Conversation
(cherry picked from commit d27537e)
(cherry picked from commit 1d1f43f)
Bumps [django-allauth](https://github.com/sponsors/pennersr) from 65.16.1 to 65.17.0. - [Commits](https://github.com/sponsors/pennersr/commits) --- updated-dependencies: - dependency-name: django-allauth dependency-version: 65.17.0 dependency-type: direct:production update-type: version-update:semver-minor ... Signed-off-by: dependabot[bot] <support@github.com> (cherry picked from commit 92a21b0)
Bumps [requests](https://github.com/psf/requests) from 2.33.1 to 2.34.2. - [Release notes](https://github.com/psf/requests/releases) - [Changelog](https://github.com/psf/requests/blob/main/HISTORY.md) - [Commits](psf/requests@v2.33.1...v2.34.2) --- updated-dependencies: - dependency-name: requests dependency-version: 2.34.2 dependency-type: direct:production update-type: version-update:semver-minor ... Signed-off-by: dependabot[bot] <support@github.com> (cherry picked from commit 440d2ae)
(cherry picked from commit e2e365c)
…ly (#14187) * Add autoload subcommand to thesaurus management command, task in tasks.py, and entrypoint call * Add documentation for thesaurus autoload command and boot-time thesauri loading * Move autoload_thesauri into its own thesaurus_subcommands/autoload.py * Log improvements, lang selection * Apply suggestions from code review * Fix mutable default argument for langs parameter in load_thesaurus * Fix patch apps.get_app_configs in correct autoload module * Fix code formatting * Improve load final log Co-authored-by: etj <717359+etj@users.noreply.github.com> Co-authored-by: Emanuele Tajariol <etj@geo-solutions.it> (cherry picked from commit 016fdd9)
(cherry picked from commit 08bd4c7)
Bumps [django](https://github.com/django/django) from 5.2.14 to 5.2.15. - [Commits](django/django@5.2.14...5.2.15) --- updated-dependencies: - dependency-name: django dependency-version: 5.2.15 dependency-type: direct:production update-type: version-update:semver-patch ... (cherry picked from commit c9ef9d1) Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
…14312) * Management command to clear gwc cache * GWC Module to handle gwc related stuffs * Updated gwc truncate command to use gwc module * Improve GWC client and truncate command error handling * Fix masstruncate URL * Improvements and fixes * Improvements --------- (cherry picked from commit b4a695d) Co-authored-by: Niraj Adhikari <41701707+nrjadkry@users.noreply.github.com> Co-authored-by: Emanuele Tajariol <etj@geo-solutions.it>
…#14323) (#14324) * [Fixes #14321] copy_with_dump is missing from copy_table_with_ogr2ogr --------- (cherry picked from commit a0f50e5) Co-authored-by: mattiagiupponi <51856725+mattiagiupponi@users.noreply.github.com> Co-authored-by: gemini-code-assist[bot] <176961590+gemini-code-assist[bot]@users.noreply.github.com>
(cherry picked from commit 0803857)
Bumps [cryptography](https://github.com/pyca/cryptography) from 48.0.0 to 49.0.0. - [Changelog](https://github.com/pyca/cryptography/blob/main/CHANGELOG.rst) - [Commits](pyca/cryptography@48.0.0...49.0.0) --- updated-dependencies: - dependency-name: cryptography dependency-version: 49.0.0 dependency-type: direct:production update-type: version-update:semver-major ... (cherry picked from commit 2b7c0ff) Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
* Upgrade of setupttols to 82 with fixes to dependencies * Sanitize metadata input * build(deps): bump cryptography from 48.0.0 to 49.0.0 Bumps [cryptography](https://github.com/pyca/cryptography) from 48.0.0 to 49.0.0. - [Changelog](https://github.com/pyca/cryptography/blob/main/CHANGELOG.rst) - [Commits](pyca/cryptography@48.0.0...49.0.0) --- updated-dependencies: - dependency-name: cryptography dependency-version: 49.0.0 dependency-type: direct:production update-type: version-update:semver-major ... * [Fixes #14339] Drop support Dropbox storage manager --------- (cherry picked from commit 3d929fc) Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: Giovanni Allegri <giohappy@gmail.com> Co-authored-by: Emanuele Tajariol <etj@geo-solutions.it> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> Co-authored-by: Mattia Giupponi <mattia.giupponi@gmail.com>
There was a problem hiding this comment.
