EGMTrans is a small, self-contained vertical-datum transformation tool. This document describes its security-relevant behavior so that infosec teams reviewing the code before adoption can make an informed decision.
EGMTrans makes exactly one kind of outbound connection: HTTPS to
github.com to download the geoid grid files on first run (or whenever a
grid file is missing or fails its checksum). No other network activity
occurs at any point during normal operation.
- Destination:
https://github.com/ngageoint/EGMTrans/releases/download/datum-grids-v1/ - Protocol: HTTPS only (no fallback)
- Triggered by: the CLI (
egmtrans,download_grids.py) and the ArcGIS Pro toolbox, only when the required grids are not already present indatums/ - No other hosts are contacted.
The command line checks, and downloads if missing, only the grids its source
and target datums need (us_nga_egm96_1.tif, us_nga_egm08_1.tif, or both).
download_grids.py and the ArcGIS Pro toolbox fetch the full set, including the
grids used only by the EGMTrans Explorer maps.
Air-gapped deployments: download the grids manually from the release page
above and place them in datums/. The tool will detect them on startup and
skip the network call entirely.
Containers: the Dockerfile downloads the two 1-arc-minute grids while the
image is built, verifying each against its pinned hash, so a running container
makes no network connection at all and can be started with --network none.
The image runs as a non-root user.
Every grid file is verified against a SHA-256 hash that is pinned in the
source code at src/egmtrans/download.py (see the GRID_FILES dictionary
near the top of the file). Hashes are recomputed after download and
compared; on mismatch the partial file is deleted and a RuntimeError is
raised. Downloads stream to a .part file and are renamed atomically on
successful verification.
If you want to verify the grids against the pinned hashes by hand:
sha256sum datums/us_nga_egm96_1.tif
sha256sum datums/us_nga_egm08_1.tif- No
eval,exec,pickle,subprocess, oros.systemcalls in the core package (src/egmtrans/). The tool uses only the standard library (urllib,hashlib) and GDAL's Python bindings to read and write raster files. - One fixed-width text codec, no binary parsing of user data beyond it.
Raster data is read and written by GDAL. The 3,428-byte DTED header (three
ASCII records of fixed length and layout, STANAG 3809 / MIL-PRF-89020B) is
read and written by
src/egmtrans/dted/header.pyfrom a field table inschema.py: every read is a bounded slice, every write is a fixed-length field checked for length and printable ASCII, and the encoder refuses to overwrite a file that does not carry a DTED data record after its header. The elevation records are read and written byrecords.pywith numpy slices of fixed length: every value is range-checked and cast to an integer before it is encoded, and a DTED file made from scratch is written under a temporary name, verified (header, records, checksums, and GDAL reading it back) and only then renamed to its output name. The optional index and profile are read with GDAL (GeoPackage),pyarrow(GeoParquet) andtomllib(TOML); XML sidecars read during an index build are refused when they declare a DOCTYPE or entities, and are parsed with entity resolution and network access off. - No credentials, API keys, or tokens of any kind, in source or at runtime.
- No telemetry. The tool does not send usage data anywhere.
- No dynamic code loading. No plugin system, no
importlibof user-supplied module names.
Runtime dependencies are pinned to permissive licenses only: numpy
(BSD), scipy (BSD), GDAL (MIT/X), numba (BSD, optional), tqdm
(MPL-2.0 / MIT); the optional index extra adds pyarrow (Apache-2.0) and
lxml (BSD). See pyproject.toml for the version floors.
Please report security issues by email to terrain@nga.mil with "EGMTrans security" in the subject line. Do not open a public GitHub issue for exploitable findings until after a fix has been published.