Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
Show all changes
78 commits
Select commit Hold shift + click to select a range
b241b07
Release wise.msfd 9.0
eea-jenkins Jun 24, 2026
8eeec82
docs: Added release 6.1.4-22
eea-jenkins Jun 24, 2026
09df242
Release eea.coremetadata 6.0
eea-jenkins Jun 25, 2026
5a674f8
Release eea.volto.policy 13.0
eea-jenkins Jun 25, 2026
4231a54
Release eeacms/plone-backend 6.1.4-7
eea-jenkins Jun 25, 2026
b814589
docs: Added release 6.1.4-23
eea-jenkins Jun 25, 2026
851ae1b
Release wise.msfd 9.1
eea-jenkins Jun 30, 2026
c87094b
Release wise.msfd 9.2
eea-jenkins Jul 1, 2026
3c81471
docs: Added release 6.1.4-24
eea-jenkins Jul 1, 2026
53f3268
Release eeacms/plone-backend 6.1.4-8
eea-jenkins Jul 5, 2026
2ee6134
docs: Added release 6.1.4-25
eea-jenkins Jul 5, 2026
e308036
Release eea.volto.policy 13.1
eea-jenkins Jul 7, 2026
be97243
Release eeacms/plone-backend 6.1.4-9
eea-jenkins Jul 7, 2026
af957ab
Release wise.msfd 9.3
eea-jenkins Jul 7, 2026
f642503
docs: Added release 6.1.4-26
eea-jenkins Jul 8, 2026
0cc8bd3
Release wise.msfd 9.4
eea-jenkins Jul 10, 2026
cbe17d9
Release eea.volto.policy 13.2
eea-jenkins Jul 10, 2026
fc28333
Release eeacms/plone-backend 6.1.4-10
eea-jenkins Jul 11, 2026
20576a3
docs: Added release 6.1.4-29
eea-jenkins Jul 11, 2026
c385c02
Release eea.api.dataconnector 12.9
eea-jenkins Jul 13, 2026
7c2bba3
Release eea.coremetadata 6.1
eea-jenkins Jul 13, 2026
c83cace
Release eea.plotly 2.5
eea-jenkins Jul 13, 2026
a810988
Release eea.volto.policy 13.3
eea-jenkins Jul 13, 2026
14b452a
Release eea.progress.workflow 3.3
eea-jenkins Jul 13, 2026
579649b
Release eeacms/plone-backend 6.1.4-11
eea-jenkins Jul 13, 2026
86a36f3
docs: Added release 6.1.4-30
eea-jenkins Jul 14, 2026
c9744c1
fix: Add betterleaks github action - refs #304517
dobri1408 Jul 14, 2026
d181a05
Release eea.coremetadata 6.2
eea-jenkins Jul 14, 2026
cc4f369
Release eeacms/plone-backend 6.1.4-12
eea-jenkins Jul 14, 2026
d7f8642
docs: Added release 6.1.4-31
eea-jenkins Jul 15, 2026
a30ed2d
Release wise.msfd 9.5
eea-jenkins Jul 16, 2026
f1acf75
Release wise.msfd 9.6
eea-jenkins Jul 17, 2026
4ea7c19
Release wise.msfd 9.7
eea-jenkins Jul 17, 2026
a9268ec
Release wise.msfd 9.8
eea-jenkins Jul 20, 2026
b8fcc9b
Release wise.msfd 9.9
eea-jenkins Jul 21, 2026
13baf02
chore: Move image build to Jenkins
valentinab25 Jul 21, 2026
565d97a
chore: Move image build to Jenkins
valentinab25 Jul 21, 2026
7a92076
chore: Improve run time
valentinab25 Jul 21, 2026
6c1cdef
chore: revert Move image build to Jenkins
laszlocseh Jul 21, 2026
575204d
docs: Added release 6.1.4-37