Copilot review overview
🟡 Changes recommended
Unresolved correctness, performance, error-handling, and test-coverage issues remain.
Get a fresh assessment by requesting another Copilot review.
Review effort: Lite
Findings: 1
Open (4)
What changed in this PR
Adds a Django management command for validating GeoNode resource metadata against JSON Schema and generating reports.
Changes:
- Supports resource filtering, language selection, and validation options.
- Generates JSON or CSV validation reports.
- Reports schema and instance validation errors.
| File | Summary |
|---|---|
geonode/metadata/management/commands/validate_metadata.py |
Implements metadata validation, filtering, error formatting, and reporting. |
geonode/metadata/management/commands/__init__.py |
Reviewed; no functional changes noted. |
geonode/metadata/management/__init__.py |
Reviewed; no functional changes noted. |
💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.
| return json.loads(json.dumps(data, cls=JSONEncoder)) | ||
|
|
||
| def select_resources(self, ids, resource_types): | ||
| queryset = ResourceBase.objects.all() |
| if not record["valid"]: | ||
| invalid_count += 1 | ||
| if not record["valid"] or options["include_valid"]: | ||
| records.append(record) |
| errors = self.drop_redundant(validator.iter_errors(instance)) | ||
| errors = sorted(errors, key=lambda err: ([str(p) for p in err.absolute_path], str(err.validator))) | ||
| reported = errors[:max_errors] if max_errors > 0 else errors |
|
|
||
| parser.add_argument("--debug", dest="debug", action="store_true", help="Set log level to debug") | ||
|
|
||
| def handle(self, *args, **options): |
cad3b88 to
a5bcca6
Compare
|
Thank you for your pull request and welcome to our community. We could not parse the GitHub identity of the following contributors: Fabian Fischer.
|
|
| GitGuardian id | GitGuardian status | Secret | Commit | Filename | |
|---|---|---|---|---|---|
| 37692361 | Triggered | Username Password | dbc4e59 | geonode/base/api/tests.py | View secret |
🛠 Guidelines to remediate hardcoded secrets
- Understand the implications of revoking this secret by investigating where it is used in your code.
- Replace and store your secret safely. Learn here the best practices.
- Revoke and rotate this secret.
- If possible, rewrite git history. Rewriting git history is not a trivial act. You might completely break other contributing developers' workflow and you risk accidentally deleting legitimate data.
To avoid such incidents in the future consider
- following these best practices for managing and storing secrets including API keys and other credentials
- install secret detection on pre-commit to catch secret before it leaves your machine and ease remediation.
🦉 GitGuardian detects secrets in your source code to help developers and security teams secure the modern development process. You are seeing this because you or someone else with access to this repository has authorized GitGuardian to scan your pull request.
1 similar comment
|
| GitGuardian id | GitGuardian status | Secret | Commit | Filename | |
|---|---|---|---|---|---|
| 37692361 | Triggered | Username Password | dbc4e59 | geonode/base/api/tests.py | View secret |
🛠 Guidelines to remediate hardcoded secrets
- Understand the implications of revoking this secret by investigating where it is used in your code.
- Replace and store your secret safely. Learn here the best practices.
- Revoke and rotate this secret.
- If possible, rewrite git history. Rewriting git history is not a trivial act. You might completely break other contributing developers' workflow and you risk accidentally deleting legitimate data.
To avoid such incidents in the future consider
- following these best practices for managing and storing secrets including API keys and other credentials
- install secret detection on pre-commit to catch secret before it leaves your machine and ease remediation.
