From d3e32a78a23f1cf75ef1d38143e22ec7d2b32bb6 Mon Sep 17 00:00:00 2001 From: tomaioo Date: Wed, 15 Apr 2026 12:39:35 -0700 Subject: [PATCH] fix(security): rendering mutable remote content from branch head (#639) The app fetches Markdown from `.../master/README.md`, which is a mutable branch reference. Content can change at any time and is immediately rendered client-side. This increases risk of unexpected content/script injection and makes output non-reproducible. Affected files: index.html Signed-off-by: tomaioo <203048277+tomaioo@users.noreply.github.com> --- index.html | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/index.html b/index.html index 075ecfa..7c03e2b 100644 --- a/index.html +++ b/index.html @@ -51,7 +51,7 @@ marked.use( markedGfmHeadingId.gfmHeadingId() ); // Get the markdown file, convert it to HTML & put it inside the main tag - fetch( 'https://raw.githubusercontent.com/offa/android-foss/master/README.md' ) + fetch( 'README.md' ) .then( response => response.text() ) .then( data => { document.querySelector( 'main' ).innerHTML = marked.parse( data );