eea-jenkins Jul 21, 2026
789729f
Release wise.msfd 10.0
eea-jenkins Jul 23, 2026
abbed91
docs: Added release 6.1.4-38
eea-jenkins Jul 23, 2026
845a876
Release wise.msfd 10.1
eea-jenkins Jul 24, 2026
8fc2949
Release eea.coremetadata 6.3
eea-jenkins Jul 28, 2026
ed17f91
Release eeacms/plone-backend 6.1.4-13
eea-jenkins Jul 29, 2026
b034b5f
docs: Added release 6.1.4-40
eea-jenkins Jul 29, 2026
8650aa9
Release wise.msfd 10.2
eea-jenkins Jul 29, 2026
3b9b153
Release wise.msfd 10.3
eea-jenkins Jul 30, 2026
492c18f
Release eea.volto.policy 13.4
eea-jenkins Aug 5, 2026
65d4e65
Release eeacms/plone-backend 6.1.4-14
eea-jenkins Aug 6, 2026
da6fae4
Release wise.msfd 10.4
eea-jenkins Aug 6, 2026
c58a5b8
Release eea.coremetadata 6.4
eea-jenkins Aug 7, 2026
e42bc3a
Release wise.msfd 10.5
eea-jenkins Aug 7, 2026
ef1a0c6
Release wise.msfd 10.6
eea-jenkins Aug 7, 2026
fc8c43a
Release eeacms/plone-backend 6.1.4-15
eea-jenkins Aug 7, 2026
a6f92f9
chore: remove eea.restapi
laszlocseh Aug 7, 2026
53d048c
Add eea.restapi package version 2.9 to constraints
laszlocseh Aug 7, 2026
a03c2c8
Add eea.restapi to requirements
laszlocseh Aug 7, 2026
dace6d0
Release eeacms/plone-backend 6.1.4-16
eea-jenkins Aug 8, 2026
7c6d806
docs: Added release 6.1.4-47
eea-jenkins Aug 8, 2026
a1645aa
Release wise.msfd 10.7
eea-jenkins Aug 10, 2026
0fca3af
Release wise.msfd 10.8
eea-jenkins Aug 11, 2026
bbdf26e
Release wise.msfd 10.9
eea-jenkins Aug 14, 2026
f5afc86
Update requirements by removing eea.restapi
laszlocseh Aug 18, 2026
2c2f839
Remove eea.restapi from constraints
laszlocseh Aug 18, 2026
7591ba4
Release eea.volto.policy 13.5
eea-jenkins Aug 18, 2026
2e073d4
Release eea.volto.policy 13.6
eea-jenkins Aug 18, 2026
3471c1b
Release eeacms/plone-backend 6.1.4-17
eea-jenkins Aug 19, 2026
7065253
Release eea.volto.policy 13.7
eea-jenkins Aug 19, 2026
a909366
Release eea.api.dataconnector 13.0
eea-jenkins Aug 19, 2026
d40ea6a
Release eeacms/plone-backend 6.1.4-18
eea-jenkins Aug 20, 2026
2b3031f
Release wise.msfd 11.0
eea-jenkins Aug 20, 2026
75a1f6a
Release wise.msfd 11.1
eea-jenkins Aug 21, 2026
107ca8f
docs: Added release 6.1.4-52
eea-jenkins Aug 22, 2026
4035d28
Release wise.msfd 11.2
eea-jenkins Aug 25, 2026
d7c952d
docs: Added release 6.1.4-53
eea-jenkins Aug 25, 2026
314faf1
Release wise.msfd 11.3
eea-jenkins Aug 27, 2026
ea13624
Merge branch 'develop' into dev-master
laszlocseh Aug 31, 2026
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
133 changes: 133 additions & 0 deletions .github/workflows/betterleaks.yml
Original file line number Diff line number Diff line change
@@ -0,0 +1,133 @@
name: Betterleaks

on:
push:
pull_request:

permissions:
contents: read

jobs:
scan:
name: Scan for secrets
runs-on: ubuntu-latest
env:
SMTP_URL: ${{ secrets.SMTP_URL }}
SMTP_PORT: ${{ secrets.SMTP_PORT || '25' }}
SMTP_EMAIL: ${{ secrets.SMTP_EMAIL }}
SMTP_PASSWORD: ${{ secrets.SMTP_PASSWORD }}
steps:
- name: Checkout repository
uses: actions/checkout@v4
with:
fetch-depth: 1
ref: ${{ github.event.pull_request.head.sha || github.sha }}

- name: Run Betterleaks
id: betterleaks
continue-on-error: true
uses: dortort/betterleaks-action@v0.1.0
with:
github-token: ${{ secrets.GITHUB_TOKEN }}
scan-mode: dir
scan-path: .
config: .gitleaks.toml
report-format: json
report-path: betterleaks-report.json
redact: "true"
no-color: "true"
no-banner: "true"
fail-on-leak: "true"

- name: Upload Betterleaks report
if: always()
uses: actions/upload-artifact@v4
with:
name: betterleaks-report
path: betterleaks-report.json
if-no-files-found: ignore

- name: Build Betterleaks email summary
id: leak_summary
if: steps.betterleaks.outcome == 'failure'
shell: bash
run: |
if [[ -s betterleaks-report.json ]]; then
jq -r '
def one_line:
tostring
| gsub("[\r\n]+"; " ")
| if length > 240 then .[0:240] + "..." else . end;

.[:20][]
| "- " + (.RuleID // "unknown-rule")
+ " at " + (.File // "unknown-file")
+ ":" + ((.StartLine // 0) | tostring)
+ "\n match: " + ((.Match // .Secret // "REDACTED") | one_line)
' betterleaks-report.json > betterleaks-email-summary.txt

count="$(jq 'length' betterleaks-report.json)"
if (( count > 20 )); then
{
echo ""
echo "... and $((count - 20)) more finding(s). Download the artifact for full details."
} >> betterleaks-email-summary.txt
fi
else
echo "No JSON report was generated. Download the workflow logs for details." > betterleaks-email-summary.txt
fi

{
echo "text<<BETTERLEAKS_SUMMARY"
cat betterleaks-email-summary.txt
echo "BETTERLEAKS_SUMMARY"
} >> "$GITHUB_OUTPUT"

- name: Resolve committer email
id: committer
if: steps.betterleaks.outcome == 'failure'
shell: bash
run: |
committer_email="$(git log -1 --format='%ce')"
author_email="$(git log -1 --format='%ae')"
email="$committer_email"
if [[ -z "$email" || "$email" == *"noreply.github.com"* ]]; then
email="$author_email"
fi
if [[ "$email" =~ ^[^[:space:]@]+@[^[:space:]@]+\.[^[:space:]@]+$ && "$email" != *"noreply.github.com"* ]]; then
echo "email=$email" >> "$GITHUB_OUTPUT"
else
echo "No deliverable committer email found; skipping Betterleaks email notification."
echo "email=" >> "$GITHUB_OUTPUT"
fi

- name: Email committer on Betterleaks failure
if: steps.betterleaks.outcome == 'failure' && steps.committer.outputs.email != '' && env.SMTP_URL != '' && env.SMTP_EMAIL != ''
uses: dawidd6/action-send-mail@v18
with:
server_address: ${{ env.SMTP_URL }}
server_port: ${{ env.SMTP_PORT }}
secure: ${{ env.SMTP_PORT == '465' }}
username: ${{ env.SMTP_EMAIL }}
password: ${{ env.SMTP_PASSWORD }}
from: ${{ env.SMTP_EMAIL }}
to: ${{ steps.committer.outputs.email }}
subject: "[Betterleaks] Secret scan failed in ${{ github.repository }}"
body: |
Betterleaks detected one or more potential secrets.

Repository: ${{ github.repository }}
Branch: ${{ github.ref_name }}
Commit: ${{ github.sha }}
Workflow run: ${{ github.server_url }}/${{ github.repository }}/actions/runs/${{ github.run_id }}

Findings:
${{ steps.leak_summary.outputs.text }}

Download the betterleaks-report artifact from the workflow run for details.

