Skip to content

feat(website): documentation site with press and tool comparisons - #190

Merged
advaitpatel merged 3 commits into
mainfrom
feat/website
Sep 21, 2026
Merged

advaitpatel merged 3 commits into
mainfrom
feat/website

Conversation

@advaitpatel

Copy link
Copy Markdown
Collaborator

A Docusaurus site under website/, following the structure OWASP CVE Lite CLI uses — all content in one folder, dependencies isolated so they never become runtime dependencies of the scanner.

Preview: cd website && npm install && npm start

Landing page

Leads with the strongest evidence we have: 2,200 findings, 9 that matter, one at the 100th EPSS percentile rated HIGH — so a severity-sorted list buries it under 226 CRITICALs. That inversion is the product thesis.

Three terminal transcripts (triage, exploit chains, --fix) are real captured output, stored in src/components/transcripts.ts with the command that produced each one. A security tool that mocks up its own results is not one to trust.

Press (36 items, 30+ outlets, 5 languages)

Help Net Security (×4), SecurityWeek, SC World, ReversingLabs, Cloud Native Now (×2), The Cyber Express, Linux Today, Open Source For U, Business Tech Weekly (×3), plus Spanish, Portuguese and Polish coverage and 2 YouTube walkthroughs.

Every URL returned HTTP 200 when compiled; every title and date was read from the page, not written by hand.

Two items were deliberately excluded — cyvex.org (certificate name mismatch) and cloudreviewer.net (TLS handshake failure). Linking a security project's press page to sites with broken certificates is indefensible. Both are low-value aggregators of the SecurityWeek piece, so nothing is lost.

Comparisons (7 pages)

Hub with a capability matrix, plus Trivy, Snyk, Docker Scout, Grype, Dependabot and Hadolint.

Each page states where the other tool is the better choice. Trivy and Hadolint are dependencies, not rivals, and saying so plainly is more credible than a matrix of unbroken ticks — technical evaluators check.

Two departures from the CVE Lite site

  • No analytics beacon. Theirs loads a Cloudflare tracker. A tracker on the site advertising "no telemetry, ever" is the first thing a sceptical evaluator would notice.
  • Theme toggle stays enabled rather than forcing dark mode.

I also split their single 1,159-line CSS file into per-component modules over a token layer, so the palette lives in one place and sections can be added without touching a monolith.

One environment fix

website/.npmrc pins the public npm registry. Without it npm inherits the machine's configuration — a corporate Artifactory mirror here — and fails with an ENOTFOUND that names nothing useful. This cost real time during the build and would hit CI and every outside contributor.

Drift guard

tests/test_website_docs.py (7 tests): sidebar entries must resolve, every doc needs front matter, no relative link may escape the site root, case-study numbers must match the repo copies, and no frontend dependency may leak into the Python package.

It earned its place immediately — caught two broken ../../README.md links during migration that would have 404'd.

Verification

  • npm run build succeeds; onBrokenLinks: 'throw' means a dead internal link fails CI
  • npm run typecheck clean
  • 25 pages generated (22 docs + landing + 404 + search)
  • 546 tests pass (up from 539), ruff check . clean

Requires after merge

Repository setting: Pages source → "GitHub Actions". Until then the build job runs and guards against regressions, but nothing deploys. Site will be at owasp.github.io/DockSec/; the owasp.org/DockSec/ redirect can be requested separately and needs no rebuild.

A Docusaurus site under website/, following the structure OWASP CVE Lite
CLI uses - all content in one folder, dependencies isolated there so they
never become runtime dependencies of the scanner.

Landing page leads with the node:18 result: 2,200 findings, 9 that
matter, one at the 100th EPSS percentile rated HIGH so a severity-sorted
list buries it. Three terminal transcripts show triage, exploit chains
and --fix, all captured from real runs and recorded in
src/components/transcripts.ts with the command that produced them.

Press page lists 36 pieces of coverage across 30+ outlets in five
languages, including Help Net Security, SecurityWeek, SC World,
ReversingLabs and Cloud Native Now, plus two YouTube walkthroughs. Every
URL returned HTTP 200 when compiled and every title and date was read
from the page rather than written by hand. Two further items were left
out because their sites present broken TLS certificates, which is not
something a security project should link to.

Comparison section covers Trivy, Snyk, Docker Scout, Grype, Dependabot
and Hadolint, with a capability matrix on the hub page. Each page is
explicit about where the other tool is the better choice - Trivy and
Hadolint are dependencies rather than rivals, and saying so is more
credible than a matrix of unbroken ticks.

Two deliberate departures from the CVE Lite site: no analytics beacon,
since a tracker on the site that advertises "no telemetry" would be the
first thing a sceptical evaluator noticed, and the theme toggle stays
enabled rather than forcing dark mode.

website/.npmrc pins the public npm registry. Without it npm inherits
whatever the machine is configured for, and a corporate Artifactory
mirror fails with an ENOTFOUND that names nothing useful - which is
exactly what happened while building this.

tests/test_website_docs.py guards against drift: sidebar entries must
resolve, every doc needs front matter, no relative link may escape the
site root, case-study numbers must match the repo copies, and no
frontend dependency may leak into the Python package. It caught two
broken README links during the migration.
@github-actions github-actions Bot added documentation Improvements or additions to documentation ci Changes to CI/CD workflows tests Changes to the test suite labels Sep 20, 2026
@github-actions

github-actions Bot commented Sep 20, 2026 •

Copy link
Copy Markdown

Dependency Review Summary

The full dependency review summary was too large to display here (2170KB, limit is 1024KB).

Please download the artifact named "dependency-review-summary" to view the complete report.

View full job summary

Advait Patel added 2 commits September 20, 2026 15:32
Two failures from the first CI run on this branch.

The setup-node step was pinned to setup-python's SHA, with a comment
claiming v6.0.0. Actions resolves by SHA within the named repository, so
it failed with "unable to find version". Now pinned to the real
setup-node v6.4.0 commit, verified against the tag rather than copied.

Dependency review flagged serialize-javascript@6.0.2, reached
transitively through webpack. Two advisories apply: GHSA-5c6j-r48x-rmvq
(RCE via RegExp.flags, patched in 7.0.3) and GHSA-qj8w-gfj5-8c6v (CPU
exhaustion DoS, patched in 7.0.5). An override of ^7.0.5 clears both and
resolves to 7.1.1.

Shipping a known high-severity RCE in the toolchain that builds
DockSec's own site is not defensible for a project whose pitch is that
it finds exactly this class of problem.

Build, typecheck and all 25 pages verified after the change.
Dependency review flagged uuid@8.3.2 (GHSA-w5hq-g745-h8pq, missing
buffer bounds check). It arrives through sockjs, a webpack-dev-server
dependency that never reaches the built site, but the gate is right to
flag it and an exception would be the wrong habit here.

Overridden to ^11.1.1, the first patched line. The top-level uuid was
already 14.0.2; only the nested copy was affected.

`npm audit` now reports zero vulnerabilities. That check should have run
before the first push - it would have caught this and the
serialize-javascript RCE together rather than one CI round each.
@advaitpatel
advaitpatel merged commit 5d252ff into main Sep 21, 2026
15 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

ci Changes to CI/CD workflows documentation Improvements or additions to documentation tests Changes to the test suite

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant