DOI-USGS / knoten

Python Geospatial Sensor Exploitation Library
Other
3 stars 21 forks source link

Administrative and Security Code Review #96

Closed jessemapel closed 2 years ago

jessemapel commented 2 years ago

All software must have an administrative security review before it is made publicly available by any method. This type of review ensures personal, private, or otherwise sensitive information is not included in the repository. Types of sensitive information include:

Administrative security reviews may be performed by any trusted person; the reviewer does not necessarily need a strong scientific or programming background. When migrating an existing project into any non-private Git repository, it is important to remember that the entire project history needs to be reviewed if that history is to be maintained after migration.

acpaquette commented 2 years ago
  1. Examples/data/:
    • EN0213023991M.json
    • EN0213110924M.json

    • One potential server referenced in the gitlab-ci.yml is code.usgs.gov:5001/astrogeology/knoten/ubuntu:latest but code.usgs.gov is technically public facing so it may be acceptable?

    • No usernames or passwords for internal accounts
jessemapel commented 2 years ago

One potential server referenced in the gitlab-ci.yml is code.usgs.gov:5001/astrogeology/knoten/ubuntu:latest but code.usgs.gov is technically public facing so it may be acceptable?

This is acceptable.

jessemapel commented 2 years ago

The release is going to need to be re-done once the issues in the administrative review are resolved.

jessemapel commented 2 years ago

I will address these issues while I'm working on ALE's history too.

jessemapel commented 2 years ago

I've wiped the history for the files with paths, then re-added them with the internal paths removed or converted to relative paths. @acpaquette This should be ready for a re-review.

acpaquette commented 2 years ago

Everything looks to have been addressed. Knoten is ready for release!