diff --git a/README.md b/README.md index f3dbf6c..8e839fd 100644 --- a/README.md +++ b/README.md @@ -1 +1,21 @@ -This repo requires pre-commit hooks installed. See the [instructions](https://github.com/uktrade/github-standards/blob/main/README.md#usage) for information of how to install these +# uktrade/.github + +This is the [`.github` repository](https://docs.github.com/en/communities/setting-up-your-project-for-healthy-contributions/creating-a-default-community-health-file) for the [`uktrade`](https://github.com/uktrade) organisation. It holds organisation-wide defaults that GitHub applies automatically to any `uktrade` repository that does not define its own. + +## What's here + +| Path | Purpose | +|---|---| +| [`SECURITY.md`](SECURITY.md) | DBT GitHub Security Policy — inherited by every repository without its own `SECURITY.md` | +| [`.github/pull_request_template.md`](.github/pull_request_template.md) | Default pull request template | +| [`templates/SECURITY_CHECKLIST.md`](templates/SECURITY_CHECKLIST.md) | Security checklist to copy into a repository root | +| [`workflow-templates/`](workflow-templates/) | Organisation [workflow templates](https://docs.github.com/en/actions/using-workflows/creating-starter-workflows-for-your-organization) offered when creating a new Action | +| [`docs/`](docs/) | Step-by-step setup guides referenced from the security policy | + +## Contributing + +Changes here affect every `uktrade` repository, so raise a PR against this repo rather than copying files elsewhere. + +This repo requires the organisation-approved pre-commit hooks. See the [github-standards instructions](https://github.com/uktrade/github-standards/blob/main/README.md#usage) to install them. + +The code security diagram (`assets/code_sec_workflow.excalidraw.svg`) is an SVG with the [Excalidraw](https://excalidraw.com/) scene embedded inside it, so it renders as a plain image in `SECURITY.md` while staying editable. Edit it with the [Excalidraw VS Code extension](https://marketplace.visualstudio.com/items?itemName=pomdtr.excalidraw-editor), which reads and writes the embedded scene directly. diff --git a/SECURITY.md b/SECURITY.md index d25e879..ae4af21 100644 --- a/SECURITY.md +++ b/SECURITY.md @@ -1,193 +1,211 @@ -# SECURITY.md +# DBT GitHub Security Policy -## Summary -This policy explains how the public can responsibly [report vulnerabilities](reporting-a-vulnerability), and how DBT developers must protect [sensitive information](handling-secrets) and follow DBT’s required [security controls](security-controls) when working in GitHub. +## Summary + +This policy explains: +- how members of the public can responsibly [report vulnerabilities](#reporting-a-vulnerability) to the Department for Business and Trade (DBT) +- how DBT developers can follow [secure development practices](#secure-development-practices) +- how DBT developers can apply DBT's required [security controls](#security-controls) in GitHub --- ## Reporting a Vulnerability -If you believe you have found a security vulnerability, please submit a report via our HackerOne [form](https://hackerone.com/2680e4cd-0436-42a5-bd2a-37fd86367276/embedded_submissions/new) +This section is for members of the public and external security researchers. DBT staff should instead report vulnerabilities directly to the Cyber Security team. + +If you believe you have found a security vulnerability, please submit a report via our [HackerOne form](https://hackerone.com/2680e4cd-0436-42a5-bd2a-37fd86367276/embedded_submissions/new). Please include: -- Where the issue can be observed (URL, IP address or page) -- A brief description (e.g. “XSS vulnerability”) -- Safe, non‑destructive reproduction steps +- Where the issue can be observed (URL, IP address or page) +- A brief description (e.g. “XSS vulnerability”) +- Safe, non-destructive reproduction steps + +**Scope** +- In scope: digital services operated by DBT, including repositories in the [`uktrade` GitHub organisation](https://github.com/uktrade) +- Out of scope: denial of service, social engineering, physical attacks, and reports from automated scanners without a working proof of concept **Disclosure guidelines** -- Do **not** share vulnerability details beyond DBT and the asset owner -- HackerOne accounts are optional but allow updates -- You must agree to HackerOne’s Terms, Privacy Policy, and Disclosure Guidelines -- NCC Group triages reports within **five working days** -- DBT Cyber assists with coordination, but the asset owner is responsible for remediation +- Do **not** share vulnerability details beyond DBT and the asset owner +- HackerOne accounts are optional, but allow you to receive updates on your report +- You must agree to HackerOne’s Terms, Privacy Policy, and Disclosure Guidelines +- DBT’s Cyber Security team assists with coordination, but the asset owner is responsible for remediation + +**Safe harbour** + +DBT will not seek prosecution of researchers who act in good faith: stay within the scope above, avoid destructive testing, and do not access, modify or retain other users’ data. --- -## Handling Secrets +## Secure Development Practices -These requirements apply to DBT developers. +These requirements apply to all DBT developers. -Information on secrets and their management can be found [here](https://dbis.sharepoint.com/:w:/r/sites/DDaTDirectorate/Shared%20Documents/Work%20-%20GitHub%20Security/Github%20Security%20Framework/Guidelines%20and%20Policies/GitHub%20Security%20Standards%20v0.6.docx?d=w022dea8105074e36af5450797083c297&csf=1&web=1&e=SR5out). +### Handling Secrets and Sensitive Data -Instructions on what to do in the event of a leak can be found [here](https://dbis.sharepoint.com/:w:/r/sites/DDaTDirectorate/Shared%20Documents/Work%20-%20GitHub%20Security/Github%20Security%20Framework/Incident%20Response/GitHub%20Repository%20Incident%20Playbook.docx?d=w9ba04ffa4a7c4ff38faaaf12ff030c94&csf=1&web=1&e=yZF5dO). +Leaked secrets (API keys, tokens, passwords) are among the most common causes of security breaches, and personal or otherwise sensitive data must be kept out of GitHub just as carefully. Sensitive data includes operational details — such as internal hostnames, IP ranges and security thresholds — that would make DBT systems easier to attack. Developers must: -**In summary, developers must:** -- Never commit secrets or sensitive data to GitHub +- Never commit secrets or sensitive data to GitHub - Use secure storage for managing secrets -- Ensure no secrets appear in PRs, logs or config files -- Follow incident‑response steps immediately if a leak occurs +- Ensure no secrets or sensitive data appear in pull requests (PRs), logs or config files ---- +The [GitHub Security Standards](https://dbis.sharepoint.com/:w:/r/sites/DDaTDirectorate/Shared%20Documents/Work%20-%20GitHub%20Security/Github%20Security%20Framework/Guidelines%20and%20Policies/GitHub%20Security%20Standards%20v0.6.docx?d=w022dea8105074e36af5450797083c297&csf=1&web=1&e=SR5out) (DBT staff access only) explain what counts as a secret and how to manage secrets securely. -## Security Controls +If a secret or sensitive data is pushed to GitHub follow the [GitHub Repository Incident Playbook](https://dbis.sharepoint.com/:w:/r/sites/DDaTDirectorate/Shared%20Documents/Work%20-%20GitHub%20Security/Github%20Security%20Framework/Incident%20Response/GitHub%20Repository%20Incident%20Playbook.docx?d=w9ba04ffa4a7c4ff38faaaf12ff030c94&csf=1&web=1&e=yZF5dO) (DBT staff access only) -DBT uses several processes to strengthen the security posture of our GitHub repositories. +### Handling Vulnerabilities -Use this checklist to ensure your repository implements these processes: +Vulnerabilities can enter through your own code or through the dependencies it relies on. Several GitHub scans guard against them: -- [ ] **Create or update `SECURITY_CHECKLIST.md`** - See: [SECURITY_CHECKLIST.md](#security_checklistmd) +- [CodeQL](https://docs.github.com/en/code-security/code-scanning/introduction-to-code-scanning/about-code-scanning-with-codeql) analyses your own code, both on pull requests and on a scheduled basis +- [Dependabot](https://docs.github.com/en/code-security/dependabot/dependabot-alerts/about-dependabot-alerts) flags vulnerable dependencies already in your project, and [Dependabot security updates](https://docs.github.com/en/code-security/dependabot/dependabot-security-updates/about-dependabot-security-updates) raise PRs to fix them automatically +- [Dependency review](https://docs.github.com/en/code-security/supply-chain-security/understanding-your-software-supply-chain/about-dependency-review) flags vulnerable dependencies a pull request would add before it is merged -- [ ] **Review the CI/CD overview** - See: [CI/CD Overview](#cicd-overview) +We are also investigating IDE scanning and non-GitHub native code security scanning solutions. -- [ ] **Set up the pre‑commit hook framework** - See: [Pre‑Commit Hooks](#precommit-hooks) +Any alerts these scans raise must be