diff --git a/.gitea/workflows/managed-validation.yml b/.gitea/workflows/managed-validation.yml index dcb89481..6f22b94c 100644 --- a/.gitea/workflows/managed-validation.yml +++ b/.gitea/workflows/managed-validation.yml @@ -23,6 +23,8 @@ jobs: # Gitea Actions does not consistently evaluate the GitHub-style `||` # expression for pull-request runs without workflow inputs. name: Managed repository validation + # Public fork code must never execute automatically on the private runner. + if: ${{ gitea.event_name != 'pull_request' || gitea.event.pull_request.head.repo.full_name == gitea.repository }} runs-on: ubuntu-latest timeout-minutes: 60 steps: diff --git a/.gitea/workflows/release-gates.yml b/.gitea/workflows/release-gates.yml index 16f5dd8a..32c60748 100644 --- a/.gitea/workflows/release-gates.yml +++ b/.gitea/workflows/release-gates.yml @@ -19,6 +19,8 @@ concurrency: jobs: quality: name: Compile, test, contracts and builds + # Public fork code must never execute automatically on the private runner. + if: ${{ gitea.event_name != 'pull_request' || gitea.event.pull_request.head.repo.full_name == gitea.repository }} runs-on: ubuntu-latest timeout-minutes: 60 steps: @@ -74,6 +76,7 @@ jobs: dependency-audit: name: Python and npm vulnerability policy + if: ${{ gitea.event_name != 'pull_request' || gitea.event.pull_request.head.repo.full_name == gitea.repository }} runs-on: ubuntu-latest timeout-minutes: 20 steps: @@ -112,6 +115,7 @@ jobs: container: name: Production AI image, SBOM and container scan + if: ${{ gitea.event_name != 'pull_request' || gitea.event.pull_request.head.repo.full_name == gitea.repository }} runs-on: ubuntu-latest timeout-minutes: 120 steps: diff --git a/README.md b/README.md index a4de9f90..36f58660 100644 --- a/README.md +++ b/README.md @@ -257,6 +257,9 @@ originele campagnebeelden staan in WebP-varianten worden door de applicatie gebruikt; de PNG-bronnen blijven beschikbaar voor drukwerk en portfolio-opmaak. +Herkomst en hergebruik van deze bestanden zijn vastgelegd in +[Asset provenance and redistribution](docs/ASSET_PROVENANCE.md). + Actuele rasterassets: | Asset | Gebruik | diff --git a/SECURITY.md b/SECURITY.md index a63d0d86..b443667f 100644 --- a/SECURITY.md +++ b/SECURITY.md @@ -8,7 +8,7 @@ explicitly documented otherwise. ## Reporting vulnerabilities -Report suspected security issues privately to the repository owner. Do not put +Report suspected security issues privately to `security@itworx.tech`. Do not put credentials, access tokens, private infrastructure, precise sensitive locations, proprietary imagery or datasets, model artifacts, production database contents, personal data or exploit-sensitive evidence in a public diff --git a/deploy/unraid/Dockerfile.all-in-one b/deploy/unraid/Dockerfile.all-in-one index 474845d9..f3ae3f40 100644 --- a/deploy/unraid/Dockerfile.all-in-one +++ b/deploy/unraid/Dockerfile.all-in-one @@ -24,6 +24,8 @@ RUN apt-get update && apt-get install -y --no-install-recommends \ gdal-bin \ libgl1 \ libglib2.0-0 \ + libexpat1 \ + libexpat1-dev \ libgdal-dev \ libgeos-dev \ libpq-dev \ diff --git a/docs/ASSET_PROVENANCE.md b/docs/ASSET_PROVENANCE.md new file mode 100644 index 00000000..16dcd5a5 --- /dev/null +++ b/docs/ASSET_PROVENANCE.md @@ -0,0 +1,32 @@ +# Asset provenance and redistribution + +The visual files distributed with GeoIntel were created for this project and +are released by the repository owner with the source under Apache-2.0. They do +not include private operator data, proprietary model weights, unpublished +imagery, or a bundled third-party geospatial dataset. + +## Project artwork + +The original PNG masters in `frontend/design-assets/portfolio/` and their +optimized WebP derivatives in `frontend/public/portfolio/` are project artwork. +The WebP files are mechanical resizes of the corresponding masters; the +reproduction command is documented in `frontend/design-assets/README.md`. + +## Product captures and generated documents + +Files in `docs/assets/portfolio/` are captures or diagrams of the GeoIntel +public-demo interface using synthetic/public demonstration content. The case +study at `output/pdf/geointel-case-study.pdf` is generated from repository +sources by `scripts/create_portfolio_case_study.py`. + +Any provider name, logo, map attribution, or dataset title visible inside a +capture remains the property of its respective owner and is included only to +identify the source or reproduce the application's attribution UI. This +repository does not relicense or redistribute the underlying provider data. + +## Integrity + +Release review verifies these paths through the repository's normal Git object +hashes and the public-release gate. Regenerated derivatives must come from a +tracked master or reproducible repository source; do not replace them with +unlicensed stock material, private screenshots, or local operator exports. diff --git a/docs/CODEX_EXECUTION_LOG.md b/docs/CODEX_EXECUTION_LOG.md index 89a9657b..5f6f1639 100644 --- a/docs/CODEX_EXECUTION_LOG.md +++ b/docs/CODEX_EXECUTION_LOG.md @@ -4,6 +4,19 @@ This public log records release-relevant repository work only. Machine-specific paths, production database state, deployment addresses, model outputs and generated evidence remain in controlled local storage. +## 2026-09-02 — public-release handoff + +- Added an explicit monitored reporting address to `SECURITY.md`. +- Documented ownership, redistribution boundaries and regeneration of the + retained portfolio assets. +- Confirmed the existing Linux/CUDA/Ultralytics lock is platform-specific, + version-pinned and SHA-256 hashed. +- Prevented pull requests from external public forks from executing code on + the private validation runners; push and maintainer-dispatch gates remain. +- Re-ran repository hygiene and full-history secret scanning successfully. +- The complete backend, frontend, migration and container gate remains the + required exact-commit check before changing repository visibility. + ## 2026-08-31 — public-release readiness - Confirmed Apache-2.0 as the repository license. diff --git a/docs/TODO.md b/docs/TODO.md index e052bdf1..8cd2e715 100644 --- a/docs/TODO.md +++ b/docs/TODO.md @@ -5,10 +5,10 @@ - [ ] Pass the complete backend, frontend, migration and container release gate. - [ ] Verify the clean-root publication candidate and local all-ref recovery bundle. -- [ ] Confirm redistribution/provenance for the retained portfolio screenshots. -- [ ] Configure a monitored private security-reporting address or Gitea security +- [x] Confirm redistribution/provenance for the retained portfolio screenshots. +- [x] Configure a monitored private security-reporting address or Gitea security channel in `SECURITY.md`. -- [ ] Finish a fully hashed, platform-specific lock for optional CUDA/Ultralytics +- [x] Finish a fully hashed, platform-specific lock for optional CUDA/Ultralytics packages; base container images are already digest-pinned. ## Product work diff --git a/frontend/package-lock.json b/frontend/package-lock.json index cf28d785..dac28de6 100644 --- a/frontend/package-lock.json +++ b/frontend/package-lock.json @@ -1829,9 +1829,9 @@ } }, "node_modules/baseline-browser-mapping": { - "version": "2.10.36", - "resolved": "https://registry.npmjs.org/baseline-browser-mapping/-/baseline-browser-mapping-2.10.36.tgz", - "integrity": "sha512-lVq/Df7LXlO79MVaaUHztSwWiG9oXoWHlgvNS51v8Dpd4+G4/VIy6qYePTw31nAVls33nUtnfezYeLkYAak9dg==", + "version": "2.11.20", + "resolved": "https://registry.npmjs.org/baseline-browser-mapping/-/baseline-browser-mapping-2.11.20.tgz", + "integrity": "sha512-H0ulySigv6icDJ1F7SjtdCD6PrhTpdYCmP0CactWy1+ekh0AFd0o1Wn5T8b+hnTmdBx19u9yhL6wvCylXMY7zw==", "dev": true, "license": "Apache-2.0", "bin": { @@ -1842,9 +1842,9 @@ } }, "node_modules/browserslist": { - "version": "4.28.2", - "resolved": "https://registry.npmjs.org/browserslist/-/browserslist-4.28.2.tgz", - "integrity": "sha512-48xSriZYYg+8qXna9kwqjIVzuQxi+KYWp2+5nCYnYKPTr0LvD89Jqk2Or5ogxz0NUMfIjhh2lIUX/LyX9B4oIg==", + "version": "4.28.8", + "resolved": "https://registry.npmjs.org/browserslist/-/browserslist-4.28.8.tgz", + "integrity": "sha512-V2NpofLblG64mfOtSgDhOJESZEGogzDMBv/q+W6oc4LXWP/q75eOXoOaaOu1EOadB9U4Bwx/e0yzbvwKH8zalA==", "dev": true, "funding": [ { @@ -1862,11 +1862,11 @@ ], "license": "MIT", "dependencies": { - "baseline-browser-mapping": "^2.10.12", - "caniuse-lite": "^1.0.30001782", - "electron-to-chromium": "^1.5.328", - "node-releases": "^2.0.36", - "update-browserslist-db": "^1.2.3" + "baseline-browser-mapping": "^2.11.12", + "caniuse-lite": "^1.0.30001809", + "electron-to-chromium": "^1.5.402", + "node-releases": "^2.0.53", + "update-browserslist-db": "^1.3.0" }, "bin": { "browserslist": "cli.js" @@ -1886,9 +1886,9 @@ } }, "node_modules/caniuse-lite": { - "version": "1.0.30001799", - "resolved": "https://registry.npmjs.org/caniuse-lite/-/caniuse-lite-1.0.30001799.tgz", - "integrity": "sha512-hG1bReV+OUU+MOqK4t/ZWI0tZOyz3rqS9XuhOUz1cIcbwBKjOyJEJuw9ER5JuNyqxNk8u/JUVbGibBOL1yrjFw==", + "version": "1.0.30001810", + "resolved": "https://registry.npmjs.org/caniuse-lite/-/caniuse-lite-1.0.30001810.tgz", + "integrity": "sha512-TITQPUkaz+aVk5GL6NhOdwk1aEaNTSDPsGFWrTuhKGtjTF70jL/Oht2W4c6rXUe5fu7Ie19VIahAXHIIiWWNeg==", "dev": true, "funding": [ { @@ -2036,9 +2036,9 @@ "license": "ISC" }, "node_modules/electron-to-chromium": { - "version": "1.5.371", - "resolved": "https://registry.npmjs.org/electron-to-chromium/-/electron-to-chromium-1.5.371.tgz", - "integrity": "sha512-e9htk9mAYL6AzmkEhSvVVw7IWGSBJ/Bqdn2eRyRLrj1g6sncN4WbFt5qnILYoCktktr45pyjIrOiRvBThQ808w==", + "version": "1.5.420", + "resolved": "https://registry.npmjs.org/electron-to-chromium/-/electron-to-chromium-1.5.420.tgz", + "integrity": "sha512-2yD6XreGusOfNV+dUcvipJEXc3n/n7fgr7996aszTG+YY5E4mqM4tOq/3uhP129cazL9YHbVWSpc79ePotWtPA==", "dev": true, "license": "ISC" }, @@ -2549,9 +2549,9 @@ } }, "node_modules/node-releases": { - "version": "2.0.47", - "resolved": "https://registry.npmjs.org/node-releases/-/node-releases-2.0.47.tgz", - "integrity": "sha512-Uzmd6LXpouKo8EUK68IjH4+E01w/hXyV3R3g/geCJo+rXLNfh1xucB+LOzYEOQPSiUK3h/xZf0cQGcSsmyL2Og==", + "version": "2.0.54", + "resolved": "https://registry.npmjs.org/node-releases/-/node-releases-2.0.54.tgz", + "integrity": "sha512-YHs7BmmcsdAI5Ozuf8JZo6PT0mv2GIWC9vMfvUC3dp65M8hn7Ux8CPL+2oBI7juNuj9d0ndhTcznq2ODBps9cQ==", "dev": true, "license": "MIT", "engines": { @@ -3092,9 +3092,9 @@ } }, "node_modules/update-browserslist-db": { - "version": "1.2.3", - "resolved": "https://registry.npmjs.org/update-browserslist-db/-/update-browserslist-db-1.2.3.tgz", - "integrity": "sha512-Js0m9cx+qOgDxo0eMiFGEueWztz+d4+M3rGlmKPT+T4IS/jP4ylw3Nwpu6cpTTP8R1MAC1kF4VbdLt3ARf209w==", + "version": "1.3.2", + "resolved": "https://registry.npmjs.org/update-browserslist-db/-/update-browserslist-db-1.3.2.tgz", + "integrity": "sha512-UQ+MSxlhRm1bzjhU+DcuXfjFO1FzNtqhK5+9Yvlp90ItDLk5vT932A0rFu619nf7RVS+Y/VeaUW1jaRDqZ8VJw==", "dev": true, "funding": [ {