Plone 6 backend for Biodiversity website. See also Plone 6 frontend for Biodiversity website.
See Plone 6 frontend for Biodiversity website
docker pull eeacms/bise-backend
docker run -it --rm -p 8080:8080 -e SITE=Plone eeacms/bise-backend
See Plone backend at http://localhost:8080/Plone
See develop
See release
This repository uses the Betterleaks GitHub Action to scan the current
repository content on every push and pull request. The scan uses the rules in
.gitleaks.toml and uploads a betterleaks-report artifact when a finding is
detected.
If the optional SMTP secrets are configured, failed scans also send an email to the last commit committer. The workflow expects these repository or organization secrets:
SMTP_URLSMTP_PORT (optional, defaults to 25)SMTP_EMAILSMTP_PASSWORD (optional if the SMTP server does not require authentication)Port 465 is sent with direct TLS; other ports use the default SMTP handshake.
The email includes a short finding summary from the redacted Betterleaks report,
including the redacted matched line from each finding.
There are three common outcomes:
Everything is OK. The Betterleaks / Scan for secrets check is green and
no action is needed. Regular references to runtime values are OK, for example:
const tokenFromCookie = req.universalCookies.get('auth_token');
A real secret was found. The check is red and the workflow log asks you to
download the betterleaks-report artifact. Open the artifact from the GitHub
Actions run and check the reported file, line and rule. Remove the committed
value, move it to the proper secret store, and rotate it if it was exposed.
A report entry looks like this:
{
"RuleID": "secret-literal-assignment",
"File": "src/config.js",
"StartLine": 12,
"Secret": "[REDACTED]"
}
The finding is a false positive. Keep the value only if it is clearly not
sensitive, such as a test fixture, placeholder, or public example. Add
betterleaks:allow on the same line and include a short explanation in the
pull request.
const testPassword = 'admin'; //betterleaks:allow
password: "admin" #betterleaks:allow
Do not add betterleaks:allow to real credentials.
The Initial Owner of the Original Code is European Environment Agency (EEA). All Rights Reserved.
See LICENSE.md for details.
Content type
Image
Digest
sha256:a46bf8da5…
Size
657 MB
Last updated
27 days ago
docker pull eeacms/bise-backend