Skip to main content
Develop Master

The eea.banner is a Plone add-on

Main features

1. Easy to install/uninstall via Site Setup > Add-ons 2. 3.

Install

Buildout installation

Source code

Eggs repository

Plone versions

It has been developed and tested for Plone 4 and 5. See buildouts section above.

How to contribute

See the contribution guidelines (CONTRIBUTING.md).

Funding

EEA - European Environment Agency (EU)

Secret Scanning

This repository uses the Betterleaks GitHub Action to scan the current repository content on every push and pull request. The scan uses the rules in .gitleaks.toml and uploads a betterleaks-report artifact when a finding is detected.

If the optional SMTP secrets are configured, failed scans also send an email to the last commit committer. The workflow expects these repository or organization secrets:

  • SMTP_URL

  • SMTP_PORT (optional, defaults to 25)

  • SMTP_EMAIL

  • SMTP_PASSWORD (optional if the SMTP server does not require authentication)

Port 465 is sent with direct TLS; other ports use the default SMTP handshake. The email includes a short finding summary from the redacted Betterleaks report, including the redacted matched line from each finding.

There are three common outcomes:

  1. Everything is OK. The Betterleaks / Scan for secrets check is green and no action is needed. Regular references to runtime values are OK, for example:

    token_from_cookie = request.cookies.get("auth_token")
  2. A real secret was found. The check is red and the workflow log asks you to download the betterleaks-report artifact. Open the artifact from the GitHub Actions run and check the reported file, line and rule. Remove the committed value, move it to the proper secret store, and rotate it if it was exposed. A report entry looks like this:

    {
      "RuleID": "secret-literal-assignment",
      "File": "src/config.py",
      "StartLine": 12,
      "Secret": "[REDACTED]"
    }
  3. The finding is a false positive. Keep the value only if it is clearly not sensitive, such as a test fixture, placeholder, or public example. Add betterleaks:allow on the same line and include a short explanation in the pull request:

    test_password = "admin"  #betterleaks:allow

Do not add betterleaks:allow to real credentials.

Changelog

1.8 - (2026-07-13)

  • Change: fix: SonarQube report - refs #305404 [avoinea]

1.7 - (2026-04-14)

  • Change: Add unit tests for isTrue function [avoinea]

1.6 - (2026-04-14)

  • Change: Add unit tests for isTrue function [avoinea]

1.5 - (2025-11-18)

  • Change: Replace Python linting to ruff [mihaidobrescu1111 = refs #286821]

  • Change: Add plone6 tests [mihaidobrescu1111 = refs #293593]

1.4 - (2022-08-29)

  • Change: Changed how eea.banner gets STATIC/DYNAMIC env vars [iulianpetchesi #153089]

1.3 - (2022-02-17)

  • Change: Fix api when addon not installed [razvanMiu]

1.2 - (2022-02-16)

  • Change: Banner can be enabled from env [razvanMiu]

1.1 - (2022-02-16)

  • Change: Check if dynamic_banner_enabled before getting rancher state. [razvanMiu]

1.0 - (2022-02-14)

  • Change: [Feature #142078] Volto banner enhancements [razvanMiu]

1.0 - (2022-02-14)

  • Initial release. [eea]

Download files

Download the file for your platform. If you're not sure which to choose, learn more about installing packages.

Source Distribution

eea_banner-1.8.tar.gz (27.6 kB view details)

Uploaded Source

File details

Details for the file eea_banner-1.8.tar.gz.

File metadata

  • Download URL: eea_banner-1.8.tar.gz
  • Upload date:
  • Size: 27.6 kB
  • Tags: Source
  • Uploaded using Trusted Publishing? No
  • Uploaded via: twine/6.2.0 CPython/3.9.25

File hashes

Hashes for eea_banner-1.8.tar.gz
Algorithm Hash digest
SHA256 099ed62844f2139c0332d16de72fd7cfc06312089dd7874cdbc000a8d4c06b62
MD5 ac99a7dac6d167ae434e7738ff85450a
BLAKE2b-256 dd41d8436af9c79b58d8460c65de6d454f339101e6d7ec7be598c343a859609b

See more details on using hashes here.

Supported by

AWS Cloud computing and Security Sponsor Datadog Monitoring Depot Continuous Integration Fastly CDN Google Download Analytics Pingdom Monitoring Sentry Error logging StatusPage Status page