- name: Fail if Betterleaks found leaks
if: steps.betterleaks.outcome == 'failure'
run: |
echo "Betterleaks detected one or more secrets. Download the betterleaks-report artifact from this workflow run for details."
exit 1
100 changes: 100 additions & 0 deletions .gitleaks.toml
Original file line number Diff line number Diff line change
@@ -0,0 +1,100 @@
title = "Betterleaks config"

[extend]
useDefault = true

[[rules]]
id = "secret-literal-assignment"
description = "Secret-like literal assignment in source, YAML, env and config files"
regex = '''(?i)([A-Za-z0-9_.-]*(?:password|passwd|pwd|api[_-]?key|apikey|access[_-]?key|secret[_-]?access[_-]?key|private[_-]?key|client[_-]?secret|consumer[_-]?key|consumer[_-]?secret|(?:auth|access|refresh|session|api|bearer|id|jwt|csrf|xsrf|oauth)[_-]?token|translate[_-]?auth|translation[_-]?auth|auth[_-]?password|auth[_-]?key|auth[_-]?credentials|database[_-]?url|connection[_-]?string)[A-Za-z0-9_.-]*)[ \t]*[:=][ \t]*["'']?([^"''[:space:]#{}$.][^"''\n#{}]{2,})["'']?'''
secretGroup = 2
keywords = [
"password",
"passwd",
"pwd",
"api_key",
"apikey",
"access_key",
"private_key",
"client_secret",
"consumer_key",
"consumer_secret",
"auth_token",
"access_token",
"refresh_token",
"session_token",
"api_token",
"bearer_token",
"id_token",
"jwt_token",
"csrf_token",
"xsrf_token",
"oauth_token",
"translate_auth",
"translation_auth",
"auth_password",
"auth_key",
"auth_credentials",
"database_url",
"connection_string"
]
tags = ["literal-secret"]

[[rules]]
id = "env-short-secret-assignment"
description = "Uppercase env-style PASS/TOKEN/SECRET assignment"
regex = '''\b((?:PASS|TOKEN|SECRET|[A-Z0-9_]*(?:_PASS|_TOKEN|_SECRET|PASS_|TOKEN_|SECRET_)[A-Z0-9_]*))[ \t]*[:=][ \t]*["'']?([^"''[:space:]#{}$.][^"''\n#{}]{2,})["'']?'''
secretGroup = 2
keywords = [
"PASS",
"TOKEN",
"SECRET"
]
tags = ["env", "literal-secret"]

[[rules]]
id = "standalone-sk-token"
description = "Standalone sk-* token not attached to a secret-like variable name"
regex = '''(?i)\b(sk-[A-Za-z0-9][A-Za-z0-9_-]{20,})\b'''
secretGroup = 1
entropy = 2.5
keywords = ["sk-"]
tags = ["standalone-token", "generic"]

[[rules]]
id = "dotenv-only-jest-setup"
description = ".env may only contain the committed Jest setup lines"
path = '''(?i)(^|/)\.env$'''
regex = '''(?m)^(.+)$'''
secretGroup = 1
tags = ["file", "dotenv"]
[[rules.allowlists]]
regexTarget = "match"
regexes = [
'''^JEST_USE_SETUP=(ON|OFF) # Jest configuration variables: ON, OFF\r?$''',
]

[[rules]]
id = "forbidden-secret-file"
description = "Forbidden secret-bearing file committed to repository"
path = '''(?i)(^|/)(\.env\..*|\.npmrc|\.pypirc|id_rsa|id_ed25519|.*\.(pem|key|p12|pfx|jks|kubeconfig))$'''
regex = '''(?s).{1,}'''
tags = ["file", "secret-file"]

[[allowlists]]
description = "Allow Jenkins SonarQube token environment variable reference"
regexTarget = "match"
regexes = [
'''SONAR_AUTH_TOKEN''',
]

[[allowlists]]
description = "Allow local development RelStorage password defaults"
paths = [
'''(?i)(^|/)develop/etc/(relstorage|alpha)\.conf$''',
]
regexTarget = "match"
regexes = [
'''password='zope''',
]

Loading
Loading