Repository navigation
Stop logging the Google Maps API key; archive security-alerts-2026-10 - #64
Merged
Merged
Conversation
CodeQL (py/clear-text-logging-sensitive-data) flagged the satellite image's debug line, which logged the full Static Maps URL with `key=` and `signature=`. It now logs only center, zoom and size. The same method had a second path CodeQL didn't flag, live at the default INFO level: an HTTP error from Google raised httpx.HTTPStatusError, whose message holds the URL; it was logged at ERROR and chained into the traceback. It now logs and raises only the status code, `from None`. The new test fails without the fix (the chained HTTPStatusError carried the key) and checks neither the logs nor the error contain it.
- new spec repository-security-scanning (secret scanning with push protection, CodeQL; not a required check), with its Purpose - automated-dependency-updates: alerts are fixed or dismissed with a reason; dependencies outside Dependabot's reach are listed - frontend-dependency-toolchain: registry-external tarballs and scoped overrides - docs/branch_protection.md: "Security scanning"; CHANGELOG Security - tasks record the post-merge outcomes: 30 -> 0 Dependabot alerts (the xlsx ones closed on their own), orphaned Dependabot PRs closed, #58, #57 and #59 merged, scanning enabled, CodeQL #1-#2 dismissed as false positives and #3 fixed. 6.3 stays open for #60, a routine update
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Follow-up to #63: triages the first CodeQL results, fixes the one real finding, and archives the OpenSpec change
security-alerts-2026-10.Fix: the Google Maps API key no longer reaches the logs
CodeQL (
py/clear-text-logging-sensitive-data) flagged the satellite image's debug line, which logged the full Static Maps URL, includingkey=andsignature=. That line only appears at DEBUG.The same method had a second path, active at the default INFO level, which CodeQL didn't flag. When Google answered with an HTTP error (an invalid key, an exhausted quota),
raise_for_status()raisedhttpx.HTTPStatusError. Its message contains the URL, and it was logged at ERROR and chained into the traceback. The client only ever got a generic 500, but the server logs had the key.Now:
from None.A new test fails without the fix and checks that neither the logs nor the raised error contain the key or the signature.
Archive of
security-alerts-2026-10repository-security-scanning:automated-dependency-updates: every alert is fixed or dismissed with a reason, and dependencies outside Dependabot's reach are listed.frontend-dependency-toolchain: rules for tarballs from outside the registry and for scoped overrides.docs/branch_protection.md: a new "Security scanning" section. The CHANGELOG's Security section is updated too.Outcome recorded in the tasks
xlsxones closed on their own after Resolve the open Dependabot alerts (SheetJS from its CDN, lockfile refresh, overrides) #63.py/path-injectionalerts in the layers store were dismissed as false positives:_metadata_pathvalidates the language and the file name, andtest_metadata_paths_cannot_escape_the_rootcovers it;Verified
openspec validate --specspasses.