Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
24 changes: 24 additions & 0 deletions .github/workflows/docs.yml
Original file line number Diff line number Diff line change
@@ -0,0 +1,24 @@
# Does this organisation advertise what it has?
#
# The landing drifts silently: a repository is created, and nothing in any
# repository fails because no page mentions it. esbuildsandbox closes a sandbox
# leak in a dependency, and was on no page of the organisation that found it.
#
# β›” NOT `on: [push, pull_request]`: both fire for a branch with a pull request
# open, so every push runs the check twice.
#
# β›” It needs NO secret. Listing a public organisation and reading its surfaces
# are public reads, so this runs on github.token.
name: docs

on:
pull_request:
push:
branches: [main]

permissions:
contents: read

jobs:
current:
uses: go-fleettools/fleettools/.github/workflows/docs-current.yml@main
5 changes: 5 additions & 0 deletions hugo.toml
Original file line number Diff line number Diff line change
Expand Up @@ -12,6 +12,11 @@ disableKinds = ["taxonomy", "term", "RSS", "sitemap", "404"]
type = "lib + cli"
blurb = "Fetch a URL β†’ DOM β†’ CSS cascade (var()/@media/dark-mode) β†’ run the page's JavaScript β†’ full box-model layout (flex/grid/tables/position) β†’ paint anti-aliased text, gradients, images and SVG to an image.RGBA / PNG. Pure Go, CGO_ENABLED=0, no Chromium; ships a `render` CLI."
badge = true
[[params.repos]]
name = "esbuildsandbox"
role = "One function, against one leak"
type = "lib"
blurb = "A safe <code>ResolveDir</code> for esbuild's <code>pkg/api</code>. A caller bundling untrusted source installs an <code>OnResolve</code>/<code>OnLoad</code> plugin and it looks complete β€” every import in its own tests goes through it. But the bundler expands a <strong>glob dynamic import</strong>, <code>import(`./${lang}/index.js`)</code>, by walking <code>ResolveDir</code> on the <strong>real filesystem</strong> through its internal resolver, bypassing the plugin entirely. Whatever that directory is β€” <code>\"/\"</code> is a common default β€” is what gets walked, following symlinks. This returns a directory where that walk finds nothing."
[[params.repos]]
name = "browserproxy"
role = "Remote-browser service"
Expand Down
Loading