Skip to content
This repository was archived by the owner on Sep 22, 2026. It is now read-only.

Security: SaneSanders/noemium

Security

SECURITY.md

Security Policy

Reporting a vulnerability

Please do not open a public issue for security problems.

We aim to acknowledge reports within 72 hours.

Scope

Noemium is a static site: content (YAML/Markdown) is rendered at build time and there is no server-side user input. The main attack surface is content PRs as untrusted input — a malicious entry must not be able to inject markup, scripts or non-https links into the built site. Issues in scope:

  • Stored XSS via content fields (tool names, taglines, receipts, JSON-LD).
  • Schema bypasses that let disallowed URL schemes (javascript:, data:) into rendered links.
  • CI/CD workflow abuse (script injection through PR-controlled input).

Not considered vulnerabilities

  • Content accuracy disputes (wrong price, stale verdict) — open a normal PR.
  • Vulnerabilities in third-party services we merely link to.
  • Self-XSS, or issues requiring the victim to run untrusted code locally.
  • Missing best practices (headers, CSP tuning) without a demonstrated exploit — suggestions are welcome as regular issues.

There aren't any published security advisories