The eea.website.policy is a Plone add-on
Main features
1. Easy to install/uninstall via Site Setup > Add-ons 2. 3.
Install
Add eea.website.policy to your eggs section in your buildout and re-run buildout:
[buildout] eggs += eea.website.policy
You can download a sample buildout from:
Or via docker:
$ docker run --rm -p 8080:8080 -e ADDONS="eea.website.policy" plone
Install eea.website.policy within Site Setup > Add-ons
Buildout installation
Source code
Eggs repository
Plone versions
It has been developed and tested for Plone 4 and 5. See buildouts section above.
How to contribute
Copyright and license
eea.website.policy (the Original Code) is free software; you can redistribute it and/or modify it under the terms of the GNU General Public License as published by the Free Software Foundation; either version 2 of the License, or (at your option) any later version.
This program is distributed in the hope that it will be useful, but WITHOUT ANY WARRANTY; without even the implied warranty of MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the GNU General Public License for more details.
You should have received a copy of the GNU General Public License along with this program; if not, write to the Free Software Foundation, Inc., 59 Temple Place, Suite 330, Boston, MA 02111-1307 USA.
The Initial Owner of the Original Code is European Environment Agency (EEA). Portions created by Eau de Web are Copyright (C) 2009 by European Environment Agency. All Rights Reserved.
Funding
EEA - European Environment Agency (EU)
Secret Scanning
This repository uses the Betterleaks GitHub Action to scan the current repository content on every push and pull request. The scan uses the rules in .gitleaks.toml and uploads a betterleaks-report artifact when a finding is detected.
If the optional SMTP secrets are configured, failed scans also send an email to the last commit committer. The workflow expects these repository or organization secrets:
SMTP_URL
SMTP_PORT (optional, defaults to 25)
SMTP_EMAIL
SMTP_PASSWORD (optional if the SMTP server does not require authentication)
Port 465 is sent with direct TLS; other ports use the default SMTP handshake. The email includes a short finding summary from the redacted Betterleaks report, including the redacted matched line from each finding.
There are three common outcomes:
Everything is OK. The Betterleaks / Scan for secrets check is green and no action is needed. Regular references to runtime values are OK, for example:
token_from_cookie = request.cookies.get("auth_token")A real secret was found. The check is red and the workflow log asks you to download the betterleaks-report artifact. Open the artifact from the GitHub Actions run and check the reported file, line and rule. Remove the committed value, move it to the proper secret store, and rotate it if it was exposed. A report entry looks like this:
{ "RuleID": "secret-literal-assignment", "File": "src/config.py", "StartLine": 12, "Secret": "[REDACTED]" }The finding is a false positive. Keep the value only if it is clearly not sensitive, such as a test fixture, placeholder, or public example. Add betterleaks:allow on the same line and include a short explanation in the pull request:
test_password = "admin" #betterleaks:allow
Do not add betterleaks:allow to real credentials.
Changelog
4.4 - (2026-07-13)
Change: Add betterleaks action [avoinea]
4.3 - (2026-07-08)
Change: fix: SonarQube report - refs #305404 [avoinea]
4.2 - (2025-11-21)
Change: Fix jenkinsfile to use token [valentinab25]
4.1 - (2025-11-19)
Change: Replace Python linting to ruff [mihaidobrescu1111 = refs #286821]
Change: Add plone6 tests [mihaidobrescu1111 = refs #293593]
4.0 - (2024-05-20)
Change: Upgrade step to Volto 17 teaserGrid to gridBlock [avoinea - refs #265726]
3.1 - (2024-04-03)
Change: dummy release [alecghica]
3.0 - (2023-06-01)
Change: Persist EEA WWW GenericSetup profile [avoinea - refs #145772]
Feature: Add dependencies: eea.progress.editing, eea.api.dataconnector, collective.volto.subsites [avoinea - refs #145772]
2.0 - (2022-11-14)
Breaking: Remove TTW DX Layout marker interface - requires plone.restapi 8.32.0 [avoinea - refs #151856]
1.3 - (2022-09-05)
Change: fix(layout): TTW DX Layout marker interface - refs #153858 [avoinea]
1.2 - (2022-08-11)
Feature: Add blocks layout to Folder ctype [avoinea]
Feature: Add homepage_inverse_view and homepage_view to LRF ctype [avoinea]
1.1 - (2022-08-05)
Feature: Persist demo-www profile and auto-install dependency profiles [avoinea]
1.0 - (2022-03-18)
Change: Add EEA supported languages [avoinea]
1.0 - (2022-03-18)
Initial release. [eea]
Download files
Download the file for your platform. If you're not sure which to choose, learn more about installing packages.
Source Distribution
File details
Details for the file eea_website_policy-4.4.tar.gz.
File metadata
- Download URL: eea_website_policy-4.4.tar.gz
- Upload date:
- Size: 46.6 kB
- Tags: Source
- Uploaded using Trusted Publishing? No
- Uploaded via: twine/6.2.0 CPython/3.9.25
File hashes
| Algorithm | Hash digest | |
|---|---|---|
| SHA256 |
ee9911de94b598d183654587fd2faea7e459e281bd17b8a1bd8457b3c37e773e
|
|
| MD5 |
89e82d445dbc8f7b1a6ccd7796ad0b9b
|
|
| BLAKE2b-256 |
0736957cedde1de74fd6c03504469d81373e478ea92695dfb390a0ac593d3f07
|