Skip to content

Security audit remediation: sanitize assets and add validation CI - #4

Open
arumes31 wants to merge 1 commit into
mainfrom
codex/audit-remediation-2026-08-28
Open

Security audit remediation: sanitize assets and add validation CI#4
arumes31 wants to merge 1 commit into
mainfrom
codex/audit-remediation-2026-08-28

Conversation

@arumes31

Copy link
Copy Markdown
Owner

Summary

  • pin CodeQL and add a dedicated theme validation workflow
  • block cross-origin SVG inlining and sanitize same-origin SVG content before DOM insertion
  • remove the mutable Google Fonts import for self-contained rendering
  • fix repository-relative installation links and document support/security
  • add CODEOWNERS, security policy, and an MIT license

Verification

  • node --check master-theme/custom.js
  • actionlint
  • self-contained asset policy check
  • git diff --check

@coderabbitai

coderabbitai Bot commented Aug 28, 2026

Copy link
Copy Markdown

Important

  • 馃攳 Trigger review

This repository does not receive automatic reviews because it has fewer than 10 stars.

鈿欙笍 Run configuration

Configuration used: defaults

Review profile: CHILL

Plan: Pro Plus

Run ID: e66d3bf4-596f-4d7f-9c0e-52e45bdfd8af


Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

鉂わ笍 Share

Comment @coderabbitai help to get the list of available commands.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant