diff --git a/.github/workflows/docs.yml b/.github/workflows/docs.yml new file mode 100644 index 0000000..2300ff5 --- /dev/null +++ b/.github/workflows/docs.yml @@ -0,0 +1,24 @@ +# Does this organisation advertise what it has? +# +# The landing drifts silently: a repository is created, and nothing in any +# repository fails because no page mentions it. esbuildsandbox closes a sandbox +# leak in a dependency, and was on no page of the organisation that found it. +# +# ⛔ NOT `on: [push, pull_request]`: both fire for a branch with a pull request +# open, so every push runs the check twice. +# +# ⛔ It needs NO secret. Listing a public organisation and reading its surfaces +# are public reads, so this runs on github.token. +name: docs + +on: + pull_request: + push: + branches: [main] + +permissions: + contents: read + +jobs: + current: + uses: go-fleettools/fleettools/.github/workflows/docs-current.yml@main diff --git a/hugo.toml b/hugo.toml index d95b451..a01bf8b 100644 --- a/hugo.toml +++ b/hugo.toml @@ -12,6 +12,11 @@ disableKinds = ["taxonomy", "term", "RSS", "sitemap", "404"] type = "lib + cli" blurb = "Fetch a URL → DOM → CSS cascade (var()/@media/dark-mode) → run the page's JavaScript → full box-model layout (flex/grid/tables/position) → paint anti-aliased text, gradients, images and SVG to an image.RGBA / PNG. Pure Go, CGO_ENABLED=0, no Chromium; ships a `render` CLI." badge = true +[[params.repos]] + name = "esbuildsandbox" + role = "One function, against one leak" + type = "lib" + blurb = "A safe ResolveDir for esbuild's pkg/api. A caller bundling untrusted source installs an OnResolve/OnLoad plugin and it looks complete — every import in its own tests goes through it. But the bundler expands a glob dynamic import, import(`./${lang}/index.js`), by walking ResolveDir on the real filesystem through its internal resolver, bypassing the plugin entirely. Whatever that directory is — \"/\" is a common default — is what gets walked, following symlinks. This returns a directory where that walk finds nothing." [[params.repos]] name = "browserproxy" role = "Remote-browser service"