From 8f2e9fa4c44a70d42509f17684f1b5be5b403fb6 Mon Sep 17 00:00:00 2001 From: "kubestellar-hive[bot]" Date: Sun, 20 Sep 2026 13:18:55 -0400 Subject: [PATCH] [sec-check] fix: add a Content-Security-Policy meta tag to docusaurus.config.js headTags The published site shipped no Content-Security-Policy. GitHub Pages cannot set response headers, so a meta http-equiv tag in headTags is the only place this site can express one. This adds base-uri 'self', object-src 'none' and form-action 'self'. These three directives need no script-src allowance, so they cannot constrain Docusaurus hydration, the ld+json block or docusaurus-plugin-search-local. script-src is deliberately omitted: Docusaurus emits inline bootstrap scripts, so it could only ship with 'unsafe-inline' and would add no protection. frame-ancestors is omitted because browsers ignore it when delivered via meta http-equiv. Verified against a full production build: the tag renders on all 46 pages, the ld+json and manifest head tags are unchanged, and the build contains no base, object, embed or form elements for the policy to break. Signed-off-by: kubestellar-hive[bot] --- docusaurus.config.js | 20 ++++++++++++++++++++ 1 file changed, 20 insertions(+) diff --git a/docusaurus.config.js b/docusaurus.config.js index ee656bc6..63a60aa9 100644 --- a/docusaurus.config.js +++ b/docusaurus.config.js @@ -50,6 +50,26 @@ const config = { href: '/favicons/apple-touch-icon.png', }, }, + { + tagName: 'meta', + attributes: { + 'http-equiv': 'Content-Security-Policy', + // Defence in depth for content this site does not author: architecture + // MDX and image assets are mirrored from cncf/architecture, and several + // data/*.json files supply href and src values rendered by src/components. + // These three directives need no allowance for inline or bundled script, + // so they hold without constraining Docusaurus hydration or local search. + // script-src is deliberately omitted: Docusaurus emits inline bootstrap + // scripts, so it could only ship with 'unsafe-inline', which would add no + // protection. frame-ancestors is omitted because browsers ignore it when + // delivered via ; it needs a real response header. + content: [ + "base-uri 'self'", + "object-src 'none'", + "form-action 'self'", + ].join('; '), + }, + }, { tagName: 'script', attributes: {