triaged, not ignored. Fix the vulnerability, or dismiss the alert with a documented reason (e.g. false positive, not exploitable in this context) -- [ ] **Set up custom GitHub properties** - See: [Custom GitHub Properties](#custom-github-properties) +Alerts must be resolved — fixed or dismissed with a reason — within the timescales provided in the [Vulnerability Management Policy](https://static.workspace.trade.gov.uk/documents/CYB.07_-_Vulnerability_Management_Policy_-_v.1.0_20251127162547.pdf) (DBT staff access only). -- [ ] **Apply the DBT GitHub security policy** - See: [GitHub Security Policy](#github-security-policy) +Do not discuss unfixed vulnerability details anywhere public — vulnerability alerts are visible only to users with write access, but comments on PRs and issues in public repositories are visible to everyone. -- [ ] **Ensure a `CODEOWNERS` file exists** - See: [CODEOWNERS](#codeowners) +### Bypassing Security Controls -- [ ] **Review GitHub Safety Tips** - See: [GitHub Safety Tips](#github-safety-tips) +Some GitHub security controls can be bypassed by repository or organisation administrators. This should only happen in exceptional circumstances and not as a substitute for fixing security issues. -- [ ] **Review Repository Access and Governance** - See: [Repository Access & Governance](#repository-access--governance) +When a control is bypassed: -- [ ] **Review the Pull Request template** - See: [Pull Request Template](#pull-request-template) +- The justification must be documented as a comment on the PR +- Any resulting security risk must be understood and accepted +- Follow-up remediation work should be tracked and completed + +--- -- [ ] **Review branch protection rules** - See: [Branch Protection Rules](#branch-protection-rules) +## Security Controls -- [ ] **Review push protection** - See: [Push Protection](#push-protection) +DBT uses several processes to strengthen the security posture of our GitHub repositories. The diagram below shows where some of these controls apply as code moves from your workspace to GitHub, following the secure development lifecycle principle of “shifting left” — catching issues at the earliest possible point. ---- +![Code security workflow](/assets/code_sec_workflow.excalidraw.svg) -### SECURITY_CHECKLIST.md +### Security Checklist -Create `SECURITY_CHECKLIST.md` in the root of your repository if not present. Copy the checklist and update it as checks are completed. +The security checklist turns those controls into concrete steps to confirm for your own repository. Copy [`SECURITY_CHECKLIST.md`](https://github.com/uktrade/.github/blob/main/templates/SECURITY_CHECKLIST.md) into your repository root and work through it from top to bottom, ticking each item once you have confirmed it. Its items follow the same order as the detailed guidance below, and each says who can action it. The result is a visible record of your repository's security posture for your team, reviewers and auditors. The Security Checklist must be refreshed at least once a year, using up-to-date documentation and noting the date last checked. --- -### CI/CD Overview +### Contributor Controls -Review the GitHub CI/CD Overview which summarises the controls DBT has in place to strengthen the security posture of our GitHub repositories. +Actions each contributor takes for themselves. -![CI/CD overview](https://raw.githubusercontent.com/uktrade/.github/refs/heads/main/assets/CI-CD%20pipeline.svg) +#### Security Training ---- +All internal contributors must have completed the following free courses in the last year. Download the certificates where applicable. Choose the language that you are most familiar with. -### Pre‑Commit Hooks +| Course | Time | Notes | +|---|---|---| +| [Snyk Learn hardcoded secrets lesson](https://learn.snyk.io/lesson/hardcoded-secrets/) | ~20mins | Reinforces the Handling Secrets and Sensitive Data requirements above | +| [Snyk Learn: Security for Developers](https://learn.snyk.io/learning-paths/security-for-developers/) | ~4 hrs | 16 lessons going deeper into specific attack techniques (injection variants, SSRF, prototype pollution etc.) | -DBT requires all contributors to use the organisation‑approved pre‑commit hooks before committing. A GitHub Action blocks PRs where the hook has not run. +For those who want to go further, the [PortSwigger Web Security Academy](https://portswigger.net/web-security) offers free, in-depth hands-on labs across the full range of web vulnerabilities. -For more information and setup guidance please refer [here](https://github.com/uktrade/github-standards). +#### GitHub Safety Tips + +Internal contributors should review the [GitHub Safety Tips](https://uktrade.atlassian.net/wiki/x/n4AEKQE) (DBT staff access only) to understand how to protect themselves when coding in the open. --- -### Custom GitHub Properties +### Repository-Level Controls -DBT uses custom github properties to enforce branch protection rules and run organisation level github actions. +Defences set up within the repository itself. -Manage custom properties: -`https://github.com/uktrade/REPO_NAME/settings/access` +#### Pre-Commit Hooks -**Mandatory** -- `reusable_workflow_opt_in` - `true` -- `scs_portfolio` - The portfolio associated with your CSC. If your portfolio is missing, this can be added by raising an SRE ticket. +Repositories must include a `.pre-commit-config.yaml` that runs the organisation-approved [pre-commit](https://pre-commit.com/) hooks, and each contributor must install them locally. The hooks use [Trufflehog](https://github.com/trufflesecurity/trufflehog) to detect secrets and [Presidio](https://microsoft.github.io/presidio/) to detect sensitive data. They run on your machine before a commit is even created — the earliest and cheapest point to stop a leak, since anything that reaches GitHub must be treated as compromised. -**Optional** -- `is_docker` — for repos that build Docker images -- `language` — all languages used by this repository should be selected, and github workflows will run with dedicated checks on that language. +As a backstop, a GitHub Actions workflow (applied via the repository's custom properties) re-runs the same scans and blocks any PR where the pre-commit hooks were skipped locally. ---- +For more information and setup guidance, see the [uktrade/github-standards](https://github.com/uktrade/github-standards) repository. -### GitHub Security Policy +#### Repository access -DBT has introduced a new organisation-wide GitHub security policy that applies the required security checks to every repository. New repositories get this policy by default, but existing ones must have it enabled before they can be made public. Over time, this policy will fully replace the old one across the uktrade account. +Review repository access and ensure all users have the appropriate level of permission. Access must be granted through GitHub teams and not directly to individual users. -**You must be an organisation administrator to apply this policy** +Review people with **Admin** permissions to ensure access is justified, as this role can modify repository settings, manage access, and bypass certain repository controls. -To add the new security policy, follow these instructions: +If a user no longer requires access, they must be removed from the relevant team by contacting the SRE team or raising a PR against the [`uktrade/terraform-github`](https://github.com/uktrade/terraform-github) repository. -1. As an organisation administrator, navigate to the [security config page](https://github.com/organizations/uktrade/settings/security_products). -1. Scroll down to the **Apply configurations** sections, and enter the name of the repository to be made public in the filter input field -1. Use the checkbox next to the results list to select all repositories being made public, then use the **Apply configuration** button to select the **Default DBT security** configuration -1. A confirmation modal will appear displaying a summary of the action being made. Click the apply button -1. In the repository that has had the new policy applied, navigate to the **Advanced Security** page in the repository settings. At the top of the page there should be a banner message **Modifications to some settings have been blocked by organization administrators.