Skip to content

πŸ›‘οΈ Sentinel: [security improvement] Add noreferrer to external links - #41

Merged
schmug merged 2 commits into
mainfrom
sentinel-noopener-noreferrer-393118282437261456
Apr 26, 2026
Merged

schmug merged 2 commits into
mainfrom
sentinel-noopener-noreferrer-393118282437261456

Conversation

@schmug

@schmug schmug commented Apr 19, 2026

Copy link
Copy Markdown
Owner

🚨 Severity: LOW
πŸ’‘ Vulnerability: External links using target="_blank" or just external navigation used rel="noopener" but missed noreferrer. This can leak the Referer header to external sites.
🎯 Impact: Minor privacy risk where external sites could see the referring page URL.
πŸ”§ Fix: Updated Astro pages (src/pages/about.astro, src/pages/index.astro, src/pages/projects.astro) and layout (src/layouts/Base.astro) to use rel="noopener noreferrer".
βœ… Verification: Ran npm run lint and npm test successfully. Checked pages with grep to ensure noreferrer is present.


PR created automatically by Jules for task 393118282437261456 started by @schmug

Co-authored-by: schmug <38227427+schmug@users.noreply.github.com>
@google-labs-jules

Copy link
Copy Markdown
Contributor

πŸ‘‹ Jules, reporting for duty! I'm here to lend a hand with this pull request.

When you start a review, I'll add a πŸ‘€ emoji to each comment to let you know I've read it. I'll focus on feedback directed at me and will do my best to stay out of conversations between you and other bots or reviewers to keep the noise down.

I'll push a commit with your requested changes shortly after. Please note there might be a delay between these steps, but rest assured I'm on the job!

For more direct control, you can switch me to Reactive Mode. When this mode is on, I will only act on comments where you specifically mention me with @jules. You can find this option in the Pull Request section of your global Jules UI settings. You can always switch back!

New to Jules? Learn more at jules.google/docs.


For security, I will only act on instructions from the user who triggered this task.

@schmug

schmug commented Apr 25, 2026

Copy link
Copy Markdown
Owner Author

@google-labs-jules Please rebase against main and drop .jules/sentinel.md from this PR. The Jules agent log files are now gitignored as of #60 β€” they should not be committed. The Verify check is failing only on prettier formatting of that log file, not on the actual code change, which looks good (adding noreferrer to external links is a real improvement).

@google-labs-jules

Copy link
Copy Markdown
Contributor

@google-labs-jules Please rebase against main and drop .jules/sentinel.md from this PR. The Jules agent log files are now gitignored as of #60 β€” they should not be committed. The Verify check is failing only on prettier formatting of that log file, not on the actual code change, which looks good (adding noreferrer to external links is a real improvement).

I have rebased the PR against main and removed the .jules/sentinel.md file as requested.

Co-authored-by: schmug <38227427+schmug@users.noreply.github.com>
@schmug
schmug merged commit 50701d3 into main Apr 26, 2026
2 checks passed
@schmug
schmug deleted the sentinel-noopener-noreferrer-393118282437261456 branch April 26, 2026 00:17
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant