Files
iimp0ster-detection-chokepo…/framework
imposterandClaude Opus 4.8 0c3709aa7e security: harden site supply chain, escaping, Actions, and governance
XSS:
- Escape `</` in all 5 jsonify-into-<script> data blobs so contributed
  YAML cannot break out of the script context (verified: JSON still
  parses, no </script breakout)
- Add `| escape` to contributor-controlled fields in chokepoint-card.html
  and ~71 value outputs in the chokepoint detail layout

Supply chain (SRI):
- Pin highlight.js, d3, and Chart.js CDN includes with sha384 integrity +
  crossorigin (hashes computed from the immutable versioned URLs)
- Document why cdn.tailwindcss.com cannot take SRI + the real fix

GitHub Actions:
- SHA-pin all 7 third-party actions to commit SHAs (version in comment)

Governance:
- SECURITY.md (private disclosure policy + scope: detection content is
  intentional, not a vuln)
- CODEOWNERS routing review to @iimp0ster
- Dependabot for github-actions / bundler / npm / pip

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
2026-06-12 20:24:30 -06:00
..