Repository navigation
feat(website): documentation site with press and tool comparisons - #190
Merged
Merged
Conversation
A Docusaurus site under website/, following the structure OWASP CVE Lite CLI uses - all content in one folder, dependencies isolated there so they never become runtime dependencies of the scanner. Landing page leads with the node:18 result: 2,200 findings, 9 that matter, one at the 100th EPSS percentile rated HIGH so a severity-sorted list buries it. Three terminal transcripts show triage, exploit chains and --fix, all captured from real runs and recorded in src/components/transcripts.ts with the command that produced them. Press page lists 36 pieces of coverage across 30+ outlets in five languages, including Help Net Security, SecurityWeek, SC World, ReversingLabs and Cloud Native Now, plus two YouTube walkthroughs. Every URL returned HTTP 200 when compiled and every title and date was read from the page rather than written by hand. Two further items were left out because their sites present broken TLS certificates, which is not something a security project should link to. Comparison section covers Trivy, Snyk, Docker Scout, Grype, Dependabot and Hadolint, with a capability matrix on the hub page. Each page is explicit about where the other tool is the better choice - Trivy and Hadolint are dependencies rather than rivals, and saying so is more credible than a matrix of unbroken ticks. Two deliberate departures from the CVE Lite site: no analytics beacon, since a tracker on the site that advertises "no telemetry" would be the first thing a sceptical evaluator noticed, and the theme toggle stays enabled rather than forcing dark mode. website/.npmrc pins the public npm registry. Without it npm inherits whatever the machine is configured for, and a corporate Artifactory mirror fails with an ENOTFOUND that names nothing useful - which is exactly what happened while building this. tests/test_website_docs.py guards against drift: sidebar entries must resolve, every doc needs front matter, no relative link may escape the site root, case-study numbers must match the repo copies, and no frontend dependency may leak into the Python package. It caught two broken README links during the migration.
Dependency Review SummaryThe full dependency review summary was too large to display here (2170KB, limit is 1024KB). Please download the artifact named "dependency-review-summary" to view the complete report. |
added 2 commits
September 20, 2026 15:32
Two failures from the first CI run on this branch. The setup-node step was pinned to setup-python's SHA, with a comment claiming v6.0.0. Actions resolves by SHA within the named repository, so it failed with "unable to find version". Now pinned to the real setup-node v6.4.0 commit, verified against the tag rather than copied. Dependency review flagged serialize-javascript@6.0.2, reached transitively through webpack. Two advisories apply: GHSA-5c6j-r48x-rmvq (RCE via RegExp.flags, patched in 7.0.3) and GHSA-qj8w-gfj5-8c6v (CPU exhaustion DoS, patched in 7.0.5). An override of ^7.0.5 clears both and resolves to 7.1.1. Shipping a known high-severity RCE in the toolchain that builds DockSec's own site is not defensible for a project whose pitch is that it finds exactly this class of problem. Build, typecheck and all 25 pages verified after the change.
Dependency review flagged uuid@8.3.2 (GHSA-w5hq-g745-h8pq, missing buffer bounds check). It arrives through sockjs, a webpack-dev-server dependency that never reaches the built site, but the gate is right to flag it and an exception would be the wrong habit here. Overridden to ^11.1.1, the first patched line. The top-level uuid was already 14.0.2; only the nested copy was affected. `npm audit` now reports zero vulnerabilities. That check should have run before the first push - it would have caught this and the serialize-javascript RCE together rather than one CI round each.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
A Docusaurus site under
website/, following the structure OWASP CVE Lite CLI uses — all content in one folder, dependencies isolated so they never become runtime dependencies of the scanner.Preview:
cd website && npm install && npm startLanding page
Leads with the strongest evidence we have: 2,200 findings, 9 that matter, one at the 100th EPSS percentile rated HIGH — so a severity-sorted list buries it under 226 CRITICALs. That inversion is the product thesis.
Three terminal transcripts (triage, exploit chains,
--fix) are real captured output, stored insrc/components/transcripts.tswith the command that produced each one. A security tool that mocks up its own results is not one to trust.Press (36 items, 30+ outlets, 5 languages)
Help Net Security (×4), SecurityWeek, SC World, ReversingLabs, Cloud Native Now (×2), The Cyber Express, Linux Today, Open Source For U, Business Tech Weekly (×3), plus Spanish, Portuguese and Polish coverage and 2 YouTube walkthroughs.
Every URL returned HTTP 200 when compiled; every title and date was read from the page, not written by hand.
Two items were deliberately excluded —
cyvex.org(certificate name mismatch) andcloudreviewer.net(TLS handshake failure). Linking a security project's press page to sites with broken certificates is indefensible. Both are low-value aggregators of the SecurityWeek piece, so nothing is lost.Comparisons (7 pages)
Hub with a capability matrix, plus Trivy, Snyk, Docker Scout, Grype, Dependabot and Hadolint.
Each page states where the other tool is the better choice. Trivy and Hadolint are dependencies, not rivals, and saying so plainly is more credible than a matrix of unbroken ticks — technical evaluators check.
Two departures from the CVE Lite site
I also split their single 1,159-line CSS file into per-component modules over a token layer, so the palette lives in one place and sections can be added without touching a monolith.
One environment fix
website/.npmrcpins the public npm registry. Without it npm inherits the machine's configuration — a corporate Artifactory mirror here — and fails with anENOTFOUNDthat names nothing useful. This cost real time during the build and would hit CI and every outside contributor.Drift guard
tests/test_website_docs.py(7 tests): sidebar entries must resolve, every doc needs front matter, no relative link may escape the site root, case-study numbers must match the repo copies, and no frontend dependency may leak into the Python package.It earned its place immediately — caught two broken
../../README.mdlinks during migration that would have 404'd.Verification
npm run buildsucceeds;onBrokenLinks: 'throw'means a dead internal link fails CInpm run typecheckcleanruff check .cleanRequires after merge
Repository setting: Pages source → "GitHub Actions". Until then the build job runs and guards against regressions, but nothing deploys. Site will be at
owasp.github.io/DockSec/; theowasp.org/DockSec/redirect can be requested separately and needs no rebuild.