Skip to content

👩‍💻 Secure Coding Policy ​

We use the OWASP Secure Coding Practices Checklist as the baseline, then apply a risk-based approach and improve continuously.

See also Information Security Policy and incident response.

Applies to anyone committing to SysReptor, SysReptor Portal, reptor, or SysLeaks.

Additionally, the following requirements must be met:

  • Every API endpoint has automated authorization tests. In Django projects that means covering it in test_api.py, gating with permission_classes in views.py, and adding explicit tests when class-level permissions are not enough.
  • If users with the same permission level can use one endpoint but only with a limited dataset (e.g., list their own projects, not those of others), cover that with explicit tests. In Django projects that means get_queryset in views.py, preferably using only_permitted (in queryset.py).
  • Do not commit secrets. Tokens, keys, and connection strings stay out of git.
  • Do not ship dependencies with known exploitable vulnerabilities. Patch or replace on a risk basis.

Further conventions ​

  • We use ruff for linting and formatting

Last reviewed: 03/09/2026