Skip to main content

eea.website.policy

Develop Master

The eea.website.policy is a Plone add-on

Main features

1. Easy to install/uninstall via Site Setup > Add-ons 2. 3.

Install

Buildout installation

Source code

Eggs repository

Plone versions

It has been developed and tested for Plone 4 and 5. See buildouts section above.

How to contribute

See the contribution guidelines (CONTRIBUTING.md).

Funding

EEA - European Environment Agency (EU)

Secret Scanning

This repository uses the Betterleaks GitHub Action to scan the current repository content on every push and pull request. The scan uses the rules in .gitleaks.toml and uploads a betterleaks-report artifact when a finding is detected.

If the optional SMTP secrets are configured, failed scans also send an email to the last commit committer. The workflow expects these repository or organization secrets:

  • SMTP_URL

  • SMTP_PORT (optional, defaults to 25)

  • SMTP_EMAIL

  • SMTP_PASSWORD (optional if the SMTP server does not require authentication)

Port 465 is sent with direct TLS; other ports use the default SMTP handshake. The email includes a short finding summary from the redacted Betterleaks report, including the redacted matched line from each finding.

There are three common outcomes:

  1. Everything is OK. The Betterleaks / Scan for secrets check is green and no action is needed. Regular references to runtime values are OK, for example:

    token_from_cookie = request.cookies.get("auth_token")
  2. A real secret was found. The check is red and the workflow log asks you to download the betterleaks-report artifact. Open the artifact from the GitHub Actions run and check the reported file, line and rule. Remove the committed value, move it to the proper secret store, and rotate it if it was exposed. A report entry looks like this:

    {
      "RuleID": "secret-literal-assignment",
      "File": "src/config.py",
      "StartLine": 12,
      "Secret": "[REDACTED]"
    }
  3. The finding is a false positive. Keep the value only if it is clearly not sensitive, such as a test fixture, placeholder, or public example. Add betterleaks:allow on the same line and include a short explanation in the pull request:

    test_password = "admin"  #betterleaks:allow

Do not add betterleaks:allow to real credentials.

Changelog

4.5 - (2026-09-21)

  • Change: Add context_navigation actions for Epanet Subsite [nileshgulia1]

4.4 - (2026-07-13)

  • Change: Add betterleaks action [avoinea]

4.3 - (2026-07-08)

  • Change: fix: SonarQube report - refs #305404 [avoinea]

4.2 - (2025-11-21)

  • Change: Fix jenkinsfile to use token [valentinab25]

4.1 - (2025-11-19)

  • Change: Replace Python linting to ruff [mihaidobrescu1111 = refs #286821]

  • Change: Add plone6 tests [mihaidobrescu1111 = refs #293593]

4.0 - (2024-05-20)

  • Change: Upgrade step to Volto 17 teaserGrid to gridBlock [avoinea - refs #265726]

3.1 - (2024-04-03)

  • Change: dummy release [alecghica]

3.0 - (2023-06-01)

  • Change: Persist EEA WWW GenericSetup profile [avoinea - refs #145772]

  • Feature: Add dependencies: eea.progress.editing, eea.api.dataconnector, collective.volto.subsites [avoinea - refs #145772]

2.0 - (2022-11-14)

  • Breaking: Remove TTW DX Layout marker interface - requires plone.restapi 8.32.0 [avoinea - refs #151856]

1.3 - (2022-09-05)

  • Change: fix(layout): TTW DX Layout marker interface - refs #153858 [avoinea]

1.2 - (2022-08-11)

  • Feature: Add blocks layout to Folder ctype [avoinea]

  • Feature: Add homepage_inverse_view and homepage_view to LRF ctype [avoinea]

1.1 - (2022-08-05)

  • Feature: Persist demo-www profile and auto-install dependency profiles [avoinea]

1.0 - (2022-03-18)

  • Change: Add EEA supported languages [avoinea]

1.0 - (2022-03-18)

  • Initial release. [eea]

Release files for eea.website.policy 4.5

For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.

Source distribution (sdist)

Source distribution for eea.website.policy 4.5
File Size Uploaded
eea_website_policy-4.5.tar.gz 47.4 kB Details

Release files / eea_website_policy-4.5.tar.gz

Download URL eea_website_policy-4.5.tar.gz
Size 47.4 kB
Tags Source
SHA-256 checksum
How to use checksums
948b31ffb9719b699cfae0a99541ff2bdde71c93641a2d3ca8d06caa534aba0c
BLAKE2b-256 checksum
How to use checksums
ce2bcc31dd16f3d65e8ae2f324db0ad9e822b0d29d549a4c4d9108df509b65f9
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
No
Uploaded via twine/6.2.0 CPython/3.9.25

Release history Release notifications | RSS feed

This release

4.5 This release

1 release file

4.4

1 release file

4.3

1 release file

4.2

1 release file

4.1

1 release file

4.0

1 release file

3.1

1 release file

3.0

1 release file

2.0

1 release file

1.3

1 release file

1.2

1 release file

1.1

1 release file

1.0

1 release file

Anthropic, PBC Visionary sponsor Bloomberg Visionary sponsor Hudson River Trading Visionary sponsor Meta Visionary sponsor NVIDIA Visionary sponsor Microsoft Sustainability sponsor Depot Continuous Integration AWS Cloud computing and Security Sponsor Datadog Monitoring Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page