security of this site
A security engineer's website should not just claim to be secure. This page documents the threat model and the controls, and links to independent scanners so you can check for yourself.
threat model
| Threat | Mitigation |
|---|---|
| XSS / content injection | Static output, strict CSP with hashes, no inline event handlers, terminal renders via textContent only. |
| Supply-chain compromise | Exact-pinned dependencies, lockfile, Dependabot, npm audit, dependency review and CodeQL in CI. |
| Clickjacking | frame-ancestors 'none' and X-Frame-Options: DENY. |
| Tracking / data leakage | No analytics, no cookies, self-hosted fonts, strict Referrer-Policy. |
| Downgrade / MITM | HTTPS only with HSTS (preload-eligible). |
| Account / infra takeover | Hardware-key MFA on hosting, DNS and GitHub; least-privilege deploy token; DNSSEC and CAA. |
| Email spoofing | SPF, DKIM and DMARC enforcement on the domain. |
| Server-side attacks | None to attack: no server code, database or form handlers. |
response headers
| Header | Value |
|---|---|
Content-Security-Policy | default-src 'self'; script/style by hash; frame-ancestors 'none'; object-src 'none'; base-uri 'none' |
Strict-Transport-Security | max-age=63072000; includeSubDomains; preload |
X-Content-Type-Options | nosniff |
Referrer-Policy | strict-origin-when-cross-origin |
Permissions-Policy | camera, microphone, geolocation, payment and others disabled |
Cross-Origin-Opener-Policy | same-origin |
Cross-Origin-Resource-Policy | same-origin |
verify it yourself
build pipeline
Every change runs through CI: type checks, npm audit, CodeQL, secret scanning and a CycloneDX SBOM. Dependabot keeps dependencies and workflow actions current.