~/sang

security of this site

A security engineer's website should not just claim to be secure. This page documents the threat model and the controls, and links to independent scanners so you can check for yourself.

threat model

ThreatMitigation
XSS / content injectionStatic output, strict CSP with hashes, no inline event handlers, terminal renders via textContent only.
Supply-chain compromiseExact-pinned dependencies, lockfile, Dependabot, npm audit, dependency review and CodeQL in CI.
Clickjackingframe-ancestors 'none' and X-Frame-Options: DENY.
Tracking / data leakageNo analytics, no cookies, self-hosted fonts, strict Referrer-Policy.
Downgrade / MITMHTTPS only with HSTS (preload-eligible).
Account / infra takeoverHardware-key MFA on hosting, DNS and GitHub; least-privilege deploy token; DNSSEC and CAA.
Email spoofingSPF, DKIM and DMARC enforcement on the domain.
Server-side attacksNone to attack: no server code, database or form handlers.

response headers

HeaderValue
Content-Security-Policydefault-src 'self'; script/style by hash; frame-ancestors 'none'; object-src 'none'; base-uri 'none'
Strict-Transport-Securitymax-age=63072000; includeSubDomains; preload
X-Content-Type-Optionsnosniff
Referrer-Policystrict-origin-when-cross-origin
Permissions-Policycamera, microphone, geolocation, payment and others disabled
Cross-Origin-Opener-Policysame-origin
Cross-Origin-Resource-Policysame-origin

verify it yourself

build pipeline

Every change runs through CI: type checks, npm audit, CodeQL, secret scanning and a CycloneDX SBOM. Dependabot keeps dependencies and workflow actions current.

guest@sang:~$