Compile, test, contracts and builds (pull_request) Successful in 2m42s
GeoIntel release gates / Deploy exact gated revision to Unraid (pull_request) Skipped
2026-09-03 01:25:54 +02:00
NuklearRabbit 4d37fa0b18 security: update vulnerable browserslist dependency
Managed validation / Managed repository validation (pull_request) Successful in 1m47s
GeoIntel release gates / Compile, test, contracts and builds (pull_request) Successful in 1m49s
GeoIntel release gates / Python and npm vulnerability policy (pull_request) Successful in 24s
GeoIntel release gates / Production AI image, SBOM and container scan (pull_request) Failing after 10m54s
GeoIntel release gates / Deploy exact gated revision to Unraid (pull_request) Skipped
2026-09-03 01:07:16 +02:00
NuklearRabbit 3969a35d7a hygiene: finalize GeoIntel public release
Managed validation / Managed repository validation (pull_request) Successful in 1m54s
GeoIntel release gates / Compile, test, contracts and builds (pull_request) Successful in 1m53s
GeoIntel release gates / Python and npm vulnerability policy (pull_request) Failing after 20s
GeoIntel release gates / Production AI image, SBOM and container scan (pull_request) Failing after 12m1s
GeoIntel release gates / Deploy exact gated revision to Unraid (pull_request) Skipped
2026-09-02 23:43:03 +02:00
9 changed files with 83 additions and 27 deletions
+2
View File
@@ -23,6 +23,8 @@ jobs:
# Gitea Actions does not consistently evaluate the GitHub-style `||`
# expression for pull-request runs without workflow inputs.
name: Managed repository validation
# Public fork code must never execute automatically on the private runner.
if: ${{ gitea.event_name != 'pull_request' || gitea.event.pull_request.head.repo.full_name == gitea.repository }}
runs-on: ubuntu-latest
timeout-minutes: 60
steps:
+4
View File
@@ -19,6 +19,8 @@ concurrency:
jobs:
quality:
name: Compile, test, contracts and builds
# Public fork code must never execute automatically on the private runner.
if: ${{ gitea.event_name != 'pull_request' || gitea.event.pull_request.head.repo.full_name == gitea.repository }}
runs-on: ubuntu-latest
timeout-minutes: 60
steps:
@@ -74,6 +76,7 @@ jobs:
dependency-audit:
name: Python and npm vulnerability policy
if: ${{ gitea.event_name != 'pull_request' || gitea.event.pull_request.head.repo.full_name == gitea.repository }}
runs-on: ubuntu-latest
timeout-minutes: 20
steps:
@@ -112,6 +115,7 @@ jobs:
container:
name: Production AI image, SBOM and container scan
if: ${{ gitea.event_name != 'pull_request' || gitea.event.pull_request.head.repo.full_name == gitea.repository }}
runs-on: ubuntu-latest
timeout-minutes: 120
steps:
+3
View File
@@ -257,6 +257,9 @@ originele campagnebeelden staan in
WebP-varianten worden door de applicatie gebruikt; de PNG-bronnen blijven
beschikbaar voor drukwerk en portfolio-opmaak.
Herkomst en hergebruik van deze bestanden zijn vastgelegd in
[Asset provenance and redistribution](docs/ASSET_PROVENANCE.md).
Actuele rasterassets:
| Asset | Gebruik |
+1 -1
View File
@@ -8,7 +8,7 @@ explicitly documented otherwise.
## Reporting vulnerabilities
Report suspected security issues privately to the repository owner. Do not put
Report suspected security issues privately to `security@itworx.tech`. Do not put
credentials, access tokens, private infrastructure, precise sensitive
locations, proprietary imagery or datasets, model artifacts, production
database contents, personal data or exploit-sensitive evidence in a public
+2
View File
@@ -24,6 +24,8 @@ RUN apt-get update && apt-get install -y --no-install-recommends \
gdal-bin \
libgl1 \
libglib2.0-0 \
libexpat1 \
libexpat1-dev \
libgdal-dev \
libgeos-dev \
libpq-dev \
+32
View File
@@ -0,0 +1,32 @@
# Asset provenance and redistribution
The visual files distributed with GeoIntel were created for this project and
are released by the repository owner with the source under Apache-2.0. They do
not include private operator data, proprietary model weights, unpublished
imagery, or a bundled third-party geospatial dataset.
## Project artwork
The original PNG masters in `frontend/design-assets/portfolio/` and their
optimized WebP derivatives in `frontend/public/portfolio/` are project artwork.
The WebP files are mechanical resizes of the corresponding masters; the
reproduction command is documented in `frontend/design-assets/README.md`.
## Product captures and generated documents
Files in `docs/assets/portfolio/` are captures or diagrams of the GeoIntel
public-demo interface using synthetic/public demonstration content. The case
study at `output/pdf/geointel-case-study.pdf` is generated from repository
sources by `scripts/create_portfolio_case_study.py`.
Any provider name, logo, map attribution, or dataset title visible inside a
capture remains the property of its respective owner and is included only to
identify the source or reproduce the application's attribution UI. This
repository does not relicense or redistribute the underlying provider data.
## Integrity
Release review verifies these paths through the repository's normal Git object
hashes and the public-release gate. Regenerated derivatives must come from a
tracked master or reproducible repository source; do not replace them with
unlicensed stock material, private screenshots, or local operator exports.
+13
View File
@@ -4,6 +4,19 @@ This public log records release-relevant repository work only. Machine-specific
paths, production database state, deployment addresses, model outputs and
generated evidence remain in controlled local storage.
## 2026-09-02 — public-release handoff
- Added an explicit monitored reporting address to `SECURITY.md`.
- Documented ownership, redistribution boundaries and regeneration of the
retained portfolio assets.
- Confirmed the existing Linux/CUDA/Ultralytics lock is platform-specific,
version-pinned and SHA-256 hashed.
- Prevented pull requests from external public forks from executing code on
the private validation runners; push and maintainer-dispatch gates remain.
- Re-ran repository hygiene and full-history secret scanning successfully.
- The complete backend, frontend, migration and container gate remains the
required exact-commit check before changing repository visibility.
## 2026-08-31 — public-release readiness
- Confirmed Apache-2.0 as the repository license.
+3 -3
View File
@@ -5,10 +5,10 @@
- [ ] Pass the complete backend, frontend, migration and container release gate.
- [ ] Verify the clean-root publication candidate and local all-ref recovery
bundle.
- [ ] Confirm redistribution/provenance for the retained portfolio screenshots.
- [ ] Configure a monitored private security-reporting address or Gitea security
- [x] Confirm redistribution/provenance for the retained portfolio screenshots.
- [x] Configure a monitored private security-reporting address or Gitea security
channel in `SECURITY.md`.
- [ ] Finish a fully hashed, platform-specific lock for optional CUDA/Ultralytics
- [x] Finish a fully hashed, platform-specific lock for optional CUDA/Ultralytics
packages; base container images are already digest-pinned.
## Product work
+23 -23
View File
@@ -1829,9 +1829,9 @@
}
},
"node_modules/baseline-browser-mapping": {
"version": "2.10.36",
"resolved": "https://registry.npmjs.org/baseline-browser-mapping/-/baseline-browser-mapping-2.10.36.tgz",
"integrity": "sha512-lVq/Df7LXlO79MVaaUHztSwWiG9oXoWHlgvNS51v8Dpd4+G4/VIy6qYePTw31nAVls33nUtnfezYeLkYAak9dg==",
"version": "2.11.20",
