docs: add SECURITY.md and ignore credential file patterns - #22
Merged
Merged
Conversation
Preparing this repository to be made public.
SECURITY.md matters more than usual here: this theme renders the login,
registration and account pages that every CivicDataLab product
authenticates through, so a finder needs a private route to report
rather than opening a public issue on an auth surface. Points at GitHub
private advisories first and info@civicdatalab.in as a fallback, sets
scope, and routes Keycloak and Keycloakify findings upstream where they
belong.
The .gitignore additions are preventative rather than corrective.
Nothing sensitive has ever been committed - 634 commits were scanned
before this change and found no .env, no key material and no
credentials, only variable references such as ${KEYCLOAK_PASSWORD} - and
these patterns are what keeps that true once the repository is public
and mistakes become permanent.
.env.example is explicitly re-included so the documented template still
ships.
Verified no currently tracked file matches the new patterns, so nothing
silently drops out of the index.
The README was still the unmodified Keycloakify starter template. It described a generic starter's release workflow and said nothing about what this repository actually is, where it deploys, or that a bad merge signs every CivicDataLab user out of every product. Leads with four badges so the repository home shows deploy and CI state at a glance - the quality gate is visible rather than something you have to open the Actions tab to learn. The Actions badges render once the repository is public; they 404 while it is private, which is expected. Documents what the starter README could not: - auth.civicdatalab.in is production, and which products depend on it - merging to main deploys; pushing to dev does not - the deploy path, including the health gate and automatic rollback - that the rollback is NOT a complete safety net, because a Keycloak major upgrade migrates the schema one-way and the older image cannot start against it - hence the pg_dump before every deploy - why the post-deploy tests live in CivicDataSpace-test: the theme ships independently of the applications, so a theme change can break sign-in while every product's own pipeline stays green - which jar to use and why copying both breaks theme selection - the identifiers that still say "staging" and must not be renamed, with the consequence of each Keeps the genuinely useful starter content - local setup, Maven requirement, account and email theme initialisation - and drops the starter's release instructions, which do not apply here.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Preparing this repository to be made public.
Audit result first
check_public_ready.shreports 0 fails. The detail, because "0 fails" alone is not evidence:.env/.pem/.keyever committed${KEYCLOAK_PASSWORD}— a variable referencegitleaks reports 4 findings; all four are false positives — the same reCAPTCHA site key in Storybook fixtures. Site keys are public by design (they ship in the HTML of any page using reCAPTCHA), and this one comes from the upstream Keycloakify starter template, dated 2024-06-05.
Secrets were correctly kept in the host's
.envand in GitHub environment secrets throughout.SECURITY.md
Matters more than usual here: this theme renders the login, registration and account pages that every CivicDataLab product authenticates through. A finder needs a private route to report, rather than opening a public issue on an auth surface.
Points at GitHub private advisories first,
info@civicdatalab.inas fallback, sets scope, and routes Keycloak/Keycloakify findings upstream where they actually get fixed..gitignore
Preventative, not corrective — nothing has leaked. These patterns are what keeps that true once the repo is public and mistakes become permanent and world-readable.
Adds
.envand variants,*.pem,*.key,*.p12, keystores,id_rsa/id_ed25519, plus the Python tooling patterns the audit flagged..env.exampleis explicitly re-included so the documented template still ships.Verified no currently tracked file matches the new patterns, so nothing silently drops out of the index.
After going public
Rulesets, branch protection, required reviewers and wait timers all become available — currently every one returns 403 on the free plan for a private repo. That is the protection worth adding for a production auth deploy.