Please do not publish credentials, private data, or detailed exploit instructions in a public issue.
flowchart TD
A["Found something?"] --> B{"GitHub private<br/>vulnerability reporting<br/>available?"}
B -- yes --> C["Report privately through GitHub"]
B -- no --> D["Contact c0k0n via the GitHub profile"]
C --> E["Include: affected page or file,<br/>reproduction steps, impact, safe evidence"]
D --> E
E --> F["Allow time for investigation<br/>before making it public"]
Basirah is a fully static website on Cloudflare Pages: no server, database, authentication, or user-generated content. In scope:
- the site itself — HTML, CSS, and JS behaviour
- the build and deployment pipeline — GitHub Actions → Wrangler
- header and CSP configuration
Only the latest deployment of main is supported. Reports are handled on a best-effort basis.
Please read this before reporting — these are documented decisions, not oversights.
| Item | Why it is accepted |
|---|---|
CSP allows 'unsafe-inline' for scripts and styles |
The inline pre-paint theme script and inline styles need it today |
| No post-deploy health check | All verification is pre-deploy; see INTEGRATIONS.md |
500.astro cannot catch origin 5xx |
That needs a Cloudflare Custom Error Rule — a hosting setting, not a route |
Everything else is locked down: default-src 'self', frame-ancestors 'none', object-src 'none', HSTS with preload, JSON-LD escaped before injection. Details in CONCERNS.md.