Skip to content

Security: c0k0n/basirah

Security

SECURITY.md

Security Policy

Reporting a vulnerability

Please do not publish credentials, private data, or detailed exploit instructions in a public issue.

flowchart TD
    A["Found something?"] --> B{"GitHub private<br/>vulnerability reporting<br/>available?"}
    B -- yes --> C["Report privately through GitHub"]
    B -- no --> D["Contact c0k0n via the GitHub profile"]
    C --> E["Include: affected page or file,<br/>reproduction steps, impact, safe evidence"]
    D --> E
    E --> F["Allow time for investigation<br/>before making it public"]
Loading

Scope

Basirah is a fully static website on Cloudflare Pages: no server, database, authentication, or user-generated content. In scope:

  • the site itself — HTML, CSS, and JS behaviour
  • the build and deployment pipeline — GitHub Actions → Wrangler
  • header and CSP configuration

Only the latest deployment of main is supported. Reports are handled on a best-effort basis.

Known accepted posture

Please read this before reporting — these are documented decisions, not oversights.

Item Why it is accepted
CSP allows 'unsafe-inline' for scripts and styles The inline pre-paint theme script and inline styles need it today
No post-deploy health check All verification is pre-deploy; see INTEGRATIONS.md
500.astro cannot catch origin 5xx That needs a Cloudflare Custom Error Rule — a hosting setting, not a route

Everything else is locked down: default-src 'self', frame-ancestors 'none', object-src 'none', HSTS with preload, JSON-LD escaped before injection. Details in CONCERNS.md.

There aren't any published security advisories