"resolved": "https://registry.npmjs.org/baseline-browser-mapping/-/baseline-browser-mapping-2.11.20.tgz",
"integrity": "sha512-H0ulySigv6icDJ1F7SjtdCD6PrhTpdYCmP0CactWy1+ekh0AFd0o1Wn5T8b+hnTmdBx19u9yhL6wvCylXMY7zw==",
"dev": true,
"license": "Apache-2.0",
"bin": {
@@ -1842,9 +1842,9 @@
}
},
"node_modules/browserslist": {
"version": "4.28.2",
"resolved": "https://registry.npmjs.org/browserslist/-/browserslist-4.28.2.tgz",
"integrity": "sha512-48xSriZYYg+8qXna9kwqjIVzuQxi+KYWp2+5nCYnYKPTr0LvD89Jqk2Or5ogxz0NUMfIjhh2lIUX/LyX9B4oIg==",
"version": "4.28.8",
"resolved": "https://registry.npmjs.org/browserslist/-/browserslist-4.28.8.tgz",
"integrity": "sha512-V2NpofLblG64mfOtSgDhOJESZEGogzDMBv/q+W6oc4LXWP/q75eOXoOaaOu1EOadB9U4Bwx/e0yzbvwKH8zalA==",
"dev": true,
"funding": [
{
@@ -1862,11 +1862,11 @@
],
"license": "MIT",
"dependencies": {
"baseline-browser-mapping": "^2.10.12",
"caniuse-lite": "^1.0.30001782",
"electron-to-chromium": "^1.5.328",
"node-releases": "^2.0.36",
"update-browserslist-db": "^1.2.3"
"baseline-browser-mapping": "^2.11.12",
"caniuse-lite": "^1.0.30001809",
"electron-to-chromium": "^1.5.402",
"node-releases": "^2.0.53",
"update-browserslist-db": "^1.3.0"
},
"bin": {
"browserslist": "cli.js"
@@ -1886,9 +1886,9 @@
}
},
"node_modules/caniuse-lite": {
"version": "1.0.30001799",
"resolved": "https://registry.npmjs.org/caniuse-lite/-/caniuse-lite-1.0.30001799.tgz",
"integrity": "sha512-hG1bReV+OUU+MOqK4t/ZWI0tZOyz3rqS9XuhOUz1cIcbwBKjOyJEJuw9ER5JuNyqxNk8u/JUVbGibBOL1yrjFw==",
"version": "1.0.30001810",
"resolved": "https://registry.npmjs.org/caniuse-lite/-/caniuse-lite-1.0.30001810.tgz",
"integrity": "sha512-TITQPUkaz+aVk5GL6NhOdwk1aEaNTSDPsGFWrTuhKGtjTF70jL/Oht2W4c6rXUe5fu7Ie19VIahAXHIIiWWNeg==",
"dev": true,
"funding": [
{
@@ -2036,9 +2036,9 @@
"license": "ISC"
},
"node_modules/electron-to-chromium": {
"version": "1.5.371",
"resolved": "https://registry.npmjs.org/electron-to-chromium/-/electron-to-chromium-1.5.371.tgz",
"integrity": "sha512-e9htk9mAYL6AzmkEhSvVVw7IWGSBJ/Bqdn2eRyRLrj1g6sncN4WbFt5qnILYoCktktr45pyjIrOiRvBThQ808w==",
"version": "1.5.420",
"resolved": "https://registry.npmjs.org/electron-to-chromium/-/electron-to-chromium-1.5.420.tgz",
"integrity": "sha512-2yD6XreGusOfNV+dUcvipJEXc3n/n7fgr7996aszTG+YY5E4mqM4tOq/3uhP129cazL9YHbVWSpc79ePotWtPA==",
"dev": true,
"license": "ISC"
},
@@ -2549,9 +2549,9 @@
}
},
"node_modules/node-releases": {
"version": "2.0.47",
"resolved": "https://registry.npmjs.org/node-releases/-/node-releases-2.0.47.tgz",
"integrity": "sha512-Uzmd6LXpouKo8EUK68IjH4+E01w/hXyV3R3g/geCJo+rXLNfh1xucB+LOzYEOQPSiUK3h/xZf0cQGcSsmyL2Og==",
"version": "2.0.54",
"resolved": "https://registry.npmjs.org/node-releases/-/node-releases-2.0.54.tgz",
"integrity": "sha512-YHs7BmmcsdAI5Ozuf8JZo6PT0mv2GIWC9vMfvUC3dp65M8hn7Ux8CPL+2oBI7juNuj9d0ndhTcznq2ODBps9cQ==",
"dev": true,
"license": "MIT",
"engines": {
@@ -3092,9 +3092,9 @@
}
},
"node_modules/update-browserslist-db": {
"version": "1.2.3",
"resolved": "https://registry.npmjs.org/update-browserslist-db/-/update-browserslist-db-1.2.3.tgz",
"integrity": "sha512-Js0m9cx+qOgDxo0eMiFGEueWztz+d4+M3rGlmKPT+T4IS/jP4ylw3Nwpu6cpTTP8R1MAC1kF4VbdLt3ARf209w==",
"version": "1.3.2",
"resolved": "https://registry.npmjs.org/update-browserslist-db/-/update-browserslist-db-1.3.2.tgz",
"integrity": "sha512-UQ+MSxlhRm1bzjhU+DcuXfjFO1FzNtqhK5+9Yvlp90ItDLk5vT932A0rFu619nf7RVS+Y/VeaUW1jaRDqZ8VJw==",
"dev": true,
"funding": [
{