krz/orgo

Lightning fast org-mode static site generator. fast go org-mode static-site-generator

Commit d78e4ddb72

d78e4ddb72b2733aeaf6800ac5e98c55abd8a017

parent: c12be9354a

Verified · cmc

cmc <hello@cleberg.net> · 2026-08-11 21:49 UTC

Add dependabot, funding and a security policy

Dependabot covers cargo and the actions, both weekly and both grouped. The
action pins matter most: a SHA pin never moves on its own, which is the point,
and also means nothing tells you it has gone stale.

The security policy says what is actually worth reporting for a program whose
whole job is turning someone's documents into HTML — content escaping into the
page unescaped, a path that writes outside the output directory, the dev server
reaching past loopback, or a crafted file that never finishes building.

Layout: unified · split

.github/FUNDING.yml added +1
@@ -0,0 +1 @@
1github: [ccleberg]
.github/dependabot.yml added +26
@@ -0,0 +1,26 @@
1# Dependabot version updates.
2#
3# Two ecosystems, both weekly: the crates this is built from, and the actions the
4# workflows pin by SHA. The action pins are the reason this matters more than usual —
5# a pinned SHA never moves on its own, which is the point, and also means nothing tells
6# you it has gone stale unless something does.
7version: 2
8updates:
9 - package-ecosystem: "cargo"
10 directory: "/"
11 schedule:
12 interval: "weekly"
13 # A dependency bump can change rendered output — syntect owns the highlighting, and
14 # its syntax definitions are data. Grouping keeps that reviewable as one diff rather
15 # than five PRs landing in an order nobody chose.
16 groups:
17 rust-dependencies:
18 patterns: ["*"]
19
20 - package-ecosystem: "github-actions"
21 directory: "/"
22 schedule:
23 interval: "weekly"
24 groups:
25 actions:
26 patterns: ["*"]
SECURITY.md added +32
@@ -0,0 +1,32 @@
1# Security Policy
2
3## Supported Versions
4
5| Version | Supported |
6|---------|-----------|
7| latest release | yes |
8| anything older | no |
9
10Fixes land in a new release rather than as patches to an old one.
11
12## Reporting
13
14Email <hello@cleberg.net>, or open a private advisory through GitHub's *Security* tab.
15Please do not open a public issue for something exploitable.
16
17## What is worth reporting
18
19orgo reads org files and writes HTML, so the interesting cases are about what a *document*
20can make it do:
21
22- Content from a source file escaping into HTML unescaped — a page that can inject script
23 into the site it is published on.
24- A path in a document or config that writes outside the output directory.
25- The `serve` development server reachable, or made reachable, beyond loopback, or serving
26 files from outside the output directory.
27- A crash, hang or unbounded allocation triggered by a crafted org file. A build that
28 refuses a file is fine; one that never finishes is not.
29
30Out of scope: `--strict` not catching something, an unhandled org construct rendering
31oddly, and anything requiring you to run orgo against files you already do not trust while
32also deploying the result unread.