Skip to content
hideouts

Type to search every app and research write-up.

Colophon

How this site is built

hideouts.io is static HTML built in public from open source. This page shows exactly which build you’re looking at and how it was made, so you can check it.

Every app and research page is generated from its GitHub repository’s README when the site is built. GitHub is the source of truth: when a README changes, the site follows on the next build. Builds run on every change to the site, nightly at 06:17 UTC, and whenever a project asks for an update.

Only the 18 repositories on an explicit allowlist are ever fetched. Images from READMEs are copied here at build time, so reading a page never contacts GitHub or an image host.

  • Plain HTML and one stylesheet. Every page works without JavaScript.
  • A tiny inline script in each page’s <head> applies your theme before the page appears and stops other sites from framing it.
  • One small script adds conveniences: copy buttons, the theme toggle, app filters, the table of contents highlight, section links, and the screenshot viewer.
  • Search is Pagefind: a static index that runs locally in your browser, so what you type never leaves it.
  • Fonts are your system’s own. There are no web fonts, frameworks, or third-party scripts.

Every page carries this policy in a <meta> tag. The browser refuses anything it doesn’t allow, including scripts from other sites and any inline script or style that isn’t hashed.

default-src 'self';
img-src 'self' data:;
font-src 'self';
connect-src 'self';
object-src 'none';
base-uri 'self';
form-action 'self';
frame-src 'none';
worker-src 'self';
script-src 'self' 'wasm-unsafe-eval' 'sha256-…';
style-src 'sha256-…'

'sha256-…' stands for the hash of each script and style on the page, computed at build time. 'wasm-unsafe-eval' lets the search index run as WebAssembly; it doesn’t allow JavaScript eval.

GitHub Pages can’t send custom response headers, so protections that only work as headers are handled differently: a small script stops other sites from showing these pages in a frame, and the referrer policy is set with a <meta> tag.

The build workflow must pass all of these before anything is published:

  1. Linting (including accessibility rules), formatting, and type checks.
  2. An allowlist check that fails if any repository outside the published list appears in the output.
  3. An internal link check covering every link, image, and #section anchor.
  4. An external link check, so the site doesn’t point at dead pages (advisory on nightly and README-update runs).

The site is then deployed to GitHub Pages straight from that workflow’s output.

To rebuild this version yourself, with GitHub CLI and Node 24:

git clone https://github.com/hideouts-io/hideouts.io.git
cd hideouts.io
git checkout 9c46ec7
npm ci
GITHUB_TOKEN=$(gh auth token) npm run content
npm run build

Pages whose README has changed since this build will differ, and so will the build details on this page.