Security
For a vulnerability in the repository's builder, website or publication tooling, use GitHub's private vulnerability reporting option in the repository's Security tab when it is enabled. Do not post exploit details or secrets in a public issue. Include the affected file, a minimal reproduction, expected and observed behaviour, and the potential impact.
On this page
Do not include customer data, real device credentials, private keys or sensitive site details. Do not test the issue against systems you do not own or have explicit permission to assess.
For a vulnerability in a vendor product, use the vendor's reporting process. This repository is not the product maintainer and cannot authorise testing or disclosure on their behalf.
Website boundary#
The published site contains static HTML, local CSS and JavaScript. It has no application backend, login, analytics or remote search service. Article HTML is escaped during rendering and incoming search text is inserted as text, not executed markup.
The local preview binds to 127.0.0.1 and serves only the generated output. It is a development preview, not a production server. The builder does not execute article snippets or contact the devices and URLs described in the content.
Keep dependencies and GitHub Actions pins under review. A passing test suite is not a guarantee that software has no vulnerabilities.