mirror of
https://github.com/iimp0ster/detection-chokepoints
synced 2026-08-09 12:41:00 +00:00
XSS: - Escape `</` in all 5 jsonify-into-<script> data blobs so contributed YAML cannot break out of the script context (verified: JSON still parses, no </script breakout) - Add `| escape` to contributor-controlled fields in chokepoint-card.html and ~71 value outputs in the chokepoint detail layout Supply chain (SRI): - Pin highlight.js, d3, and Chart.js CDN includes with sha384 integrity + crossorigin (hashes computed from the immutable versioned URLs) - Document why cdn.tailwindcss.com cannot take SRI + the real fix GitHub Actions: - SHA-pin all 7 third-party actions to commit SHAs (version in comment) Governance: - SECURITY.md (private disclosure policy + scope: detection content is intentional, not a vuln) - CODEOWNERS routing review to @iimp0ster - Dependabot for github-actions / bundler / npm / pip Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>