~/sang

sangtran.dev: a strict-CSP static site

AstroTypeScriptCloudflare WorkersVitestPlaywrightaxe-coreLighthouse CIGitHub ActionsCodeQL

Problem: a personal site is easy to ship once and let drift. Security headers get loosened to make one feature work, accessibility regresses unnoticed, and dependencies age. For a security engineer’s site, the page itself is part of the portfolio.

Approach: treat each rule as something the build must prove, not something I remember to do.

Outcome: as of October 2026, the repository has unit, build-output and end-to-end test suites, a clean npm audit, and automated accessibility and Lighthouse checks that gate every change. The checks have caught real bugs, including a keyboard-focus defect and a phone layout overflow, which I describe in a write-up on the blog.

What it does not do yet: there is no CSP violation reporting, and the end-to-end tests run only in Chrome with emulated phones, not on real devices or Safari.

guest@sang:~$