** +#### CODEOWNERS ---- +Repositories must include a [`CODEOWNERS`](https://docs.github.com/en/repositories/managing-your-repositorys-settings-and-features/customizing-your-repository/about-code-owners) file. GitHub automatically requests a review from the listed owners when a PR touches their code, ensuring changes are seen by people who understand their security implications. -### CodeQL for Fork‑Based PRs (Optional) +#### Pull Request Template -The default DBT GitHub Security policy does not currently support scanning PRs raised from a fork of a repository. -If PRs from forks must be supported, switch to **Advanced** CodeQL to generate a `codeql.yml` workflow: +A [pull request template](https://docs.github.com/en/communities/using-templates-to-encourage-useful-issues-and-pull-requests/creating-a-pull-request-template-for-your-repository) pre-fills the PR description with a standard checklist. PR review is the last human check before code is published, so the [DBT template](https://github.com/uktrade/.github/blob/main/.github/pull_request_template.md) prompts reviewers to look for secrets explicitly rather than relying on automated scanning alone. -1. Open the GitHub settings page, and navigate to the Advanced Security section using the left hand menu -1. Scroll down to the Code Scanning section, under the Tools sub-section there will be an item for CodeQL analysis -1. Click the ... button next to Default setup text, then choose the Switch to advanced option from the menu -1. On the popup, click the Disable CodeQL button. Although you are disabling CodeQL, there is still a branch protection rule in place that blocks a PR unless a CodeQL scan is detected. Disabling here will not allow PRs to be merged -1. The GitHub online editor will open to create a new file called codeql.yml in your repo, and the contents of this file will be prefilled with the languages CodeQL has detected in your repo. You can modify the contents of this file if needed, however you must leave the workflow name as `CodeQL Advanced` -1. Once happy with the workflow file contents, click the green Commit changes button to trigger a PR to merge this into the main branch -1. Approve and merge the PR with this workflow file. Once merged, the CodeQL scan will perform an initial scan that can take a while but you can track the progress by viewing the Actions tab for your repository +If your repository does not already contain a `pull_request_template.md` file, you will inherit the DBT template as a [community health file](https://docs.github.com/en/communities/setting-up-your-project-for-healthy-contributions/creating-a-default-community-health-file). If you are already using your own template, copy its Reviewer Checklist section across so reviewers are still reminded to check for exposed secrets: -### CODEOWNERS +``` +## Reviewer Checklist -Repositories must include a `CODEOWNERS` file: -https://docs.github.com/en/repositories/managing-your-repositorys-settings-and-features/customizing-your-repository/about-code-owners +- [ ] I have reviewed the PR and ensured no secret values are present +``` -### GitHub Safety Tips +#### Custom GitHub Properties -Internal contributors should review the [GitHub Safety Tips](https://uktrade.atlassian.net/wiki/x/n4AEKQE) to understand how to protect themselves when coding in the open. +DBT uses [custom GitHub properties](https://docs.github.com/en/organizations/managing-organization-settings/managing-custom-properties-for-repositories-in-your-organization) to enforce branch protection rules and run organisation-level GitHub Actions workflows. They describe what kind of repository this is, so the organisation's automation can apply the checks relevant to it — if they are missing or wrong, your repository may not get the right protections. -### Repository Access & Governance +View or set custom properties under **Settings → Custom properties**: +`https://github.com/uktrade/REPO_NAME/settings/custom-properties` -TBC +**Mandatory** +- `reusable_workflow_opt_in` — set to `true` +- `scs_portfolio` — the portfolio associated with your Senior Civil Servant (SCS). If your portfolio is missing, this can be added by raising a ticket with the SRE team -### Pull Request Template +**Optional** +- `is_docker` — for repositories that build Docker images +- `language` — select all languages used by the repository, so the organisation-level workflows run language-specific checks -If your repository does not already contain a pull_request_template.md file, you will inherit the DBT template by default. If you are already using your own template, you should add this section to remind reviewers they should be ensuring no secret values are visible: +#### CodeQL for Fork-Based PRs (Optional) -``` -### Reviewer Checklist +The DBT GitHub security configuration does not currently support scanning PRs raised from a fork of a repository. Fork PRs typically come from contributors outside the organisation, so leaving them unscanned would create a gap in coverage. -- [ ] I have reviewed the PR and ensured no secret or sensitive data is present -``` +If PRs from forks must be supported, switch to [**Advanced** CodeQL](https://docs.github.com/en/code-security/how-tos/find-and-fix-code-vulnerabilities/configure-code-scanning/configuring-advanced-setup-for-code-scanning) — follow the [step-by-step instructions](https://github.com/uktrade/.github/blob/main/docs/codeql-advanced-setup.md). + +--- + +### Organisation-Applied Controls + +An organisation administrator applies these centrally, and they cannot be weakened at repository level. Verify they are active rather than configuring them yourself. -### Branch Protection Rules +#### GitHub Security Configuration -An organisation ruleset has been created to apply a minimum set of branch protection rules: +DBT has introduced an organisation-wide GitHub [security configuration](https://docs.github.com/en/code-security/how-tos/secure-at-scale/configure-organization-security/establish-complete-coverage/apply-custom-configuration) that applies the required security checks to every repository. New repositories get this configuration by default, but existing ones must have it enabled before they can be made public. Over time, it will fully replace the old configuration across the `uktrade` organisation. -- A PR is required for merges into the default branch (usually main) +An organisation administrator must apply it — follow the [step-by-step instructions](https://github.com/uktrade/.github/blob/main/docs/github-security-configuration.md). + +#### Branch Protection Rules + +Branch protection stops unreviewed code reaching the default branch — the version of the code that gets deployed and that others build on. An organisation [ruleset](https://docs.github.com/en/repositories/configuring-branches-and-merges-in-your-repository/managing-rulesets/about-rulesets) has been created to apply a minimum set of branch protection rules: + +- A PR is required for merges into the default branch (usually `main`) - At least 1 approver is required before a PR can be merged - Any conversations on the PR must be marked as resolved -Organisation admins and repository admins have been added to the bypass list for this branch protection ruleset. +Confirm the default branch protection policy ruleset is applied under Settings → Rules → Rulesets. + +Repository administrators may add additional rules to their own repositories, but cannot weaken the organisation ruleset: where rules overlap, the most restrictive rule applies. For example, a repository ruleset that drops the required number of approvers to 0 would have no effect, while one that raises it to 3 would apply. -Repository admins might decide to add additional rules to their own repositories. It is not possible for repository admins to add their own rules that reduce this level of protection. As an example, a repository admin could add a ruleset that drops the required number of approvers to 0 but that would have no effect as the organisation ruleset would take precedence. They could add a ruleset that sets the number of approvers to 3, and as this is not reducing the organisation ruleset protection this would take precedence. +#### GitHub Secret Protection -## Push Protection +The DBT GitHub security configuration enables two complementary features. [Push protection](https://docs.github.com/en/code-security/concepts/secret-security/push-protection) blocks pushes containing high-confidence secret formats, stopping them before they reach the repository's history. [Secret scanning](https://docs.github.com/en/code-security/secret-scanning/introduction/about-secret-scanning) covers a broader range, detecting secrets already committed and raising alerts in the **Security** tab. Both can apply [custom patterns](https://docs.github.com/en/code-security/how-tos/secure-your-secrets/customize-leak-detection/define-custom-patterns) for DBT-specific secrets. -Push protection is required for all repositories using the default DBT GitHub security policy. -DBT also defines [custom secret‑scanning patterns](https://docs.github.com/en/code-security/concepts/secret-security/about-push-protection). +Confirm both features are enabled for your repository under Settings → Advanced Security → Secret Protection. If you need additional custom patterns, raise a ticket with the SRE team. + +#### Vulnerability Scanning + +The DBT GitHub security configuration and rulesets also enables the features described under [Handling Vulnerabilities](#handling-vulnerabilities) — CodeQL, Dependabot, Dependabot security updates and dependency review. Confirm these are active on your repository. + +--- -You