Colophon
How this site is built
hideouts.io is static HTML built in public from open source. This page shows exactly which build you’re looking at and how it was made, so you can check it.
Where the content comes from
Link to section: Where the content comes fromEvery app and research page is generated from its GitHub repository’s README when the site is built. GitHub is the source of truth: when a README changes, the site follows on the next build. Builds run on every change to the site, nightly at 06:17 UTC, and whenever a project asks for an update.
Only the 18 repositories on an explicit allowlist are ever fetched. Images from READMEs are copied here at build time, so reading a page never contacts GitHub or an image host.
What runs in your browser
Link to section: What runs in your browser- Plain HTML and one stylesheet. Every page works without JavaScript.
- A tiny inline script in each page’s
<head>applies your theme before the page appears and stops other sites from framing it. - One small script adds conveniences: copy buttons, the theme toggle, app filters, the table of contents highlight, section links, and the screenshot viewer.
- Search is Pagefind: a static index that runs locally in your browser, so what you type never leaves it.
- Fonts are your system’s own. There are no web fonts, frameworks, or third-party scripts.
Content Security Policy
Link to section: Content Security PolicyEvery page carries this policy in a <meta> tag. The browser refuses anything it doesn’t allow, including scripts from other sites and any inline script or style that isn’t hashed.
default-src 'self';
img-src 'self' data:;
font-src 'self';
connect-src 'self';
object-src 'none';
base-uri 'self';
form-action 'self';
frame-src 'none';
worker-src 'self';
script-src 'self' 'wasm-unsafe-eval' 'sha256-…';
style-src 'sha256-…''sha256-…' stands for the hash of each script and style on the page, computed at build time. 'wasm-unsafe-eval' lets the search index run as WebAssembly; it doesn’t allow JavaScript eval.
GitHub Pages can’t send custom response headers, so protections that only work as headers are handled differently: a small script stops other sites from showing these pages in a frame, and the referrer policy is set with a <meta> tag.
Checks on every build
Link to section: Checks on every buildThe build workflow must pass all of these before anything is published:
- Linting (including accessibility rules), formatting, and type checks.
- An allowlist check that fails if any repository outside the published list appears in the output.
- An internal link check covering every link, image, and
#sectionanchor. - An external link check, so the site doesn’t point at dead pages (advisory on nightly and README-update runs).
The site is then deployed to GitHub Pages straight from that workflow’s output.
Reproduce this build
Link to section: Reproduce this buildTo rebuild this version yourself, with GitHub CLI and Node 24:
git clone https://github.com/hideouts-io/hideouts.io.git
cd hideouts.io
git checkout 9c46ec7
npm ci
GITHUB_TOKEN=$(gh auth token) npm run content
npm run buildPages whose README has changed since this build will differ, and so will the build details on this page.