Skip to content

Security: ngageoint/EGMTrans

Security

SECURITY.md

Security Policy

EGMTrans is a small, self-contained vertical-datum transformation tool. This document describes its security-relevant behavior so that infosec teams reviewing the code before adoption can make an informed decision.

Network egress

EGMTrans makes exactly one kind of outbound connection: HTTPS to github.com to download the geoid grid files on first run (or whenever a grid file is missing or fails its checksum). No other network activity occurs at any point during normal operation.

  • Destination: https://github.com/ngageoint/EGMTrans/releases/download/datum-grids-v1/
  • Protocol: HTTPS only (no fallback)
  • Triggered by: the CLI (egmtrans, download_grids.py) and the ArcGIS Pro toolbox, only when the required grids are not already present in datums/
  • No other hosts are contacted.

The command line checks, and downloads if missing, only the grids its source and target datums need (us_nga_egm96_1.tif, us_nga_egm08_1.tif, or both). download_grids.py and the ArcGIS Pro toolbox fetch the full set, including the grids used only by the EGMTrans Explorer maps.

Air-gapped deployments: download the grids manually from the release page above and place them in datums/. The tool will detect them on startup and skip the network call entirely.

Containers: the Dockerfile downloads the two 1-arc-minute grids while the image is built, verifying each against its pinned hash, so a running container makes no network connection at all and can be started with --network none. The image runs as a non-root user.

Grid integrity

Every grid file is verified against a SHA-256 hash that is pinned in the source code at src/egmtrans/download.py (see the GRID_FILES dictionary near the top of the file). Hashes are recomputed after download and compared; on mismatch the partial file is deleted and a RuntimeError is raised. Downloads stream to a .part file and are renamed atomically on successful verification.

If you want to verify the grids against the pinned hashes by hand:

sha256sum datums/us_nga_egm96_1.tif
sha256sum datums/us_nga_egm08_1.tif

Static analysis of the attack surface

  • No eval, exec, pickle, subprocess, or os.system calls in the core package (src/egmtrans/). The tool uses only the standard library (urllib, hashlib) and GDAL's Python bindings to read and write raster files.
  • One fixed-width text codec, no binary parsing of user data beyond it. Raster data is read and written by GDAL. The 3,428-byte DTED header (three ASCII records of fixed length and layout, STANAG 3809 / MIL-PRF-89020B) is read and written by src/egmtrans/dted/header.py from a field table in schema.py: every read is a bounded slice, every write is a fixed-length field checked for length and printable ASCII, and the encoder refuses to overwrite a file that does not carry a DTED data record after its header. The elevation records are read and written by records.py with numpy slices of fixed length: every value is range-checked and cast to an integer before it is encoded, and a DTED file made from scratch is written under a temporary name, verified (header, records, checksums, and GDAL reading it back) and only then renamed to its output name. The optional index and profile are read with GDAL (GeoPackage), pyarrow (GeoParquet) and tomllib (TOML); XML sidecars read during an index build are refused when they declare a DOCTYPE or entities, and are parsed with entity resolution and network access off.
  • No credentials, API keys, or tokens of any kind, in source or at runtime.
  • No telemetry. The tool does not send usage data anywhere.
  • No dynamic code loading. No plugin system, no importlib of user-supplied module names.

Dependencies

Runtime dependencies are pinned to permissive licenses only: numpy (BSD), scipy (BSD), GDAL (MIT/X), numba (BSD, optional), tqdm (MPL-2.0 / MIT); the optional index extra adds pyarrow (Apache-2.0) and lxml (BSD). See pyproject.toml for the version floors.

Reporting a vulnerability

Please report security issues by email to terrain@nga.mil with "EGMTrans security" in the subject line. Do not open a public GitHub issue for exploitable findings until after a fix has been published.

There aren't any published security advisories