should confirm that push protection is enabled on your repository. +## About This Policy -Please raise a ticket with SRE if you need additional patterns. +The [DBT GitHub Security Policy](https://github.com/uktrade/.github/blob/main/SECURITY.md) is defined as a [community health file](https://docs.github.com/en/communities/setting-up-your-project-for-healthy-contributions/creating-a-default-community-health-file), so every `uktrade` repository without its own `SECURITY.md` inherits it automatically. Do not add a `SECURITY.md` to your own repository — to suggest changes, raise a PR against the [`.github` repository](https://github.com/uktrade/.github) instead. diff --git a/assets/CI-CD pipeline.svg b/assets/CI-CD pipeline.svg deleted file mode 100644 index ba382fd..0000000 --- a/assets/CI-CD pipeline.svg +++ /dev/null @@ -1 +0,0 @@ - \ No newline at end of file diff --git a/assets/code_sec_workflow.excalidraw.svg b/assets/code_sec_workflow.excalidraw.svg new file mode 100644 index 0000000..c5ea6d1 --- /dev/null +++ b/assets/code_sec_workflow.excalidraw.svg @@ -0,0 +1,2 @@ +eyJ2ZXJzaW9uIjoiMSIsImVuY29kaW5nIjoiYnN0cmluZyIsImNvbXByZXNzZWQiOnRydWUsImVuY29kZWQiOiJ4nO1963LbSLLm/3lcbobnb1x1MDAwYlOVdT9cdTAwMTFcdTAwMWJcdTAwMWLypW23b2r57vVcdFx1MDAwN0VCXHUwMDEybYqkScqyfGKe4TzL/tvn2Vx1MDAxN9hX2ExSXCJuXHUwMDA1oCCSXHUwMDE2JZGK6ekmgVx1MDAwMlDIzC/v+V//aLXuTc9H8b3/aN2Lf3ba/V533D6791x1MDAwN33/I1x1MDAxZU96w1x1MDAwMf5cdTAwMDSz/55cZk/HndmRx9PpaPJcdTAwMWb/+tdJe/wtno767U5cdTAwMWP96E1O2/3J9LTbXHUwMDFiRp3hyb960/hk8j/pny/bJ/H/XHUwMDE4XHJPutNxlFxcZCfu9qbD8fxacT8+iVx1MDAwN9NcdK7+v/C/W63/mv1cdTAwMTN/aVx1MDAwZo76dFH2x+U3w1G705ue43ecJd9cdTAwMWWNh6ejp93ZXG7/ufj2cIzXftrFL1x1MDAwN6f9/uJrPPboeFx1MDAxME8mmYVcdTAwMGZ7/f7r6fnscvi0eJv3XHUwMDE2v02m4+G3uOzXg+HpoPso9VxmyVx1MDAxZJyOuu1pTHfAjVx1MDAxNc5cYqm45mrxe783+Ja/vf6w8212yiHuaJzcQzz7XHUwMDEyjOPcabv4/uJFvVx1MDAxY1x1MDAwZWavh3PLlHXcufxcdTAwMTH4o1Z88W1v8lx1MDAxMPd96rlSj76i22j3k4e8pFx1MDAxM7zjOPn2J11cdTAwMTGkiyTXi49Z/EyvaVx1MDAwN5SLgFx1MDAwYqmNUFay5L7Oet3p8exFWlx1MDAxNykrks/ikOO4d3Q8nT92ZIUtLjJ/NVx1MDAwZoZ9JCa8vX92XHUwMDBluirmqZfT7nwj6lx1MDAxOHSTY+LDQ314mH+97y9vJ00og+5cdTAwMDWhZF5Rb9CN6dHvtVmyymjYS9MwfZJ/ayWUNvuPxb//51x1MDAxZt6jcU94hHtcdNZcdTAwMDKAXHUwMDA1XHUwMDAzTU/XXHUwMDExY8xcdTAwMWEmgVlwMn26jFx1MDAwNFx1MDAxM9ZZzZEglJAmYDlcdTAwMWI5YGBcdTAwMTlSl1x1MDAwMCvSy9lIM2OcXHUwMDAxgcsy7VTAckgxRkojnMYzMjfHIUJcbsdVrHRKaiZlwHImklopXHUwMDEwXHUwMDA2d8yAzaxnXCJcdTAwMDCJwoI7iYcoXGJ5Wlx1MDAxMSmlJW67XHUwMDA0h1x1MDAwZpdeXHUwMDBmeIRrOGct50xcdTAwMWJrXHUwMDAy7lx1MDAwZomXXHSBL1x1MDAwM/dcYp8r87ygkLC5dXgpg0xcdTAwMDBcdTAwMTCwfUZFwlx1MDAwMD6uUM7hWen1XHUwMDA0i7hQxtHOMWeVXHUwMDExXHUwMDAx64nIaMfwNFB4TmY5XHUwMDE5SXxLTmrNNFx1MDAxN1x1MDAwZUJcdTAwMWVXRkZaY1x1MDAxOFNcdTAwMDZfSmY5iz/hXVx1MDAwYjCGg1x1MDAwM1x1MDAxZLKciZyVVuNr1FJChlx1MDAxM6SImKJNwF/psUNoXHUwMDBmXCKJXHUwMDE0jFx1MDAxY8ClQbmUWc5EeHPWaVx1MDAxMFx1MDAxNnmDXHUwMDA38ZlcdTAwMDYphMFXXHUwMDBiNlx1MDAxMe30UcTCwjhpXHUwMDE1in0tw1x1MDAxOIMjTFx1MDAxOIOyXHUwMDBlxXxmNVx1MDAxNTmNr1x0+ZVry41cdTAwMGJaXHLZXHUwMDBihDZKXHUwMDEyg6SX0yxcdTAwMDLDXHUwMDE1cjVSsjNcXOqgh0XeRDbXzCphMlunZYTbL1x1MDAxZEORg6827EXgK0B4MFrYXHUwMDA0mWaL2chcdTAwMWGHMkpcdTAwMDBcdTAwMDcwNoQnbCRcdTAwMDTHl+CQ7sBkqFx1MDAwZembO9wxQVx1MDAxMlVIXHUwMDAxQTSMh1x1MDAxM59cdTAwMWKLzJnZOiRIlE3azVx1MDAwNLPEl1x1MDAxMsZhXHUwMDEymUdwusVcZlx0o6DHyyiHb1x1MDAwYvlBsVx1MDAxMH5VXHUwMDExV6hKoFx1MDAwNHdS6Ix8wnfEmZDWoWg3lomQm0NcdG6MZlx1MDAwMolLc55ZzrFI4t0jjeBtO1x1MDAxNFx1MDAxMEHSk6MwwVtjXHUwMDFhWdNllkPRgFtgNVxuiJlcdTAwMDBcclx1MDAxMu7coWBcdTAwMTTSIS+JzN45XHUwMDE0rEjejjMkXHUwMDE2blRcdTAwMTiHXHSnkP2RvVx1MDAxMWQyy+HGRYLEMPJcdTAwMDNcbmxcYmMxpi3KTck4Vyy3nIm04PikXHUwMDAyNEowXGJjMUFcdTAwMGaCqK9QscqQMedcdTAwMWOJUqFowrcuNEJJXHUwMDEwkzFcXExKblCeSJVdT0eAXCJcdTAwMWTFk1wiOndhwlx1MDAxOIFcdTAwMTGxXGaVXG6QWejhwFwihSSOolx1MDAwYlnayZD9MyQ2mFx1MDAxNlqhJMiRMmqWkZVcdTAwMDafwThwXGZ1hSBGQyVFXHUwMDAzc1xuqY9ln1x1MDAxN1C6Klx1MDAxNMco9lGNRjhcdTAwMGJiNT3bONRcdTAwMWZQXHUwMDFjZJZcdTAwMTNcdTAwMDLVXHUwMDBlxHWSe/jYIXpcdTAwMTRqXHUwMDAyXHUwMDEy9TIhXHUwMDE5ckbubVxigyiM2otcdTAwMTSGId6GvFxcgfSApFx1MDAwN3RcdTAwMGYsq+ShZI1cdTAwMTjyXHUwMDFhvifUUTTwkPXwXHUwMDBlcJPEhVTOLoeEaVx1MDAxNKqlKCecQVxcXHUwMDBm4lxyhH+nXHUwMDEwXHUwMDE1XHUwMDE0Q0U0s55iKHRQXHRlXHUwMDAwXGYlo1xy4VxyVFx1MDAxZfBlXGJH0oXnWFehwHZcdTAwMWNhUyEpOWSTgPXw3VwirVpShFM2xXw5NFqcXHUwMDAyUs2A4cOHiFx1MDAwMlx1MDAxZaGCjGJcdTAwMDPRXHUwMDA3tans7WlUKfH+XGK3XHUwMDExOlEzXG5iNUZcIkXSXHUwMDBlIVx1MDAxM2fXQ6VcYrVtyyRcdTAwMWVcIlWYVlx1MDAwNjOgRcVcdTAwMTBPyXKagVxiUHU3tLNcbjXeME5DgYzqtkNZhFx1MDAxYVN2PVx1MDAxZCmiJ4PCguFLXHUwMDBiWFx1MDAwZXFLIN3hrlx1MDAxM65lXHUwMDA1i2WkKuBqqDAqx4NsXHUwMDAy1INx55AvhGNZ1Yfji+eo/FjUY1x1MDAxMHhcdTAwMTFUXHUwMDAylpNcdTAwMTHRXHUwMDE1Pq/CtyFy6yFXXHUwMDBiYm5cdTAwMDDET1x1MDAxMWRi2IgjPCNEXHUwMDAz8WZ2PYfaXHUwMDAywp0xVuKvNkRJLjOh5+tZtD+sNfPNXHUwMDEzLkRcdTAwMTRYgknccYVcdTAwMDa9Mlx1MDAxOe1cZlxywVxiX1x1MDAxNVxuXHUwMDAxXHUwMDE0j1xi8SHbp9BcdTAwMWPF94vKq9JZXHUwMDAzXHLpXHUwMDBlIVx1MDAwNa+CVFx1MDAwNFx1MDAxY0VViCRAoOHIm1x1MDAxYVx1MDAxNWFkgax9xlwi0qZmulx1MDAwZvJcdTAwMWJcdTAwMGZhXHKNJlx1MDAwMSc4w1N4VvBcdTAwMDFXyDeoVWqtiM5DXHUwMDE4V6JWgsCAZlx1MDAxM4opl1tcdTAwMGVfXHUwMDE03jaSkWFAUixoPbRtOIo9zfFccmY4XHKtwIhcZktS0Vx1MDAxMDzQNFxielxcXHUwMDAyVVx1MDAwNPGZXHKZ3T4gwpSaLEFcdTAwMDGEyUFvw6F4N/jMXGJCPEN7qO2iqY/whMpcdTAwMGKq0WgvXHUwMDA3XHUwMDExXHUwMDBi0lx0miT4yPhaVHY9vHmLliBaSWjrh6jySMr4YpHZZ1ps1kRcdTAwMDPJI0ZcdTAwMWGBRPGNakbI3dFcdTAwMGJcdTAwMTSo71x1MDAxOUC5orNvV+KtI97iViD3XCLqhayHklx1MDAxYzFcdTAwMTWllFWoYWTfhnT4qkCjwsJJwoRcYlx1MDAwMlx1MDAxNPN4XHUwMDA3KFlcdTAwMTA2TM53gSDJUC3SiI9IXHUwMDAwQeYyaixkXHUwMDFioKjH+3BZXHUwMDEwXHUwMDA3hVJcdTAwMDLvSlslkY5C7GXUp5BOXHUwMDExzTTZd5CVK1x1MDAxYVDZXCKDhlx1MDAxM1DpXHUwMDEwk5T0PWU5oiQ+j+PZ29Nor+KF0MxFXCJAXHUwMDFlXHUwMDBlQ0nJydJBjVx1MDAwMLX2jFKA3IX6MsPbR6JcdTAwMTTGhoCkIatcdTAwMTRcdTAwMTXc+VxyZmlcdTAwMGb3Qlx01FeQ+lBMiFx1MDAxMLlX4Vx1MDAxNMy7SOtWYys7OeWO/EfurHv99mT6YHhy0ptO4+5cdTAwMWW5SPPO1Mm0PZ7e71xyur3BUf63eNAt+WV21u54PDw7jttcdTAwMDVcdTAwMTc/nlf622jYPz+aucOn49N49u2/5z/e3rCD0GhhyeSlNFx1MDAwZjugXHUwMDAwQEhcdTAwMDWeLJJcdTAwMGI8IH1rZN7E3ZeKO/BUyKMu7vBrOIi/nLQ7xz38/357kHbmV1x1MDAwNSFcdTAwMDB1XHUwMDEyvD0gqMF/5oNcdTAwMTCaRYvf6J/Jc1xchiFcdTAwMTBUUHIujklcIiyNg1x1MDAxMNNxezBcdTAwMTm1x/hiqlx1MDAwM1x1MDAxMYeHhyYuvPCrXHUwMDA1XCJcdTAwMWWvKVx1MDAxMlG2LUufvJVXW3l18VNWXikyobljy8grRXoo2seFKOiluLLSkIvNecVV4j2uXHUwMDE1V+P4ZDiNQ0VURihxhmaoTn2Sqy5Co1wicTklclxire6I7KTFp0xcdTAwMTD97mgoX1c0VGRcctDGJ1x1MDAxNHaskbxofPZcdTAwMGVKvWzYS5NcdTAwMDWOdI1cdTAwMTZcdTAwMTJcdTAwMDKyrDXAd0yUdYFcYi1I1dZcdTAwMDJcclx1MDAxNUlcdTAwMGLV31x1MDAwNNlcdTAwMTWZJVBbV478NWieUFxip3ZcdTAwMDVcdTAwMWRljUNkzYicieSW4lx1MDAxNFx1MDAxYaldXHUwMDAxolxcNNEhyXPykki6i3qvWpSLbkqKR6JtQClcdTAwMGVaS1O7XHIqklx1MDAxOSVcdTAwMWVccq1cYo1b1J/VLJ5Ze1x1MDAwYibKXHUwMDA2k4QgX1x1MDAwNjmrXHUwMDA1XHUwMDFhz/g+a3fBRFplV2BcdTAwMTHQXHUwMDAzkO+JsjVqzTBcdTAwMTVlrWBcdTAwMDGKvFxiaKJTyM3pXHUwMDAw72mEu53+ZElcdTAwMDNYhGRlUVFDmSlcdTAwMDLoU6DZXFyxXHUwMDFlJ29cdTAwMWVcdTAwMDVcdTAwMDI5vmW0vOqpVaMtlF2CU+TJUFjCalx1MDAxNkCtSO/ZN02OJSeJXFxcdTAwMWPacjbgJlxmcml2XHRcdTAwMWU5Q/5cdTAwMTDUoIHcNlx1MDAwMVx1MDAxYuOyVp4z+PJQR8FnoDhfreRBNZalP1l3ilx1MDAwM9wnRVx1MDAwMVxmlCNcdTAwMDFcdTAwMTEqmSN/1IwjO3f7XHUwMDAwUlBAXHUwMDA0zpDcSX+yj2dnlKAtXHUwMDA3lFxuLoCbcv4ritvahVgztS5cdTAwMDQkLJm+m6xcdTAwMDfBiGhm6lBkXHUwMDE06n11uJmZ01FMO0VudVx1MDAxNJDOXHReu8BcdTAwMGWPrM3wQdbholx1MDAxMVx0wGg+XHUwMDBmrtY7SHZUlPO1Klx1MDAxNylcbpAgc4KtXHUwMDE3mEjCNreAjIzjylxuqSRcblx1MDAxY17rMcMlco5cbsUoyIlcdTAwMTJcdTAwMGJcdTAwMDRD6qtcdTAwMGZR42PkXlxmOcZcdTAwMTR+XHUwMDE4OVx1MDAxZHW9226HvLhcdTAwMTmyy5KNZFx1MDAxMa6CJlx1MDAwNaXpsPqNRfR0meWyfjuU6SSPuVx1MDAwNYrCXHUwMDA3ZLlofE/lZCh4REl6XHUwMDA0s3iHpj7QmLWMQEdcdTAwMTLfXHUwMDE3XHUwMDA19Yxy9S5YXHUwMDFk2axwz67GI6NR9uCCpFvXXHUwMDA3XHUwMDAykYdyKU8oXHUwMDE3pZFKcFx1MDAwNE5Ezdrd2aG3U8FcdTAwMTacjHVJbkV8dbjh9Vx1MDAwNIVEnKVJiq2jXHUwMDE2XHUwMDAxTEl8X6bee4ZkLbP3lFtcdTAwMTB1XHUwMDE1i9RJIT+rXHUwMDE1hFx1MDAwMI7NRtFcdTAwMWP5zpWwlH2FpkX9NiHV5VwiNVwikrjFTuFcdTAwMDPhdtdHMVHDykbeKEgqXGI2XHUwMDE0Jy95PSVcdTAwMDOSauaTvSMrkZXJOOFKclef7VZ4JEORVOFcZnmQ8IFqX7WpXCJmTvlcdTAwMDLkymeIgVx1MDAwNFx1MDAxYrVcdTAwMWJU/da5dlx1MDAxMbKZXHUwMDEzyG7Gslx1MDAwMNLOXHUwMDEzXCLXaMVJkqxcdTAwMGVcdTAwMTU5cPVZXHUwMDAwyFx1MDAxYrJcXFx1MDAxNPGZp1xuzV9ltJK6fsN38uzKlaL4XHUwMDBlxcGZQaFWXHUwMDFmqkflK0fJKPFcdTAwMWRcblcjKMomRH3AdSdcdTAwMWKwlTpcdTAwMDLUslFCk1+Qq3q9SeeAj0vU/aVcdTAwMGJXnHBcdTAwMWZEXHUwMDA1XHUwMDE0c4FcdTAwMGaJTMUooK5cdTAwMTCTa3dcdTAwMDW3QFYwhkDG4YIyYpFHtFJcdTAwMDGWSFx1MDAxNiU4oGrlOOrcXHUwMDA2tVRcdTAwMTZEy0qVglx1MDAwZVx1MDAwN6A0LoNcdTAwMTaBQFx1MDAxOV1cdTAwMWZcYiRNoVxcsUPNXHUwMDFkXHUwMDExXHUwMDE48ZpS8EKyelVcdTAwMTVcIuJORSCRe4FcdTAwMTJcdTAwMDedXHRcYqNGtlx1MDAwMrA5Q1uWmIRRaFZcdTAwMDTs/k5O16NcXC+Kv3NcdTAwMDaU/Cjq8212SPVML0HZZ1x1MDAxNoWaJXBEIVmv3eW1XycjiilcdTAwMWJD9iw9SMBcblXauHVcdTAwMTRKR85FgmTa1CdcdTAwMGXs5O1cdTAwMDNLeY+oQCtKbkZcdTAwMTiq35Vqg8WiqctcdTAwMTll0lhcdTAwMDTp+mxEUcl0hqx5VKcpN05q5Lt6XHUwMDFhZ1BcbiaGRYayMlHhZ4JyiOtXyy6gNerFxL6O0lx1MDAwN4yt3Sw0cstvR/NIXGJSQWaZKfXJfdUmuELjXHUwMDE3SdKhXGZFtFx1MDAxMaY+42in2keg0Fx1MDAxNGaUK0h51lwiYO938l5cdTAwMGJJTi3kXHUwMDEzoFx1MDAwNH9cdTAwMWSw3zt5z4mESKJcdTAwMTVcdTAwMGWgUJF1xoaYQznvXHJ+IWe+Ycpbqt/knaL/KGJcdTAwMTRcbnOUI0pZjlx1MDAwMduaXHUwMDBifKDFi6jhkPZcZopJW4/PqJlmOCxcdTAwMTfVp9QyaVx1MDAxNKWAXHUwMDE4oMqEejLM+vU4pVujkFd8lohcdTAwMTNixOtyUS8jtDZccuI+bY+uz1nIuzopmVxu7WVQXHUwMDE2XHUwMDA0vuVaus07W1FDQ1x1MDAwYspcdTAwMDGgkaiB2Ybe3m10aCOiQ4u38F+pd7NcYq+0aT/upV/bRTxcdTAwMDZ/+NLrxq/jzulcdTAwMThcdTAwMWbxdac9+DJcdTAwMWHH85f2ZDj8Nrm3OOnff/gvMl/p0zvx/Mfp45fi0/nZq+/fdlx1MDAxZnfuu+/ZS2bvJlm3QDf5XHUwMDAwl1x1MDAwNKF0koJ5hVx1MDAwMFx1MDAxN1x0UuRcdTAwMGZXXHUwMDFl4Vx1MDAxMoKBMiB4/lx1MDAwMPxccnlz8W1dhCu3e4tfL1x1MDAxZn5cdTAwMWN3pnNcdTAwMTJb/DRcdTAwMGJ3WVQg0yH3JLo1j8hzloKHJOJFXHUwMDE1MKnTXHUwMDEyQZWKw3OePvVKQS+I7SFrXHUwMDE29Epo5PLZL9W1fydbtoiFwb1bz4xL80kl//X6T4/5+zf69f7z0cf3Z8O/h2+/n6+K/1B9YcIuw3+orFx1MDAwM5e2mO+SVOJKK1x1MDAxNVryvlx1MDAxMDPaaMFcZnjUm1x1MDAxZZ9cdTAwMWWgRFx1MDAxYsfTvfFwivxGi4QyXCIwl40775BPx1nN1OWnmFxmXHUwMDAzSSZdwneUN01Vo4vPhrOguCssON57+lI++vr4x97HyYtne5/Onu/LnVx1MDAxNbGKplx1MDAxMrfE+L5cdTAwMTKrSFRNQVx1MDAwMitlXHUwMDE11NW0kkr6itaFtMGsMsK72o+/n8aT6etp+8iTl1GGVip1d0RcYqCppjj1XHTlXHUwMDExJ1wikf6YXHJnXHUwMDEyefuZJEhpTJHOl7nE3Z3J2Vx1MDAwMH0xaP3Mml9GcTzej3/04ka8iIjDjVimfYSTXHUwMDAyyNWhSllRWS6dTNWmpVjRhqdxZrcwXFxpTEmaXHUwMDE5qaXYspLvXHUwMDA0XHUwMDA1XHUwMDA0U5+kOHlD+U7dfr5LMdeC3L9048P2aX96f9xcdTAwMWV0jlegJlby1kog0EhuyO2+XHUwMDA026GmiConYkN531x1MDAxNsrqYJol1dfphERcdTAwMTVcdTAwMGWB49mTN0O/gopIISTlkuREUzTU/FxcyFRcdTAwMDQsqUODJVNcdTAwMTPXzoX69nPh5bufxj+nZeA0a/bzZ9yeno7jOWdcdTAwMTacKP2DfjNcdTAwMGZcdTAwMDdcdTAwMTXoLZPCq41cdTAwMDM0r0ypg4PqMIVG3dLLMqi0XHUwMDA280zYXHUwMDE2XHUwMDE02SlcdTAwMGL4c1x1MDAwNJNcdTAwMTRcdTAwMTfM90CSusA/XHUwMDE0XHUwMDEx49yT3ctKWVx1MDAwNp9V2oNKlvGWXHUwMDFlZNlcdTAwMDa8bJNzKq4yeTf7oLlzXG6E1NjFmmL4i0ZiM9a7N+tPNuZfXHUwMDBl2t2UKCSOXHUwMDFidk7p4XhkXGbV7FJqXHUwMDAzXHUwMDAzmVx1MDAwZT/fO2qPZi8zkopcdTAwMWGQMKUlyKSrSVwiSjI+3bJbKSOk1M2wiFx1MDAwMd6GkEpQs1x1MDAwYurwUrydjD9NKVu8nUaOZKSWXlx1MDAwZVxyXHUwMDEyyeiSL+P+wfAsYZ6txKz1Mf9+aWm0XHUwMDExXGZJp1RaUuidMlx1MDAxZvzCMiklXGZcdTAwMTKWNVx1MDAxZfYgQWmYi1JNISpcdTAwMDQli0SqnutcdTAwMTZcdTAwMGLKzIPmzlm3oIRgQalSYeFLyVx1MDAwNJFV+CuqsNQ+y6jLVIiGgnI6Pj087MfHwyNcIiTfvewwit9cdTAwMDJlXHUwMDFjU3czp9N9MVx1MDAxNmJ7jXJxdytcdTAwMTer5OK8XHUwMDFlKqtHpV0rXHJcdTAwMDWjXHUwMDA2NL1SjuYreFx1MDAxZlx1MDAxMSedY4qXml6oR1wisiutfd5H28D0XG54/lBcdTAwMWTSRqlcblWiXHUwMDE1yYtcdTAwMGVIXHUwMDA3kVx1MDAwMU987LZcdMbsc+ZOWV4ulsfoy8SU74VmdTnOjaGuPVaixFx1MDAwNM6KQkpGSN+zLnJaSaNhnTLr4VZmVcmsUtfvNUirmVx1MDAwNaCUK62zxytp6kfFfHF9bcJcdTAwMWL8Vju9w1Q4Klx1MDAxYlx1MDAxM1mPrU9QWTKJ74Cgyj5n7pT1KXA14lxiVSZObZJcZt5cdTAwMWKg0kRaU7U4wmMvc8BKXHUwMDE0uKtnL1VcbqpHW0FVJajK/NxccuXUzKGd6qt0XHUwMDE1h7YzM0IpXGKhSzElXHUwMDA1eUyUN4ykbDOdqta9XyWkgFx1MDAwMY/SSa3JtWfiXG5cdTAwMDCtUJTcWpG/midFXHUwMDAzXHUwMDBi6aVtpFx1MDAxOJpcdTAwMWKMa8OENlx1MDAxZVOUU4dzZ4EqKy01XCK9ZYKtdFx1MDAwYuizU3j63yH0JrhQuTNNXCI0XHUwMDE5XHUwMDBlXHUwMDEybVEqeUyX7FxcXHUwMDFhiS5DXHUwMDE1xlx1MDAxNMNcdTAwMDRBuqAv3pKzV6l+mJpdXHUwMDFizpWF4q1ApFx1MDAxOTVcdTAwMTil/mNSKLkoIVqHLvjnVsRW6oIlkcrGqiBcdTAwMTJcdTAwMTRcdTAwMTfLxFxmXHJzlGCWiszlNUHqXHUwMDE4jcDOvVx0ZqlcdTAwMTBEkCZYXHUwMDE3oa2UsYLJKD23oVRcdTAwMTG0UXo+xO1VXHUwMDA0M8+ZO2WNiqAv8p2Silx1MDAxYVx1MDAxNJeGUWGg4CpcdTAwMTWSKXecXHUwMDA1ycCymH7q0ij5pGbAXHUwMDE0dVqUXHUwMDE5c/7y4mtcdTAwMTR6j7dCr0zoeeKe01x1MDAxNaU8XHUwMDA1hFRcdTAwMWJIVImKXHUwMDFjJG2GryBRpbFcXKOSV56EoYVcdTAwMTVcdTAwMWPh2qe1ylSwNmh4TubJw1OgQGUzXHUwMDExd0xyv0mWfHLMQojq8pQngI5ScaVcdTAwMTT9Z7dz2IlNM1x02izZ4sltSrZYJ6FyXHUwMDA0dUB6k+XdXHUwMDE2UWF01I3dXHUwMDE3zpNcdTAwMTDuXHUwMDA18rJ/gVYzwuOCTK2hTjSo7zNJtV4qS7TaRJ5QXHUwMDFlqlx0XHUwMDE3SVx1MDAxZFx1MDAxNOtOp1x1MDAxNS+oWIqkoUGBjjk1YZbLalx1MDAwM8nuXHUwMDFjXHUwMDBlXHUwMDA309e9X3Pez3z7Z/uk16cnSb6ebVx1MDAwMl7hOW3Z58HhfNNaXHUwMDA3Of5cdTAwMWWOe0e9Qbv/JuxwWnW33zuiXHUwMDE3d6+Dd1x1MDAxZI/vpd/ptIenL1x1MDAwZTjpdbtpidHBW233XHUwMDA28fhprdyhjnRPXHUwMDEygzWVRppw6NN7aVx1MDAwNvIrSu3T6XA/nsx37YZcdTAwMTWddduT43j1XHUwMDE4mlx1MDAwZodfXHUwMDBigC5zoeCKud+A0k5ZbcHKgmS7lH2KXHUwMDAzY1BcIvpEuOirTe8qrVx1MDAxNZDUrEJ6WsWW4jW13kud4rOBKuA7wFxi+uchP1SHrlx1MDAxOXyXtHH8a4vTgVxuJS0hZFxuOnKkinDlLFx1MDAxOOWz0KVcdTAwMGXPuSlcbphcdTAwMTCIVsbSTFx1MDAxNMrHsIIxk6NTpaNcIqW6WbtcdTAwMWZUL6xcdTAwMTCOWlx1MDAwMlx1MDAxNlx0XHUwMDE1eFSe1rtcdTAwMWF7fUmEfvrwUWuC+zQgs7VcdTAwMTSY/UetXHUwMDE0j0tFTFxiXHUwMDE4P7vlYLxcdTAwMWV7NptCXHUwMDE0XHUwMDAyxY3T2jL30ahYYZ015cJplY48XFylppxcdTAwMDOXTMpyl6N2klx1MDAxOVx1MDAwNsWq85lAXHUwMDBiN5BLXHUwMDEyverrg2jmVnlROfeU6aFcdTAwMTjMVJQnsiWB3qXkXHUwMDE5tXE/LO+g3Fxiep/fXHLoXVx1MDAwMa1SsMQyV17IXHUwMDA2TtHsOG//XHUwMDAzlUqbakaqgdBrZy2jhXVa0jw3mYNersBjXHUwMDFlXHUwMDFi6mk1m9pcItLR2TDTmFx1MDAxZHJcdTAwMDPta1x1MDAwNt43i736j8+DyaxifVJcdTAwMGXA1UevXHUwMDE0iMvkTVxiXHUwMDBlv9ji8PzTXGKHXHUwMDExOye9bm9YQOHfXHUwMDAwZE7QPCqnSvVyzpzmXHUwMDAypYNcdTAwMWbHkvNcdTAwMDKaoyyecmUolnLuJiCmMian8YiHzUGxl1tcdTAwMTRcdTAwMGJEMS5cdTAwMWPNwy3P9nNcdTAwMTRFXHUwMDE2uohzhGK8QWeELDtcdTAwMDZhmKZ6XHUwMDA0Tlxy7lxmTT7MXHUwMDEyqbZeXHUwMDA3L6fxq9zRbDvpN1x1MDAxZjdcdTAwMWbF9i72aoZKg0lv2vtcdTAwMTG38NW3y6Es4JSV4plf7oSg2as7jmZVTYGoP/kyKVx1MDAxYtxRU0HLVblWqo1cdTAwMDSae+/3XGKFa6WeerMgnlx1MDAxNryyKVx1MDAxN/PYT3hcbnVLYlxccVx1MDAxYc1nm7qENoWndzqzXHJrXHUwMDFkZ2vUPKxcXHJkhoP78eG0gn+nw1FcdTAwMTnzZlx0KoBl97Yse/FTcbBcdTAwMWRcIk7Ku3oln4eaXHJuL9VcdTAwMTUtSIpVcp+qqF3DnIBgRqXBpCZcdTAwMTdTpSFcbsVGXGaCS2pcdTAwMDRrXHUwMDA0dSH3XHUwMDFijlDehGiNzJlq3VLDnPfjw+E4bnWG3bg1jtud43jSmlx1MDAxZdO/j4aIpcPxeTm7Njn3ulx1MDAxOPjva2Xgi+9aXHUwMDA0XHUwMDFhb+KTUVx1MDAxZlnoy9GlRba57H3Ze2ypNpk0mUaCKFewldHgrOU+N1x1MDAxMTRoeJTsbZG/PcPgVK5sXHUwMDA2rM8j5M3zUS4qXHUwMDBmXHUwMDE1ilx1MDAwM1x1MDAwYoe6JtPnIG5cdTAwMWbGZbz828ue7VLHq/pO8kZFjqX+sqdHun6Or0FcdTAwMTWIp/4yK+iofshcdTAwMDbqfZGB1J/KLVx1MDAxMTBMWFx1MDAwYrzV9F9mXHSDtlrtXHUwMDEyNExIpv7yS9S3jiZHRHpcdTAwMDWZyXKledD1XHUwMDBmolBMpp8jv0T90GxpovRmZtuMq/qpcmiDpl8nZE+PoH6quHBRmqR4boWAYc5cInfTUT1cdTAwMTFcdFZByEFcdTAwMTdcdTAwMDWdJWTR/MlcdTAwMDGylCxcdTAwMWHuPbdZMlaN3z4qPFx1MDAxOSrOr1x1MDAxMECCnGWpWDVnXHUwMDA0prNUnF9cIoBcdTAwMWRcdTAwMTlkydg0XHUwMDE2XG40cSj9QvMr1EsmXG74l1x1MDAxMnKIcHRccsWxrZLGMqpcdTAwMWZcdTAwMTFheVx1MDAxNVxyiyhgjkNOXHUwMDE4Q25cdTAwMDVeP9KxUlx1MDAxNiOU1/KRdlVEXGZR/Zw2rapoXHUwMDE4LfLap9CVglx1MDAxOH+sW0Dl5HBcdTAwMTZcdTAwMThr56EoUUW9LKqfPlwis2KYWZ1bon5cdTAwMDRKbt/wlNozcmI4O1x1MDAxNSbooqJSXHUwMDBlhzy5gCpcdTAwMWGu3XqwVVx1MDAwNFx1MDAxY/DqISeEZX6FevKDvFx1MDAxMDaNeYDrKlxuXHUwMDBl4UOek8G2uTDIy2CVW6FeIMlcdTAwMWNcdTAwMTVnXHUwMDFmI0QoNlx1MDAxNMK3ZuJFYoUtrO326qJPi425i6YzSFx1MDAxYdRjoTRcdTAwMWJcYlx1MDAxOFCZo/R2uFx1MDAwN1x1MDAxN97hPrW5gZmNVkZZ51x1MDAxOOA3noxcblx1MDAxZNG4KMVcdTAwMTSnoYrCk/tTXW9cdTAwMTCLtr1u1/Xj3vTJ6UFrb//zoOhiyLvDKlx1MDAwZl5lXGKqsVx1MDAxM+zgjnuxXHUwMDE3sqRZXHUwMDFhRapDy6rKXG7qelSt5iohXHLVXHUwMDBignT1Yow6PtBA39JOXHUwMDE1VFx1MDAxMYuwn65LvqJcdTAwMDewqs1XaS1Bzlx1MDAwZihcdTAwMTL944ZX+3XuRlx1MDAxMshcboBWXHUwMDBioCmWXHUwMDE18zGcYlJIXHUwMDAxviyQRkCbkSZhSIv6Mc2ZomF1lJiYoVbJ0ui5qPKnOaXALcKuVU74cpUqXHUwMDAzxlx1MDAxYlHlt4db1Vx1MDAxYefZuVx1MDAxMCz2XHUwMDFltdpUXHUwMDBmn1hcdFx1MDAwMdzuXHUwMDE2cOefRoA7h6qXbcrguSxcdTAwMDZ4cFx1MDAxY3e+TZrVXHUwMDEyrHcmXHUwMDAxilx1MDAxZIn28jJjeWhMrJNcdTAwMTWBb23wXHUwMDAyToM3MqbCcbF8R1x1MDAxYmRMQjb9XGZUYLDMbkxSZHw38FBowUWqXHUwMDEy5CpcdTAwMWRbQVmjmSo1PFx1MDAxMYdmg2y8dmeDsrpKXlx1MDAwZkFHK1x1MDAxOc3JsFx1MDAxMvQsOSpHpFr7YrpcdTAwMTJcIupDQU1cdTAwMWOpiVrqflPKXXbia/mkNVx1MDAxZdPfZlioVEw3+Y/Pg4fxKEayXHUwMDFmdM5b8+5Yn1x1MDAwN1x1MDAwZobd+O/ntWZrg1x1MDAxNVaKsSFcIipcdTAwMDRyXHUwMDBmt5A7/zSC3M7pZDo8udz3d228Rptgs2HZXHUwMDAwp95zS1x0XHUwMDFlTlx1MDAxM99YukVgXvBw6jiuizNJZsIgPFx1MDAxYrvsia9cdTAwMGWIXFzzzNiRSlA0XHUwMDE0Wkw+4HLv+9ow8uhcdTAwMGVgpFx1MDAwNFCCUWX4XHUwMDEypGpcdTAwMDTNXG6xtlx1MDAxNFwiXHUwMDE148Kg4eZzalxiXHUwMDE1nmdcXMGbYVx1MDAwMKlcIoRytFx1MDAxYy1cdTAwMTWg8zzR0uxvkUxt8/g+XHUwMDA0RNKgqmpn5ejeupdgsNyITORcdTAwMTmutEaLLOPPg1macVx1MDAwYi/calx1MDAwZrqtz1x1MDAwM/xpfDqYg2E5ZObXaYUts1LcrJdjIah5fMtRc01dZy47oG6WXaqpKeUyNVGGIWahUCif10BIT3OSPKKtQT52oYFsY8xcdTAwMTXaU6i3XHUwMDBlI3R1rV16d1x1MDAwMGBng1KZUktcckrl5JGV1pQ3XHUwMDBiXHUwMDA0VFx1MDAwNqVgxVqf2V2El5Cm2DhcZlFFpFxmOVaZdjTRKUuSlke+XHUwMDEyXHUwMDFlVPikXHUwMDA1SzV9QvGU8yQsXHUwMDBlulx1MDAxMV1dcON3LuzEwcxSm1x1MDAxNY3PkCeg20uzs1eKkkVJXHUwMDEzgopfbzkqXpW7hTKWXHUwMDE5o5dcdTAwMTmzXHUwMDAxkoHiaX0zx9yC8lx1MDAwNay2XHUwMDA17ifVOpy3i9NEglg8N4ucg6ejXHUwMDE4M1x1MDAxMen/qMtcdTAwMWKhXHUwMDA1WE9qw+ZX5V0wZDs/dKTEPVQ47rpcbnq+XStvLtSxe/Nmknvj4TSebc3+aT+e3IxcdTAwMDQlgVx1MDAwMGbYUu5cdTAwMWFhrHbSlFx1MDAwNjA4KM2p3bXPXGK24f3RvbtcdTAwMWNS5Vx1MDAwM5xlXHUwMDFiv+Cjb6t8rnL8tspnvsS2ymexwrbKZ1vlU7fEtsrncoVtlc+2ymdb5ZM+pfaMbZXPtsonLZC2VT6bVOXTX0eVz922p1xygLNOp6JcdTAwMWF5l7dW0jnubYXDeXhQ2b/NQf5v4DLbs1xuXHJFn0nNXHUwMDA1zVx1MDAwMFx1MDAwNOXU1Vx1MDAxYdFtUuXPfLs+XHUwMDBmRotccmuNsy6IXHUwMDEyf1n9iddaXHUwMDExdHLHPdxcdTAwMGK506xcIiiZ1LeyUp2y4X+1y/++uLJQRqT6ZF7B528lXHUwMDE4Y12pdKNrOGmNN6DXpFx1MDAwZahiQG1JaLngKFxcRVx1MDAxOdBvzt1cdTAwMWHcjdDy8oTIKVx1MDAwMis4VHR95ZppVFO97Ym5XHUwMDBiXHUwMDFmcZORXHUwMDE1QehKjj9pXHUwMDFj09JJLlm2OK2k3EdFnEluXHLj3HDbuNxnI1wiUXu4U1x1MDAxN7nGXHUwMDE11T6+g1Zb7OORXHUwMDFkIVA63ELp/NNcYkq7szTz9sEwqLY2wbrUeWWjT5fCOkNj9Zap7aFcdTAwMDbMRlx0w0pjY4iFQkhtfSVcdTAwMTRNJEyyXHUwMDE14WAnXFxcIvnmdVx1MDAxMopyl5NcZs7kppqkMafKQa5cdTAwMTlcbkd3XHUwMDA0XG6Xp1MujFbck1CfxHCFdKh9eae9XHUwMDAxXHUwMDBmr/XJ8HpcYlx1MDAxNEohXCKLeIYqodBcdTAwMTKySFxihmcylz2J94xFoDRqdlx1MDAwMlx1MDAwZkZcdTAwMTNUXHUwMDE2XHT4hmUue4t0aEevWN/jP3WleOpcdTAwMTNPIXj6fYun809DPE2B4UZZp5uP2Ew5UIbZ0j5cdTAwMTWOMS3AgbfokYVns/ifvzFo355GXHUwMDE14y1aXHUwMDA30qiVjDNcdTAwMDflc3WU1mg9evOtoIF/OC9HwuCaRYJcdGu1RFx1MDAwM9tkidVvuFJcdTAwMGWlcFx1MDAwMIjPXHUwMDA2rD8tevNcdTAwMWJVPJxvVu1cdTAwMWPqsuNWjLde4Vx1MDAxMlx1MDAwMrmTO1x1MDAwZbllnEtTXHUwMDBlgKdNueacS/OwXHUwMDE0uOJcdTAwMWPaRa9cdTAwMDfAS7h0yUS6oj68wcy8tVSDKVx1MDAwN4niP3s7vFi8IFCRpjFJzMl5ufxcclx1MDAxY3Cwe4hcXHW1+Vx1MDAwNlxyTr2ubOjplnMvfiqMXHUwMDE0XHUwMDAyNFxcxXJJzk5YVd6DkUtqlIEs6nNcdTAwMTWnXVwidZxcdTAwMWI2bz6Ys5FXXHUwMDExW5XSRlDdUYpp57OnKaupyOpcdTAwMTBpza1WaPR7S325jVxc2mBm5Vx1MDAwMVxcMZvntFx1MDAxZWyWmW8r+P5cZvetollj7ueVXCJx2PtsXHUwMDA00Vx1MDAwN4xvOf3ipzVwOpXncaZZeadC5CpcctpcdTAwMTlvUb9cYi99rZ91XHUwMDFkzOeG0uQ4V6h2o/lq81x1MDAwM8X8fC51pKWxc7/Ysoy+zlx1MDAwZTjBjD4vwS/n9PzvK2f1wNHlYWxcdTAwMGVbNr/4aVxy3Vx1MDAxZVx1MDAxOSDNO6srRlx1MDAxMlmpXHUwMDFkWtpeM9qFu7xcdTAwMDN6vYbjuXaRMYIpyVxmsW0+MCwj5cFzXHUwMDE2MVx1MDAxNFxu1CBLlVxytb5pkD5u9yZcdTAwMTWQnvt55Xxe17u3XHUwMDE5o6sto1/8tHpGXHUwMDE32lj8K68x5sCs5sLfo6dJg8XKbsuNkFxcS8VQWXfWpjKkqzhcXFx1MDAwMuWHW4En31x1MDAxNp19ilx1MDAxY32UZtM8i1x1MDAxN1x1MDAwZVg5k5e3zm7G3nrL3lx1MDAxNz9cdTAwMTXb1DhtYFx1MDAxOXVdKY70zlVpOqE0jFx1MDAxYua8KN6gZXNVbmUob1x1MDAwM1x1MDAxMyZyRihccrNcdTAwMWOtrNNNWFx1MDAxOSU8s8DuWVwimDXKmVx1MDAxMqdcdTAwMWKumYles4p65U1g7Fnw+fOgNWpPKlKn/UetnMVr02XDONxsOfzip3WEuzi11tC8PNylQCBcXEpvSLZBvKsqylx1MDAxZMzjXHUwMDAybKTALFx1MDAxYeVlLfEy/GZcdTAwMTElRVx1MDAwYrgl2vlJPD6q0M5zP69cdTAwMWW4y1JcdTAwMTWacbW9Vq6++Fx1MDAwZb/9NH5w9uPT60/Cvnnz69vryYfem96Lm1BcZqWFXHUwMDAxnXKaX4X5mVx1MDAwNC1teciMM8FcdTAwMDCc8HreebpcdTAwMTdrXHUwMDFk+3P16+XbXfhgOrt/v3n8fPDtl+j0ijzv7S9iXCLDkiTIkJlI/m4jZtttJPlPXHUwMDE10Cukqr5dLN1tRC7fbUQu321ELd9tRC3fbUQv321EL91tJOD8qm4jZuluI+Zcbt1GzLLdRoIuWt1tJOjJq7uNXHUwMDA09Fxuqew2XHUwMDEy8varu41cdTAwMDSRYHW3kSBGqO42XHUwMDEyxI7V3UZChEJ1t5FcdTAwMTDJVNltJEQ4uobiuLLbXGIs3W2EL91thC/dbYQt3W2ELdttRLplu43gXG7LdVx1MDAxYpG1nYcqu41Iu3S3XHUwMDExXFyiabdcdTAwMTE6pfaMym4jQVx1MDAxN63sNlx1MDAxMvTkld1G6re+sttIyKuv7jZcdTAwMTJEfjXdRkJ4oLrbSFxiXHUwMDFm1nRcdTAwMWJcdFx1MDAxMVx1MDAwNtXdRkJcdTAwMDRSdbeRXHUwMDEwodhQXGLf4m4jXHUwMDA3zK2j3chcdTAwMWS2r51iIIRNJYfky1x1MDAxZICSSrh3xlx1MDAxM0/HzOqs62Fbf43/PHn17M2JOX618+z0cffkIMijRpOaQDuHz8yUsy655sy6dsrbeFx1MDAwNL/VXHUwMDEyb1x1MDAxZTnOOuab7lSdU75cdI1HXHUwMDFlvHr46NX7l4/2X5f70nzHXFxnO5FcdTAwMDO2u3WGX/yU65itnVx1MDAxMZZxlt7Opt0zmOBcdTAwMTRcdTAwMTgu9v5ZxLukkVIo5XOHpWVFXHUwMDFkv8r7oz+fv//0dPS6d/5kdHD05/TBq5NcdTAwMTB+pf5FkbdcdTAwMWN4loomUrnmSYKKjVx1MDAxNFNcdTAwMDLfaemo0lx1MDAwNmGudeaa28y3VbxLqeKXuWCt98Pxt8P+sKKpQd3x15RVfsBcdTAwMWXdcXZe6Fx0jWowhy/Pf43ev4c3k3f2XHUwMDAz++vjg+f61cMmtYyUyWrFUp12mFx1MDAwNUdDjctT3JhcdTAwMDAmtS1WO85O1+G5L5/eiec/Tlx1MDAxZr9cdTAwMTSfzs9eff+2+7hz330vSotsgelFUJyzKJ1ON5NcdTAwMTKyXGLpXHUwMDE2TbNUSdtCMLDci131uIzf7TTPPmfulOWV+FRRZjyn8ouWJ/5M1Zmg65zSw+1QXHUwMDFhoTNcdTAwMWHNXHUwMDE4lNBcYkPGuJR5fO+oPVwiOY22K+qUljmF6qGVl1x1MDAwNlJS8rlcIsuBXHUwMDEygHJcdTAwMTWyKamVqmSP+1x1MDAwN8OzhHJvkWhaa1x1MDAxZbxcdTAwMTaKofiwpdJcdTAwMDOYc/ietfHZXHUwMDA2loU3L/HLylx1MDAxMNOAXHRcdTAwMTVcdOqWpNCyxv/KSZGS8lx1MDAxNlx1MDAxNqFcdTAwMTFhLflmSpSNm5b3PjqdVJScZn9dabS9Ru5cdTAwMDcpXHUwMDE4L36LguE2lYmvpl90jnujL+PTwbR3XHUwMDEyz1x1MDAwYozClVx1MDAwYjRDXGZcdTAwMDOllsqfp1x1MDAxZVxiiN2ufOxcdTAwMDeCXHUwMDA1Q4zwlslcdTAwMThcdTAwMTOuW1x1MDAxNFx1MDAxZvXLXGK3vyggSlx1MDAwN8ZJXHUwMDE1UVx1MDAwN9JcdTAwMDUoZaVcdTAwMDRQXHUwMDBi+qKY4Fx1MDAwZfEu1djI0zhcdTAwMDZk+sR1T+u6cmuFXHUwMDAzsXtcdTAwMTd6K6yErDVNPFdalld/aXA0Ntbbn9I2XHUwMDE56Vrk4Fx1MDAwMMjjVouIg2Y0XHUwMDFmWSsu87RcZkiSXuBa0DWiXCJcdTAwMDPcMKfUbFx1MDAxNqxcdTAwMGb/ZHaVipZI65xJl/22XHUwMDAy//bfvnzdevWy9fHV2/3W+1f7z17v7T54VI6IdcevdjprnfxcbkFJsftuXHUwMDBik630Y5Qzynzrins/T/bljaaZO+SxXHUwMDE0q1+pctxprmRpgjpcdTAwMWHpXHUwMDBlYVT7tOirouTFkzbDSUh7yS+RsSg+wFx1MDAwYoQ3XHUwMDAxXHUwMDA1799cdTAwMDVcdTAwMTRcXFx1MDAwNc1aZVx1MDAxZDOyPCrErSPvkt9xZMKDQl72XGYy/EyBVH2NhTykyn9cdTAwMWapLlx1MDAwNWWPn7558vZ+PYTlj1tcdTAwMWZ0+YVKXHUwMDEweN3/PeC1wbPFayokUpVIV2kzy4RgooggXHUwMDBidjU0cZhJb4WESsU0Qiokanv4VXp7pc31r5PSMynZk1x1MDAxYS302lx1MDAwNyP/bk9v5mh6vuSEgmKyMj+vp1x1MDAxNWcr8fGiyVx1MDAwYlJoZlx1MDAwNDfAXHUwMDFkXHUwMDFhXGI8lfJy4eKlpJXLoTclbt3yq/u7PqZvgFmDklx1MDAxYiTdXHUwMDAwjVx1MDAxOVx1MDAxNoVcdTAwMWLgXHUwMDExTfymsL6W1K5DXHUwMDE0YX91rmTxIFVcdTAwMDdyXHUwMDE3fcnLl3CRcc7ByfL2wlJcdTAwMWGNhre/10KqwVeD9sKTXHUwMDBlSuTTfnBcdTAwMTc0XHUwMDEwJjvvWUhT11x1MDAwZtuxSFx1MDAxOXBcdTAwMTaMtcwq59M3kK8zruSl2mNfWf+AzLdcdTAwMTX6x//97//9//7Pf7fG8dFpvz2et1xuLtdCqo++rpi1ePB4ZfrGnK52ejtHXHUwMDFmf0xe9j7y+z/ax1Lej8WzoNogRkmjVlx1MDAxOY6Siv6ZS4dcdTAwMDBcdTAwMWGhqcE6qZhcdTAwMDPn0WI9WFxiRqNcdTAwMDTUqOSjaemUTE4qyp5VxSvqRU1cdTAwMTFG80rSkMAr82ZcdTAwMTYyLaHaXHUwMDE1XGLLXHUwMDE0JTz1XHUwMDEzQtFyvFx1MDAwNN9cdTAwMTSEXFyG0cFKq63wXHKhT5eX5qtSyUNumVx06Vx1MDAwN9WoXHUwMDBipVx1MDAxMizlwm4gjdenvFx1MDAxNFxicpWazLrSTldcdTAwMDbeXHQtvehcZt8+++vvXHUwMDA3X1//9eBn3zzYmXx4MrpcdJmkK/BzcVx1MDAwNdSTyJQyhFUo45ji3lRS3lx1MDAwMORcdTAwMGZOu2+Go3P25f2zt9/YrttcdTAwMDf45UlNKynUTGNxrlx1MDAxZOKsXHUwMDAyriCAt5WatcdvKzXnS2wrNVx1MDAxNytsKzW3lZp1S2wrNS9X2FZqbis1t5Wa6VNqz9hWam4rNdNcdTAwMDJpW6m5SZWa4q91VGreYftcdTAwMWG0XHUwMDEzmmbwlZrX1HNMWetzofMmg5PbXHUwMDA350/YXHUwMDBmMd7t9s5cdTAwMWV/+9s+OPre/Vx1MDAxMFapiVxuOaexP5xr7VxcbljfXHUwMDBl98b60PKPlGYgOZ1yhcG1m1GqeTqZXHUwMDBlT1qjNrLouMpjXnrgtVx1MDAxNm2mndm3MkB/tfSyOUOctMff4jH/MjhNvEzzV5ZmhcVcdTAwMGb//qNqsYZcdTAwMDMhMtdpPFx1MDAxME8yJ1x1MDAxNFumiIwrpplcdTAwMTWyXCK5gFsmnEi3cU1cdJ5cdTAwMDZcdLGX23zQ7ma6XHUwMDAzXjx83O/3RpN8bjc1VEwnKs1cdTAwMDSNtVx1MDAxMVx1MDAxNFx1MDAxM7qFL6ugPFDyQFx1MDAxYctcdTAwMWVUO/Hyx4QkrZVEKuSfdyM7bXmStFx1MDAxYYQ2Tpb3XHUwMDAzNbP0tOI021x1MDAxOUGG9/z18X1lc37uo0VUK6VLPkW6tJFo2p0gPyR5lUmVZfSZXG6pXlx0IXk5JvL1oGCZRClcdTAwMDfEu41wsDqEXHUwMDBinIOSuUZzdKN+XHUwMDAxsExiXG5aq5JcdTAwMWJRhK5kXGKIXHUwMDAxgb/7ij24SC5cdTAwMWQmSqBcdTAwMTm2aatcIq1cdTAwMWMsslx1MDAwN25cdTAwMDHKPbkjKLc0aVKFtbBSXHUwMDE3zLmkXHUwMDEwXHT1Llx0/jFUXFyE23s+5q+COe2qyfK2XHUwMDAw3tMlXHUwMDAxXHUwMDBmylx1MDAwMVx1MDAwZtZcbnhcdTAwMDUxs1x1MDAwNbzFJ0PzXCJcdTAwMTjwXHUwMDAysFxi+TGVQHhcdTAwMDUsclxuQChXXnlolOCOVF9cdTAwMGbDp+eAhzG8aFx1MDAwNkbO6MhZtshjyzI9XHUwMDAwi8yNXHUwMDAzo1x1MDAxNfoor5/c10mb3EpO9aa8lDiFoVGC6Vx1MDAwMSXL0WYoXHUwMDE44U1VkSXXkbpcdTAwMTVg9GxJMFx1MDAxMuVgJNZcbkZcdTAwMDUxs1x1MDAwNaPFJ0PzenVgROonXHUwMDE3PL3ljUuKhOGo4pU7WcBp0H5+XHUwMDA3XHUwMDFiXlx1MDAwMXj57M2wyPLI5Vx1MDAxYy0g9VxyRKC9u4FAy1x1MDAxM6RcdTAwMDXhrODlY/yAXHTGKY1+VVx1MDAxNFx1MDAxOYxAzkOMipp4eVx1MDAxM01vXHUwMDE47vy9JO7octzRa8WdgkjZ4s7ik6F0s0LcXHUwMDAxppRYJsqtuDacWL3cXGJCfkMjiXk9cjJ8+PblwzdcdTAwMDRcdTAwMWVcdTAwMTZxl+V1gbx+43Bn/47gztJcdTAwMDSJqCVcdTAwMTmaXHUwMDE25S5iXHUwMDBi4Kg+yOuGu1x1MDAwMkGG446PXHUwMDE2ZWT8XHUwMDA1XHUwMDBlN1xmd14viTumXHUwMDFjd8xacacgUba4s/hkKN2uXGZ3jOSWWVhGvURbhsr1VCnuSGWNXHUwMDEy4O3Sw6Epl9tGsFx1MDAwM2BFpF3ix8h63GeFXHUwMDE0N8/0eXMnIGhcdTAwMDW0aVxmmk9girXxiU5kXHUwMDEwgIQp9uu5XCJxXHUwMDA2Qlx1MDAxMI1drKRLQ41cIlx1MDAxMjDy9HS+XHUwMDE5YPR2STCy5WBk11xuRlx1MDAwNTlzXHUwMDFkYLRcdTAwMTDk91x1MDAwNsNpzL9cdTAwMWONNyhlt1xup+a3uzLryFxuo2Gp6Vx1MDAwZlx1MDAxY9VZXHUwMDA3WuryZnJojTBUe1x1MDAwYm5cdTAwMTKS/Vx1MDAxMJ76NH/0RrZcdTAwMTEwV8h+UsjKN1x1MDAwZZjeryNzfVx1MDAwM0l/rZRKPVxumFWq1F8ngFq+OFUg5StRaqjRXHUwMDA03EekKir2Obwh0PRhSWi6hqw8r2zZXHUwMDAy0+/kTis0XHUwMDFhM1BcbiPcSYss7GdO25Q5p71p31x1MDAwMyM+9lTcw57CgyFcXFFbXHUwMDFkK4RcdTAwMDOB/7DS15W0ilmBo1VV3aNh5cz6cUlmfTNGNupcco5a7UG3dXTa67bpdZUycM3hv7c705aNV87GXHUwMDAyIVx1MDAxNom4XHUwMDFjY4FcdTAwMGIjQGlWiOLeI49G+ISOXHUwMDBikT3snl+djZVPXHUwMDE1XHUwMDA0MFx1MDAxMdqPKGtAOlx1MDAwNsLHxlxyJn+pXeqh9nuZ+pOfqYNnd7xAXHUwMDFlPelN4lZvgHfRPe1M8f18XHUwMDFlXGZcdTAwMGZbP077yGTtg16/N+3Fk1x1MDAxOVx1MDAxYk/izjietvpx+1v7qIL3V7Pq7Vx1MDAxNFx1MDAxMbBZXCJicXMlJmh4Wn7hkdah2EtcdTAwMDFMO10+90NcbunwRfBVaPZccjPmlVG3w1x1MDAwNm2vy1x1MDAwNt0w2l+vt4RcdTAwMDNQd/3yNuZG0VxmK1Mk5iuRaqhcdTAwMTGqrI9Kb7BcdTAwMTF6sKRee1xymfJe4bKFpt/JnpxZxawo72jAlbJcdTAwMWGVV+b1ZqaM0zD2XGY3QzU3oWaoZJHiIKhUXHUwMDA3KFBzXHUwMDEzzNDOkuy6XHUwMDFmt/s7NFx1MDAxMqB1iK+S7ricf6uO3WqXN5+FkYk1lEcmXHUwMDE514JzWUzbxFx1MDAxZqVcYu9ccnAhrkNcclAvXHUwMDAz+1xyUG4jQFPYWFx1MDAwMNBK+6ZhbbhcdTAwMDHa9bNzsFx1MDAwMfq0i7fSOzwvWIZcdTAwMDfx4XBcdTAwMWO3OsNu/HnQm+C/XFy0ICpn92XWup3iQGyWOFjcXFyJsbnCkrjl5YvWWkrHXFxpS2FcdTAwMGWKUiPArcLWbFpcdTAwMTAnfb7qXHUwMDFiaGvG67I1N4z014uEqMdpKYqzkFx1MDAxN1x0ZFxc0jhss1x1MDAxYUpcck5cdTAwMTL1XHUwMDA2VG6wqXm4pO56XHJ1cF7Zslx1MDAwNabfyJ2AXHUwMDFhqDValeqpqN6h+WaLZVx1MDAwNzPGXHJvpTDf13BD01lcYjU0XHUwMDA1j6ykXHUwMDFhJ8WFNtwmt7q5hubRksy6N4535opi6zjTN6bAu+VHbrXKXHUwMDFizrxcdTAwMGUkKFbuxFx1MDAwNWb0rDOCXHUwMDBmWaVccs9+vZDToTams6JBkFx1MDAxM/eCS4lSxmlvh8tccrcxj/2cXHUwMDFjbGNcIn/+wJu5jDC2hoeXMUdcbj9+XHUwMDFlTOLBXHUwMDA0XHLFXHUwMDFmcVx1MDAwYsmnfWktXCI3h5mdK17+dspcZrlZMmNxcyWWqFxctSW6VD08XGJOxqYsz7XQjmlcdTAwMDC/r7qhfi+blYdcYkberrI0/Fx1MDAxYmmT9tZlk25cdTAwMThcdTAwMTOsk2aBaYRcdTAwMWPFoDRUj0dcdTAwMTgnXHUwMDA02FXEP2Vw2Yjg1fR6g83Tr0tqvLJcdTAwMWPjZFx0Pq3CPC1cYpwtWv1GRuWc1qBWfmWMyi1NRVx1MDAwMO73XHUwMDFl6fBcdTAwMDHO851ccjZQQUhXyapeU1XbyCFgoqJrpOQylX24uabqtyVcdTAwMTn3cW/65PSgNTqdXHUwMDFjt0Zj3OVZwl05N9dcdTAwMWS/VUFvOlMzYZVcdTAwMTOuXHUwMDFjfblzilvHi0XHRGEyvGfahVx1MDAwNFx1MDAwZjRcXOt42mvColx1MDAwMIqsXHUwMDEzgPfrZiztXHUwMDAx41xyN2H7flx1MDAwZW9swmZzZS9syc+DuTE5Oj3o9ybHcbc1XHUwMDFktuY8Xm+1Xn3F2ykl9GZJicXNlVx1MDAxOKorbNy2XHUwMDAysSOFXHUwMDEzylbMJebKaG2F8+ZkNFX6XHUwMDFiNm7z5edqr8DZcPv0+7rs01xyo/21kiqZp4ZcdTAwMTU7OSXRfcdcdTAwMTmSi11ccqUuk56r1VxyNkrHS+q219DDzStbtsj0O7nTKGdcdTAwMTEoSrlTXHUwMDE4pcD4UaTBtLH5ti6Xm6uVz1x1MDAwZYXZiFr8WKtAXHR3I+zQyZK8emFXptPvzluTTntAhaC15mjdaVt986ZzNTNGXG7k6tLSb1x1MDAxMFx1MDAwMllfeaOpxjTWXHUwMDBll8nY1dZcdTAwMWJNVTZcdTAwMDJwTEhcdMKCTbbjpliiUz+PL5+w21x1MDAxYsxcdTAwMTJsL4Ke3XhcdTAwMTTjP1x1MDAwNlx1MDAxZPzpj9Zw0Nrbn/3SjVx1MDAwZtun/WnrYDZ5rnWFZN4lr3NbpMgtXHUwMDE3XHUwMDE1gikuZEVcdTAwMGJcdTAwMTetXGZnyvibXHKZ8I7LJCqaNmL1JN+GXHUwMDFikuBcIpf5iNxcdTAwMGK4PsPydFx1MDAxZIbl32Omfjz9trs3ePssPv3iztRB98PGXHUwMDAznuTUI8hcdTAwMWEmlqFiNFx1MDAxZq1UTJWP+EJ+sVxm9cOCx4SoRzZDvFx1MDAwNu1biVqRTa3RXGatXFwnc7SsI8Q45lxmgpxgyUz3XHUwMDA1XbtII7BcdTAwMDFcdTAwMTdcdTAwMWFcdTAwMDSTunE+4HVcdTAwMTiip++W1G5/f1fXa1x1MDAwN5ktXHUwMDE3XHUwMDEzsUvEXHUwMDEz61x0fy5GfmplQShvIbeCZvFR0yiBt5hcdTAwMDRYYo1cblx1MDAxYjFcdTAwMDGKcVx1MDAwMIa7wZt6jq7DXHUwMDFh/bEkv+52uz2Ka7b7jS3SXHUwMDA2p95cdTAwMTZ9csvqM5ZyxnDJi3M8koHTXHUwMDA2XHUwMDA0d9yrd0rTzPVklkv4LTNR0Vx1MDAwMNWodHDQTiGr37yE37N12ajT41x1MDAxOXku2Fx1MDAxOFxySHxcdTAwMGaUXHUwMDAz8aPXjbutQZvydPvnrYPz2lx1MDAwMOpaLnL7pFx00bndLFx1MDAxZtfi5kpiqqtrXHUwMDBlv1x1MDAwMkuYMrOshYqWR9xKY5gn6HqveaCqYW/46uTfXHUwMDFiXHUwMDE5XFw9X1dwdcOYYJ00i7qwo0kgZSQr0VwiNmh4rlwi8ze8YXx15u+NXHUwMDBlsv5aUlW+hlx1MDAxZfFeabOFqt/pY1x1MDAwNanAgSkvKzFOamdNMYuQ+NQ1a6BimyT+KlbJqV5cdTAwMTNXQcQ1U4rwUnHlS1x1MDAxMtw0XHUwMDEzV7El+XYvjsetcfyjXHUwMDE3n82iXHUwMDFlXHUwMDE30Y6QXHUwMDFj4Fx1MDAwNqduldJcdTAwMWLO6WC5U0jdpWl5knHjrPJcdTAwMWG1ijerYrWrSlx1MDAwNi4xb4WNnEPFk+pyjfby+Wabt4r7ub5xMvDpYM6/aFPOXCKih+PhyefBQUw250k8PsLvz3rTYzRI41xcPLQ+LXhcdTAwMTVr3z65cfjw6dmr4/u7o2dcdTAwMWZed94+er47evtif/NliORcbpXttL59lTohZDgrmSmdwq6ZXHUwMDEzXHUwMDFhjPNpXHUwMDBi0CApK3Zs77vZ08Pv/b9cdTAwMGWc2vnVefLiXVGejFx1MDAxMabmbzMnVKyKsn6yXHUwMDFkUC5cdTAwMTJuPqN99s+iou+N1JZbpVx1MDAwMFx1MDAxZKXiSrHxz27nsFx1MDAxM5sykVx1MDAwMWmyWIiMxCNx+Zzi4pt/eyXJu3VYq3eZyplcdTAwMDCaPl5cdTAwMTGxlVx1MDAxNPekXHUwMDE5XHUwMDE1XjLXwWQu3lx1MDAxZD7/9mL6fW//w0n/+1+n7/96okxcdTAwMTBsSvBQuKmjcG5UXHUwMDA0wszitb4mXHUwMDEwXHUwMDFjcTVcdTAwMDOaUEr9NFJbqdWB5pVQcD9cdTAwMWVccie96XB83vpX62w4/nbYXHUwMDFmnrUmU6SIcnhcdTAwMGI66ffiVoqdU/2GS/WI31x1MDAwMXPPXHUwMDA3XHUwMDA33+DPh+rn6bvn99WXXHUwMDFm5u3LYe+GXGJcdTAwMDCrU5x5lVxikFx1MDAxMU44z0TdpG7dcWo7qr3+Vlx1MDAxZS5cdTAwMDB+vnP8i/2x996+fbi7i/R//+/R/nI4x1REzaRcdTAwMTZiILnFK+JcdTAwMWMpx/agXHUwMDFh5/JcdTAwMGWvXHUwMDEwnCtTjWEtgHaX6ZlphFx1MDAwNeFKtTZO02dcdTAwMTWgarckOavnz98++37858efe6/ffeR/gnt6f3plPGOijpK59Vh+qX7eXHUwMDFiXHRae+NhXHUwMDA3KVx0wYewYjzs079cdTAwMWTHVU2sXHUwMDAzTrk2wFx1MDAxMlx1MDAxYlx1MDAwMlhHv75+VO/d4U94wiffv5lcdTAwMDe/PpwnvjU84Fvn6duHsVx1MDAxMZ92u592ulx1MDAxZp+8Nfzl8I5IXHUwMDAwp7VwTpU3yrbcgLbgU2iFXG5PX3pcdTAwMWSbh+LFu92HXHUwMDAzuffkr7dcdTAwMWbMXHUwMDE3fvyoKFx1MDAwMIiw6qGMU+yQL9RZmVxuw1RBXHUwMDE5J0OvXFxcdTAwMDRcdTAwMWNYOKx28f6ze1x1MDAxMLdcdTAwMGbjJdBsNOzl48zJv7VcdTAwMTL6mf3H4t//81x1MDAwZu/RYpnDuY6YrjtcdTAwMDVcXCrEdXGWXHUwMDEytWfZKNF/ZmeZ2lNMlPTRm59cdTAwMTJJXHUwMDE1cFZCuFx1MDAxN2fZ+ofCZ3CZs6jReu1ZKkpw8uIsZVx1MDAwM85KQpZcdTAwMTdnXHUwMDA13KGMVHY3XFzEXFztWVwiSizMi7Og/lpcIkpw8eIsUX9cdTAwMTZE+Vx1MDAxYlx1MDAxNPU3yCNcdTAwMGLNL8UjLps/XHUwMDE2i2TzLcSDjGn8umZLNyZccjxI5lx0qp5cZpHCjWhM8nhcdTAwMTBrzl7I7FwiS1C1fMxVpLPUXHUwMDE0XCIwuMqdUi+ZuMxLJkSJ+vcr8pJJRVx1MDAxY2rPgrxwkviUXHUwMDAxZ+WEk1xmoFvO88JcdLm6/losL5xEpOppieWFk1xiuEOXl02ojNe+YZtcdTAwMTdNXHUwMDEwQLU2L5kgMrUnmZxgwnNq707n5VLIhXReLIU8kspLpZDNk3mhXHUwMDE08ppkXiaFUITIi6RcdTAwMTDig7xEXG6hc8hcdTAwMGKkIJbKy6NcdTAwMTDuZXmJXHUwMDE0XCIomqtKZbrYP3Jn3eu3J9NcdTAwMDeXnV33SFx1MDAxZswriZNpezy9j5ZcdTAwMTTlkud+i1x1MDAwN92SX2Zn7Y7Hw7PjuF2wUvC80t9Gw/750UyjJ1x1MDAwYixR3FOm3Fo8L3fZ7tLGMemULJ3KgJdcdTAwMDAlXHUwMDE4909cdTAwMThcdTAwMGKPuk/aL23n7NmD7tM/XHUwMDFm2P2zh0d/dn61r+p54dLVXHUwMDE5XpxS5TRuXHUwMDEySKOUVc4zd+ymRVx1MDAxM/aQUjrncyfLYe9cYv9lXHUwMDFhn4z6lcGEkHOuzTUjN8Q18/ro3Vx1MDAwMZe7U9Z9fM66X6dnT1x1MDAwZb+8/31cdTAwMTKg26b2ZdckXHUwMDAylFx1MDAwNiqOLHW8aCUkaK29npdcdTAwMDb5daOj8de3g69v3+mjXHUwMDFmP8XLh/Hxi6EoXG6AXHUwMDA2kVx1MDAwNGdcdTAwMTB2XHUwMDE3Mlx1MDAwMFx1MDAxMlm0zjhcdTAwMDI/VIduNXFcdTAwMDS5XHUwMDE2NLtmWr5WNOPCOFCKl1x1MDAwN1x1MDAxMqSmQIItluw3pOaXb08m5smbx24ygVx1MDAxZPn96Su+N1JXhTOnalximVx1MDAwYk/x8qaHXHUwMDEx3lwipY9bvcGPeDLtXHUwMDFktaszPStcdTAwMGa+NnxSXHUwMDFigk/jZ93Y7Vx1MDAxZqqHg9HO+Puv81x1MDAxN2+H7viO8DRNXGawSrPy1s94gLRSav94k4SK63iavXn27eXuUWf/z4dn9qtcdTAwMWRcdTAwMWS++CXvL4NQnEUmSVx1MDAxY3WoZi9cdTAwMGJRnYOuink1RMWHh7ppqLthSpdaXHUwMDBict1hKkdcdTAwMGKGXHUwMDE5QFx1MDAwNaSMyI3jXHUwMDE21TSvXHUwMDE2Jl14XHUwMDAw/OPoXHI7/7a39/Pty97H06P92L2yXHUwMDFmr4hb5J6qIW986ZHmaIdRfrP196K6aVbY/ulgQk2c6mpvy467NjTTXHUwMDFigmb3XHUwMDBmXHUwMDFlnXe/n+09fzJ9+fQ7e957sfvC3FxyPkfdXHUwMDEzSNUrV1BBoVx1MDAxMcKs199cIlO1XHUwMDBmdYz+bufZSWf3/GF3/1R+eG6mu8NHT5ZcdTAwMDKzXHUwMDFkKVwiLZLkTbl84lZcYppcdTAwMWRcdTAwMWVcdTAwMWWauPAyV4pmXHUwMDBm1lx1MDAwMWZ3mMiVXHUwMDEyhilXkc5cdTAwMDWCOa2E8JbyNOjrP51cdTAwMWXv/Jq8cf0vvz7tjj9cdTAwMGXUaNhcdTAwMWVdXHUwMDExzXYkr6VvrmRkXHUwMDAx71ByJ4W4XHUwMDE1TsVLmDpcdTAwMWaejmfZxni5TlV2cs3x11x1MDAwNm9cdTAwMGY3XHUwMDA03tovpv2d/uTZXHUwMDAz89f3XHUwMDA3XHUwMDBm33aevf/y+tXmc/5K+kDgR1x1MDAxYleuxlLDclRcdTAwMDaF8SZyumZcdTAwMWRcdTAwMTFVgzZU4Fx1MDAxOfPsr9Gl4TzAcD+s0VKTYenBtE2r0X2+ZI3uRXfjizlcdTAwMWLB3ZBLj799VXV3mKupjFx1MDAwMIBcdTAwMTX9K4tG584wRHTv7C0lwuF8ztTB7aa8PO2vx1x1MDAwNVx1MDAxM0lcdTAwMTQ9wnLcXHUwMDEyJ27efFn1Ysl63NfIo63D4bjVblx1MDAxZIyHbfK24i2mJ8FO/mh9XHUwMDFl0Fx1MDAxYm02o2dlXHUwMDBib2XGLZJcdTAwMTmaMcotMKWaXHUwMDAwMqE1lnPvaC9cdTAwMTGuXGJ8//Li059vnr58+4N14dODl72P02Moilx1MDAwZn+TZGAmgpRcdTAwMGIruZlcdTAwMTlcdTAwMTNRlkFBllxikfV6paopXHUwMDEzWYLHqNxrubZuUerlOuzbO0zbXFwqXHUwMDAzTEhdMZdcdTAwMDdcdFsx6Z1cdTAwMTFcdTAwMDBccrJm3n08+ftk8OHNy+6bXv/055cv00ffe2HgOEuFXHUwMDA2pUFYLcAzrefWdU9Wr5bUglU5yqlcdTAwMTKcuunNkzeZU7VR1vJlKuWp24NS3JU2j3JcZiRcdTAwMThZhKl7XHUwMDE0OlxmT1x1MDAwN3jeffjq+fNH02lbfXk0Ov/14fiTeFx1MDAxYohCoFTyjOezL3hkhdCXn1x1MDAxNMIsXHUwMDE02mx/fmN8IMRolcVcdTAwMDdUeb7A70akvdUh0u0mYC5nSFKse01mXHUwMDE1citcdTAwMDFldFx1MDAwMYuIglNcdTAwMTZZXHUwMDFkXHUwMDA1u97wWfdMvH9w+OY1Y8dcdTAwMDc/9++j4lx1MDAxMIA0XGIxOkI+W/TpVzliNlx1MDAxMd5cdTAwMWWakMw6p31BwptcYjV/L1x0Nb9/YtxcdTAwMTZqSnrqekl7/r7nmcv2XHUwMDAze1x1MDAxNr/+ZY/++it+uf/147PnL1Wqv+5cdTAwMWb+Zecn9/pPj/n7N/r1/vPRx/dnw7+Hb7+fZ69yef025cWH9+11RuD/pF6mlbjmXHUwMDFhmLNcdTAwMTW5NVx1MDAxYVx1MDAwZpCCXHUwMDE10sPpZFx1MDAxM67HTvW30eHH6a8vo4d99/7n6Zve4XNZlC5l0UiOdlx1MDAxYdfJJ1x1MDAxN7kxNkJcdTAwMDGyQLrU3SZ1+J7IpC738Pzullx1MDAxMm/uXHUwMDA2IFxup1x1MDAxNU9ZxlcpWCBcdTAwMWNRspxkXHUwMDE1tVxmRbPcR7KGhzsj/WxcdTAwMWZcdTAwMDKIXFyySFx1MDAxOKmoRVx1MDAxM2N5YtWG4K6SWKlGXG5RXTk8XGb8gzCkiMrjiuyQXHUwMDFiaK9cdTAwMGVcdTAwMTCXXHQpfFx1MDAxZYxOJ2HdPuvPWGlz31x1MDAxYZlcdTAwMTRcdTAwMTRzTOn411x1MDAxMHPcYFY3yKGoXHUwMDAws/R2NmV11HuVsVx1MDAxZdV2wepcdTAwMDJcclx1MDAxZtRcdTAwMTl9uq9h4U0hpoOzzt7zV3///fLs0+6H0bE4mux60lxiStBcdOVcco9cdTAwMTSKXHUwMDFjsNZJliqlOp8jaOSx33w8zY2OyvtCXHUwMDA0pX5CbFx1MDAwZlkzXHK3YbLMwZ1AKiRfS31blyBfJ7SjupryJn0gpVx1MDAwMe2pvZvtmVxi9z6M956+lI++Pv6x93Hy4tnep7Pn+3KnSL9zXHUwMDA1M0u7QspIXCLYWOaU5oJnaFcgylxiXHUwMDA0XCJjnGJoZXoyYljEXHUwMDEx6VCDNFRsp40wvla3NoJZVptyYPBPLaV4XHUwMDA1QNfv7oBSsVx1MDAwYvQpPn+yYEHLb1xcl5ti4HhO23N8m1x1MDAwN99cdTAwMWXGeVx1MDAxNJ1Bd+eUnn2HoeKsjUFBi/Y3kpy16Vxu9HtH7Vx1MDAxMVx1MDAxMcnl7SZcdTAwMDIhU/5bdlx1MDAwM+P4XHUwMDA0IfzPuD09XHUwMDFkx/ezfXdTN4H3QJM0XHUwMDE5U2hRoPJcdTAwMDTCuOI9XHUwMDE0bqFRnTFcdTAwMTJNLye6UzKtk3xcdTAwMWL3XHUwMDBmhmdcdKOtTNYlz3P88s3DL/vn31x1MDAwN50nb79cdTAwMWOKXHUwMDEz9XV0cnJcdTAwMTNcdTAwMDInXHUwMDA2XHJFlWLv5lwi0Vx1MDAxYUZiRpeKRMMoU1xce4fUce7CvVmdr53ex1+vd/dcdTAwMWa++P7i+zP2clx1MDAwZiZPi1x1MDAxMrHY5olcdTAwMDMlXHUwMDA1JWBcdTAwMGW5lHfLZs4qT3JfpampTFQu825ex6fUM17l+IBOLEZFjqX+sqdHOmBcdTAwMDVcdTAwMWVZnvrLrCBDWtygpWYg9adyS9j6m9B0q+m/zFx1MDAxMlxu0bV2XHTlXCIlU3/5JVx1MDAwMrqyKGr3kfrLdPFQOlx1MDAxMlx1MDAwMZ1xqOdF6i+/RH1HXHUwMDFlSU2yUn/Z3VxmOJ9cdTAwMWFEJX+QPT2C+vY5gvojJX88t0J9XHUwMDBiKC5yN1x1MDAxZNVcdTAwMTORYFx1MDAxNYRcdTAwMWN0UdBZQlx1MDAxNs2fXHUwMDFjIEvJouHec5slY9X47XOZpeL8XG5cdTAwMDEkyFmWilVzRmA6S8X5JVx1MDAwMtiRQZaMTWOh4GyGkHl+hXrJ5GRcdTAwMDUhh1xiR9dQXHUwMDFj2yppXGaRqH3/llfRMFx1MDAwZumnlFx1MDAxM8aQW6G+J5iplMWI67V8pF1cdTAwMTVcdTAwMTGzgCZAWlXQsHSRrn1cbl0liHGF2nepcnLYZlx1MDAxN6g9XVRQr7SRqWUhmVx1MDAxNcMs25FLUtPG2iVU/pTaM3JiONszK+iiokpcdTAwMGVcdTAwMDc9uYBcblx1MDAxYa7ferBcdTAwMTVcdTAwMDRcdTAwMWPy6iEnhGV+hXryg7xcdTAwMTA2jXmA6ypVXCKEXHUwMDBmeU5cdTAwMDbb5sIgL4NVboV6gSRzVJx9jFx1MDAxMKHYUFxi3+rOXkfryFG8w6a25pwrlp5Wlc/Zt47RuC1f/i1cdTAwMWHB4ZNwXHUwMDBl4t1cdTAwMWZ/uemjX/3p7vP78budJ6+Hx0VT25eiiGqFNkKhXHUwMDE5rcn5lJ2sxVx1MDAxZK81tVFcdTAwMWEpzUByjVx1MDAwNjv3TlxmqcxcdTAwMWPhsWjb61x1MDAwZZQ9OJ1MhyetUVx1MDAxYtl1PJiUx8dKXHUwMDBmvIY0kVx1MDAxNOumXvadjIEt5E2zrJKsd/bLNDSjpNrZn7l2w4xcdTAwMTKKeoAzfJmMXHUwMDEyiXJcdTAwMDX/ilNzXHUwMDE3k0k4d1Jb4VxuTkByXHUwMDEwNihwL3Nv14fryERicpFPklx1MDAxNTvpNMmbkj3SuysxOaJOuVx1MDAwNHVyLbgxKj0wIN/tjupcdTAwMDM4k4XadaLOXHUwMDA2c1x1MDAwNorsXHUwMDFkhogmUswyKVx1MDAxY0inTS6VUtvIU5OO2jB3XHUwMDAwqIxbIZy3XvVcdTAwMDZlizQtQa04Y6XZXCKl4iZcYiO/bjFy/mmEkZ5cdTAwMDBiXGJO+uPdqXXxhy++tUe4J/vx99N4XHUwMDEyjMZL5HdeXHUwMDE3ylx1MDAwYq2lXHUwMDE2qVx1MDAwNLqrNGVTXHUwMDBl9XNeXHUwMDBl81xcSmVcdTAwMWNn4IN5wcMjeVVB5CWhXtjA6F1cdTAwMDXUb8iMzW93Qlx1MDAwM1hcdTAwMDHlWtTvjODldjFHPVx1MDAwM41nyb2Ey8JcdTAwMGJT/cIrSFx1MDAwYnA0aoQxaVxmOSpTfoBcdTAwMTnVOvBpXHUwMDAxTEZcdTAwMGUs5U6g3S9cdTAwMWPzXHUwMDE0XHUwMDA0VWpcdTAwMDHII0qssKb9SlrA/mzPPlx1MDAwZlx1MDAwZee7VjtcYrru+JVqXHUwMDAwlZIoSFx1MDAwYuhvtYD5p5FcdTAwMTbw/qnb//bi7/HPzvuvvf3Xr89/6uPTRnVcdTAwMTJSgF4qXHUwMDE1ldpboD5e3lx1MDAwMEOg9u2M9llccuBcdTAwMWE406rViapMPlx1MDAxMExH2mRcdTAwMTP4qGdcdTAwMWI3KS9cdTAwMWEvpqJyanhDfZFcdTAwMGJcdTAwMTiZXGJcdTAwMGVlaJlS2XEzk/aoXHUwMDA02prFY7PsRFx1MDAxZVx1MDAxNsl0xVx0XHUwMDFlWevPp+gv2o6LT25YXHUwMDBmZ1x1MDAxMdcmqcesjTDscLLtbG5cdTAwMGVcdTAwMGan4tDaYJX33Iv3WH8uo0fJhcjy51x1MDAxNthuZYmL1Yn5rUzmIEK1kbSdSlx1MDAxOMlcdTAwMDVL3fNvyl4sXjAy0ixoxzlXuP5cblNcdTAwMTdThui6Ulx1MDAxN69cdTAwMWY3Klx1MDAxNEJcdTAwMGKZOehXmTwpUFx1MDAxZFx1MDAwNFFRYotyXHUwMDFkNHDjk+5Oh/uE/EBcdTAwMTaiXHUwMDExXHUwMDFhSVx1MDAxZOKBXHUwMDBiw4CaOmTtXHUwMDE45ahhWUGwXHUwMDFiPIc5g6aaXHUwMDAy7u9j1qBXIY/pbz36YXBcdTAwMTOj2UjZSWvUnlSESbxcdTAwMDetVFx1MDAxM6xB6SBdcLjVXHUwMDA151x1MDAxZo/z46Q9/lx1MDAxNo/ll8Hpid/lMaOHRFx1MDAwM/yjarH1VeCS+EE7zS1cdTAwMTOn5UIyjjztSj0p0jglnCr2VCS9XHUwMDEzwlx1MDAxZCmXm3rQ7lx1MDAxZXl6JvpbU4BcdTAwMTGRlEm7o6zg2XFcIjKu6ETxtVx1MDAwMU59d93dJ0Z3xFlimdSwJHEqZVx1MDAwNYfS/inGOupar30lTIKH14f7OL6qxFx1MDAxNmwlXVpcdTAwMTeRg3LxKVo9NjW2c4PbTHxPlrmSQ0WWw6RcXFx1MDAxMziWyJm72XGiXCKYXHTOKr1MgaGxILXg5dU0qC4qRFxiz1D1e81C7XvDn2K4+8A9Plx1MDAxYb9wXHUwMDA3nSdD/bbvqabx99iTNPQ3ZUtnOFx1MDAxNaSJUla2TjFySaujNDNvXCK4jO9cdTAwMDS4rCBcdTAwMTYvXHUwMDFkIGlwW17drfFPOuVzxFx1MDAxYlx1MDAxMW52XHQ+/NZ/9fCvt48/7f/qfj96p1jnRVxiynBcdCbiQjFFta9oZ+Y7XHUwMDFiIVx1MDAwNim96Gyki4rQTexsNFlcdTAwMTJyblpcdTAwMTO9f1xcKPj32qPR6ynNxbz0XHQhM/a6XHUwMDE3z3+paM+/m8bk6FGpr15cZrvxo0H7oJ8nw3s/evHZ/fJcdTAwMDSgf1xcyFxuYtt4XHUwMDE2+fv3P/79/1x1MDAwMdYtNpcifQ==writecommitraisetriggerscans passmergeLocalfeature branchIDE scanningTrufflehog:secretsPresidio:sensitive dataPre-commit hooksBefore code reaches the repositoryGitHub PRTemplatePull requestGitHub scans:Dependency reviewCodeQLCheck pre-commithooks ran and re-run scansNon-GitHub nativesecurity scanningGitHub actionsGitHub branchprotection rulesPeer reviewGitHub scans:DependabotCodeQLDefault branchAfter code reaches the repositoryCODEOWNERSCode Security WorkflowpushRUNS ON YOUR WORKSPACERUNS ON GITHUB⏱️ regular scansCustom patterns1236781Training and guidanceMinimise introductionof vulnerabilities and secret leakage2Real-time feedbackIdentify vulnerabilities before codeis committed3Pre-commit hooksPrevent leakage of secret and sensitive data before it is committed4GitHub push protectionPrevent secret leakage beforeit is published to GitHub6GitHub vulnerability scanningIdentify vulnerabilities in code and dependencies, on PR and default branch 7Additional vulnerability scanningIdentify vulnerabilities through scanning not provided natively by GitHub8Peer review and branch protectionPrevent unreviewed code frombeing merged with the default branchRepository / workflow stateProcess / control / checkPolicy / config / templateUnder investigationRuns on GitHubRuns on your workspaceGitHub secret scanningScan for a broader range of secrets, once published to GitHub56GitHub push protectionCustom patternsGitHub secret scanningRemotefeature branchchecks pass45 \ No newline at end of file diff --git a/docs/codeql-advanced-setup.md b/docs/codeql-advanced-setup.md new file mode 100644 index 0000000..0116502 --- /dev/null +++ b/docs/codeql-advanced-setup.md @@ -0,0 +1,11 @@ +# Setting Up Advanced CodeQL for Fork-Based PRs + +These instructions support the [CodeQL for Fork-Based PRs](https://github.com/uktrade/.github/blob/main/SECURITY.md#codeql-for-fork-based-prs-optional) control in the DBT GitHub Security Policy. Switching to [**Advanced** CodeQL](https://docs.github.com/en/code-security/how-tos/find-and-fix-code-vulnerabilities/configure-code-scanning/configuring-advanced-setup-for-code-scanning) generates a `codeql.yml` workflow: + +1. Navigate to **Settings → Advanced Security** in your repository +1. Scroll down to the **Code scanning** section; under the **Tools** sub-section there will be an item for CodeQL analysis +1. Click the **...** button next to the **Default** setup text, then choose **Switch to advanced** from the menu +1. On the popup, click the **Disable CodeQL** button. This only disables the *default* CodeQL setup — a branch protection rule remains in place that blocks PRs unless a CodeQL scan is detected, so PRs still cannot be merged without the advanced workflow you create in the next step +1. GitHub will then open its online editor to create a new file called `codeql.yml`, prefilled with the languages CodeQL has detected in your repository. You can modify the contents of this file if needed, however you must leave the workflow name as `CodeQL Advanced` +1. Once happy with the workflow file contents, click the green **Commit changes** button to trigger a PR to merge this into the default branch +1. Approve and merge the PR with this workflow file. Once merged, CodeQL will perform an initial scan that can take a while; you can track the progress in the **Actions** tab for your repository diff --git a/docs/github-security-configuration.md b/docs/github-security-configuration.md new file mode 100644 index 0000000..c8b5095 --- /dev/null +++ b/docs/github-security-configuration.md @@ -0,0 +1,11 @@ +# Applying the DBT GitHub Security Configuration + +These instructions support the [GitHub Security Configuration](https://github.com/uktrade/.github/blob/main/SECURITY.md#github-security-configuration) control in the DBT GitHub Security Policy. + +**You must be an organisation administrator to apply this configuration** + +1. As an organisation administrator, navigate to the [security configurations page](https://github.com/organizations/uktrade/settings/security_products) +1. Scroll down to the **Apply configurations** section, and enter the name of the repository to be made public in the filter input field +1. Use the checkbox next to the results list to select all repositories being made public, then use the **Apply configuration** button to select the **Default DBT security** configuration +1. A confirmation modal will appear displaying a summary of the action being made. Click the **Apply** button +1. To confirm the configuration has been applied, navigate to **Settings → Advanced Security** in the repository. At the top of the page there should be a banner message **Modifications to some settings have been blocked by organization administrators** diff --git a/templates/SECURITY_CHECKLIST.md b/templates/SECURITY_CHECKLIST.md new file mode 100644 index 0000000..9765196 --- /dev/null +++ b/templates/SECURITY_CHECKLIST.md @@ -0,0 +1,33 @@ +# Security Checklist + +Work through this checklist from top to bottom, ticking each item once you have confirmed it is true. Each item links to detailed guidance in the [DBT GitHub Security Policy](https://github.com/uktrade/.github/blob/main/SECURITY.md). + +Last checked against the policy: _add date_ + +## 1. Contributor controls + +Actions each contributor takes for themselves, so everyone knows what the controls are and why they exist. + +- [ ] [All internal contributors have read the DBT GitHub Security Policy](https://github.com/uktrade/.github/blob/main/SECURITY.md) +- [ ] [All internal contributors have completed code security training in the last year](https://github.com/uktrade/.github/blob/main/SECURITY.md#security-training) +- [ ] [All internal contributors have reviewed the GitHub Safety Tips on coding in the open](https://github.com/uktrade/.github/blob/main/SECURITY.md#github-safety-tips) + +## 2. Repository-level controls + +Defences set up within the repository itself. + +- [ ] [A `.pre-commit-config.yaml` file exists so the organisation-approved hooks run before commits](https://github.com/uktrade/.github/blob/main/SECURITY.md#pre-commit-hooks) +- [ ] [Repository access has been reviewed](https://github.com/uktrade/.github/blob/main/SECURITY.md#repository-access) +- [ ] [A `CODEOWNERS` file exists so the right people review changes](https://github.com/uktrade/.github/blob/main/SECURITY.md#codeowners) +- [ ] [The pull request template reminds reviewers to check for secrets](https://github.com/uktrade/.github/blob/main/SECURITY.md#pull-request-template) +- [ ] [The mandatory custom GitHub properties are set](https://github.com/uktrade/.github/blob/main/SECURITY.md#custom-github-properties) +- [ ] [Advanced CodeQL is set up if the repository accepts PRs from forks (optional)](https://github.com/uktrade/.github/blob/main/SECURITY.md#codeql-for-fork-based-prs-optional) + +## 3. Organisation-applied controls + +Controls applied by an organisation administrator and verified by a repository administrator. + +- [ ] [The DBT GitHub security configuration is applied to the repository](https://github.com/uktrade/.github/blob/main/SECURITY.md#github-security-configuration) +- [ ] [The default branch protection ruleset is applied to the default branch](https://github.com/uktrade/.github/blob/main/SECURITY.md#branch-protection-rules) +- [ ] [GitHub Secret Protection is enabled and blocking secrets](https://github.com/uktrade/.github/blob/main/SECURITY.md#github-secret-protection) +- [ ] [The relevant vulnerability scans are active](https://github.com/uktrade/.github/blob/main/SECURITY.md#vulnerability-scanning)