Internal-operations tool for a CESFAM's own staff — one establishment per install, named in that
install's configuration and never in this repository. It holds no patient/clinical data;
development uses synthetic fixtures only. The gestion repository is private; only the
organization profile is public.
Do not open a public issue for a security problem. Use the repo's Report a vulnerability button (GitHub Private Vulnerability Reporting) to reach the maintainer privately. One person reads these, so expect a first response in days rather than hours.
The dev stack runs locally, bound to loopback, with synthetic data. These are deliberate local-dev conveniences, not production weaknesses, and are out of scope for vulnerability reports:
- Redis without a password (internal to the compose network, not published).
- Services bound to
127.0.0.1only.
There is no production deployment in this repo. If one is ever built, these must be revisited.
Secret handling (all secrets in the gitignored .env, vault = Proton Pass) and the 1-approval
PR gate — including why the free plan can't enforce it — are owned by
CONTRIBUTING.md; see it rather than a second copy here. A local pre-commit guard
(.githooks/pre-commit, enabled with git config core.hooksPath .githooks) blocks committing secret files.
Owner actions in GitHub settings (free-tier; verified 2026-07-19), priority order:
- Enable Private Vulnerability Reporting (Repo → Settings → Code security → Private vulnerability reporting) so the "Report a vulnerability" button above is active.
- Enforce org-wide 2FA (Org → Settings → Authentication security). Confirm all members are enrolled first — members without 2FA are removed when it's turned on.
- Secret scanning + push protection on the public
.githubrepo (free for public repos). - Lock repo visibility & deletion to owners (Org → Member privileges) so
gestioncan't be flipped public by accident. - Enable Dependabot alerts on
gestion(free on private repos; zero config). - Enable Dependabot security updates — the automatic fix PRs, a separate setting from alerts, which is why this is its own line.
- Enable the local secret-guard hook on every clone —
.githooks/pre-commit, enabled withgit config core.hooksPath .githooks. The docs gate fails a hook that is not executable.
- Least-privilege base permission (org base = Read/None). Grant explicit Write per person if anyone is added; today the only account with access is the owner.
- One Owner: the organisation has one member, who is the owner. Re-check when that changes.
- GitHub Actions: landed 2026-07-29 and now the merge gate — do not disable. Workflow permissions stay read-only.
- Restrict third-party OAuth apps + require approval for fine-grained PATs at the org level.
- Keep the public
.githubrepo to the profile README plus the four generic org defaults ADR-0012 allows — and nothing that states security posture, a host path, or a person. -
.gitignorecatch-alls for*.pem,*.key,*.p12,id_rsa*. - Quarterly visibility audit:
gh repo list APS-Conecta --json name,visibility—gestionprivate,.githubpublic.