GeoIntel release gates / Compile, test, contracts and builds (push) Successful in 1m49s
GeoIntel release gates / Python and npm vulnerability policy (push) Successful in 21s
GeoIntel release gates / Production AI image, SBOM and container scan (push) Successful in 5m39s
GeoIntel release gates / Deploy exact gated revision to Unraid (push) Failing after 58m43s
27 lines
795 B
Markdown
27 lines
795 B
Markdown
# Security and Secret Handling
|
|
|
|
## Secrets
|
|
Never commit API keys, tokens, model credentials, STAC credentials, database passwords, or private URLs.
|
|
|
|
## Environment Variables
|
|
All secrets must be loaded from `.env` or deployment environment.
|
|
|
|
## File Upload Safety
|
|
- limit accepted extensions;
|
|
- validate MIME/type where possible;
|
|
- store uploads outside source directories;
|
|
- generate server-side filenames;
|
|
- never execute uploaded files;
|
|
- reject path traversal.
|
|
|
|
## External Connectors
|
|
- log endpoint names but not credentials;
|
|
- timeout external requests;
|
|
- cache responses where appropriate;
|
|
- show connector status in UI.
|
|
|
|
## AI/Model Safety
|
|
- model files must be treated as artifacts;
|
|
- do not auto-download arbitrary executable code;
|
|
- keep model registry metadata separate from weights.
|