🦉 GitGuardian detects secrets in your source code to help developers and security teams secure the modern development process. You are seeing this because you or someone else with access to this repository has authorized GitGuardian to scan your pull request.
There was a problem hiding this comment.
Copilot review overview
🔵 Needs a closer look
Unresolved critical security, data-loss, and correctness findings remain in this broad change set.
Review effort: Lite
Findings: 5
Open (14)
Preserve oversized metadata before destructive deletion · New Merge duplicate GroupForm clean methods · New Recursively validate nested serializer values · New Use safe path containment checks during extraction · New Use polymorphic queryset to preserve resource-specific metadata Combine metadata filters conjunctively · New Handle layers with no identifiable CRS · New Handle null GDAL layers before accessing methods · New Use validated JSON candidate for base asset · New Handle schema errors during validation Stream reports to prevent unbounded memory use Fix misspelling in security-policy link · New Use cloned directory consistently in installation instructions · New Add tests for metadata validation command behavior
| if len(value) > 1024: | ||
| logger.warning( | ||
| f"ExtraMetadata pk={extra_meta.pk} for resource {extra_meta.resource.id}:{extra_meta.resource.title} " | ||
| f"skipped during migration to SparseField: " | ||
| f"serialized value exceeds 1024 characters" | ||
| ) | ||
| continue |
| def clean(self): | ||
| cleaned_data = self.cleaned_data | ||
| for field_name, value in list(cleaned_data.items()): | ||
| if contains_disallowed_template_tokens(value): | ||
| raise forms.ValidationError( | ||
| _("Field %(field_name)s contains characters that are not allowed."), | ||
| params={"field_name": field_name}, | ||
| ) | ||
| return cleaned_data |
| def contains_disallowed_template_tokens(value): | ||
| values = value if isinstance(value, (list, tuple)) else [value] | ||
| return any(isinstance(item, str) and any(token in item for token in DISALLOWED_TEMPLATE_TOKENS) for item in values) |
| if not os.path.realpath(os.path.join(extract_dir, member)).startswith( | ||
| os.path.realpath(extract_dir) | ||
| ): | ||
| raise ImportException(f"Invalid zip entry: {member}") |
| # Compare values in a type-agnostic way. | ||
| if str(stored_value.get(field_name, None)) == str(filter_value): | ||
| batch_pks.add(sf.resource.pk) | ||
|
|
||
| filtered_pks.update(batch_pks) |
| logger.error( | ||
| f"The following layer {layer.GetName()} does not have a Coordinate Reference System (CRS) and will be skipped." | ||
| ) | ||
| return f"{_name}:{_code}" |
| raise InvalidGeopackageException("The geopackage provided is invalid") | ||
|
|
||
| layers_count = len(layers) | ||
| layers_count = layers[0].GetLayerCount() |
| if js_file: | ||
| files = {"base_file": files.get("base_file")} |
| 1. The reported vulnerability has been verified by working with the GeoNode PSC | ||
| 2. GitHub [security advisory](https://github.com/geonode/geonode/security) is used to reserve a CVE number by the GeoNode Organization | ||
| 3. A fix or documentation clarification is accepted and backported to active branches | ||
| 4. A fix is included for the active branches release downloads ([reelases](https://github.com/GeoNode/geonode/releases), or issued via emergency update) |
| Go inside the `geonode-project` folder and create the .env file by using the `create-envfile` script: | ||
|
|
||
| ```bash | ||
| cd my_geonode |
a5bcca6 to
4038798
Compare
|
Thank you for your pull request and welcome to our community. We could not parse the GitHub identity of the following contributors: Fabian Fischer.
|
|
That branch was supposed to be merged on 5.1.x. |



Checklist
For all pull requests:
The following are required only for core and extension modules (they are welcomed, but not required, for contrib modules):
Submitting the PR does not require you to check all items, but by the time it gets merged, they should be either satisfied or inapplicable.