Security: nullNEU/nullify

SECURITY.md

Security Policy for the official null NEU website aka 'nullify'

Repository

Name: nullify

Description: This repository houses all code (and data) related to the official website of the Northeastern University chapter of the null community.

Tech Stack

The website is built with Hugo, a popular static site generator written in Go. All the data displayed on the website is stored in .md files or .yaml files. The website is deployed using Cloudflare pages, ensuring high security, availability in different regions, and improved performance.

Privacy and Security Highlights

  • User Privacy Centric: Our website is designed with user privacy as a top priority, ensuring minimal data collection and usage.
  • Minimalistic Design: The site is intentionally minimalistic, making it easy for users to navigate and understand our content.
  • No JavaScript Dependency: We have avoided using JavaScript in our codebase, ensuring that the website remains fully functional even if all scripts are blocked on a user's browser.

Security Measures

  1. Data Integrity and Confidentiality:

    • All data files (.md and .yaml) are regularly reviewed to ensure they do not contain sensitive information.
    • Sensitive information should never be hardcoded into the codebase or configuration files.
    • Sensitive data, if required, should be encrypted and stored securely.
  2. Access Control:

    • Only authorized members of the null NEU chapter should have write access to the repository.
    • Access permissions are reviewed regularly to ensure they align with the current team structure.
    • Two-factor authentication (2FA) is enforced for all accounts with write access to the repository.
  3. Code Review and Approval:

    • All code changes must go through a peer review process before being merged into the main branch.
    • Use GitHub's pull request feature to facilitate code reviews and discussions.
    • Reviewers should have the necessary security knowledge to identify and address potential security concerns.
  4. Issue and Bug Reporting:

    • If you find a bug or a security vulnerability, please raise a new issue on GitHub.
    • For sensitive security issues, please report them via our secure communication channel: Signal Group
    • Before creating a new issue, check if the bug or feature has already been reported to avoid duplicates.
  5. Dependencies and Updates:

    • Regularly update Hugo and any other dependencies to their latest stable versions to ensure security patches are applied.
    • Use tools like Dependabot to monitor and automate dependency updates.
  6. Deployment Security:

    • The website is deployed using Cloudflare pages, which provides DDoS protection and enhances the security of our site.
    • Deployment credentials and secrets are stored securely and not exposed in the codebase.
    • Secure communication channels (HTTPS) are used for all data transmissions during deployment.
  7. Monitoring and Logging:

    • Security monitoring tools are implemented to detect and respond to security incidents promptly.
    • Logs of access and changes to the repository are maintained for auditing and investigating suspicious activities.
    • Regular reviews of logs are conducted to identify potential security breaches or unauthorized access attempts.

Contributing

If you wish to contribute to the project:

  • Follow the detailed guidelines provided in the contribution guidelines for setting up the project locally and contributing.
  • Ensure all contributions comply with the security measures outlined in this policy.
  • Adhere to the security best practices and guidelines specific to this project.

Note

Please ensure that the bug/feature you are raising/requesting has not already been reported before you create a new issue!

By adhering to this security policy, we aim to maintain a secure, privacy-centric, and user-friendly website for the null NEU community.

There aren't any published security advisories

, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Add copy buttons to all
 blocks\n(function() {\n function addCopyButtons() {\n document.querySelectorAll('pre code').forEach(function(codeBlock) {\n if (codeBlock.parentElement.hasAttribute('data-copy-added')) return;\n codeBlock.parentElement.setAttribute('data-copy-added', 'true');\n \n var btn = document.createElement('button');\n btn.textContent = 'Copy';\n btn.style.cssText = 'position:absolute;top:4px;right:4px;padding:2px 8px;font-size:11px;background:#4ecdc4;border:none;border-radius:4px;color:#1a1a2e;cursor:pointer;opacity:0.7;transition:opacity 0.2s;';\n btn.onmouseover = function() { this.style.opacity = '1'; };\n btn.onmouseout = function() { this.style.opacity = '0.7'; };\n btn.onclick = function() {\n navigator.clipboard.writeText(codeBlock.textContent).then(function() {\n btn.textContent = 'Copied!';\n setTimeout(function() { btn.textContent = 'Copy'; }, 1500);\n });\n };\n codeBlock.parentElement.style.position = 'relative';\n codeBlock.parentElement.appendChild(btn);\n });\n }\n \n addCopyButtons();\n \n // Re-run on dynamic content\n var observer = new MutationObserver(addCopyButtons);\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Add Copy Buttons to Code Blocks");
}
} catch(__e) { console.warn('[Userscript:Add Copy Buttons to Code Blocks]', __e); }
})();
(function(){
try {
var __m = "github.com";
var __re = new RegExp('^' + "github\\.com" + '
Skip to content

Security: nullNEU/nullify

SECURITY.md

Security Policy for the official null NEU website aka 'nullify'

Repository

Name: nullify

Description: This repository houses all code (and data) related to the official website of the Northeastern University chapter of the null community.

Tech Stack

The website is built with Hugo, a popular static site generator written in Go. All the data displayed on the website is stored in .md files or .yaml files. The website is deployed using Cloudflare pages, ensuring high security, availability in different regions, and improved performance.

Privacy and Security Highlights

  • User Privacy Centric: Our website is designed with user privacy as a top priority, ensuring minimal data collection and usage.
  • Minimalistic Design: The site is intentionally minimalistic, making it easy for users to navigate and understand our content.
  • No JavaScript Dependency: We have avoided using JavaScript in our codebase, ensuring that the website remains fully functional even if all scripts are blocked on a user's browser.

Security Measures

  1. Data Integrity and Confidentiality:

    • All data files (.md and .yaml) are regularly reviewed to ensure they do not contain sensitive information.
    • Sensitive information should never be hardcoded into the codebase or configuration files.
    • Sensitive data, if required, should be encrypted and stored securely.
  2. Access Control:

    • Only authorized members of the null NEU chapter should have write access to the repository.
    • Access permissions are reviewed regularly to ensure they align with the current team structure.
    • Two-factor authentication (2FA) is enforced for all accounts with write access to the repository.
  3. Code Review and Approval:

    • All code changes must go through a peer review process before being merged into the main branch.
    • Use GitHub's pull request feature to facilitate code reviews and discussions.
    • Reviewers should have the necessary security knowledge to identify and address potential security concerns.
  4. Issue and Bug Reporting:

    • If you find a bug or a security vulnerability, please raise a new issue on GitHub.
    • For sensitive security issues, please report them via our secure communication channel: Signal Group
    • Before creating a new issue, check if the bug or feature has already been reported to avoid duplicates.
  5. Dependencies and Updates:

    • Regularly update Hugo and any other dependencies to their latest stable versions to ensure security patches are applied.
    • Use tools like Dependabot to monitor and automate dependency updates.
  6. Deployment Security:

    • The website is deployed using Cloudflare pages, which provides DDoS protection and enhances the security of our site.
    • Deployment credentials and secrets are stored securely and not exposed in the codebase.
    • Secure communication channels (HTTPS) are used for all data transmissions during deployment.
  7. Monitoring and Logging:

    • Security monitoring tools are implemented to detect and respond to security incidents promptly.
    • Logs of access and changes to the repository are maintained for auditing and investigating suspicious activities.
    • Regular reviews of logs are conducted to identify potential security breaches or unauthorized access attempts.

Contributing

If you wish to contribute to the project:

  • Follow the detailed guidelines provided in the contribution guidelines for setting up the project locally and contributing.
  • Ensure all contributions comply with the security measures outlined in this policy.
  • Adhere to the security best practices and guidelines specific to this project.

Note

Please ensure that the bug/feature you are raising/requesting has not already been reported before you create a new issue!

By adhering to this security policy, we aim to maintain a secure, privacy-centric, and user-friendly website for the null NEU community.

There aren't any published security advisories

, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Force GitHub README to respect dark mode\n(function() {\n var style = document.createElement('style');\n style.textContent = '\n .markdown-body {\n color-scheme: dark light;\n }\n .markdown-body pre { background: #161b22 !important; }\n .markdown-body code { background: rgba(110, 118, 129, 0.4) !important; }\n .markdown-body table th, .markdown-body table td { border-color: #30363d !important; }\n .markdown-body img { background: #0d1117; }\n .markdown-body blockquote { border-left-color: #8b949e; }\n .markdown-body hr { border-color: #30363d; }\n ';\n document.head.appendChild(style);\n})();", "GitHub Dark Mode README Fix"); } } catch(__e) { console.warn('[Userscript:GitHub Dark Mode README Fix]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

Security: nullNEU/nullify

SECURITY.md

Security Policy for the official null NEU website aka 'nullify'

Repository

Name: nullify

Description: This repository houses all code (and data) related to the official website of the Northeastern University chapter of the null community.

Tech Stack

The website is built with Hugo, a popular static site generator written in Go. All the data displayed on the website is stored in .md files or .yaml files. The website is deployed using Cloudflare pages, ensuring high security, availability in different regions, and improved performance.

Privacy and Security Highlights

  • User Privacy Centric: Our website is designed with user privacy as a top priority, ensuring minimal data collection and usage.
  • Minimalistic Design: The site is intentionally minimalistic, making it easy for users to navigate and understand our content.
  • No JavaScript Dependency: We have avoided using JavaScript in our codebase, ensuring that the website remains fully functional even if all scripts are blocked on a user's browser.

Security Measures

  1. Data Integrity and Confidentiality:

    • All data files (.md and .yaml) are regularly reviewed to ensure they do not contain sensitive information.
    • Sensitive information should never be hardcoded into the codebase or configuration files.
    • Sensitive data, if required, should be encrypted and stored securely.
  2. Access Control:

    • Only authorized members of the null NEU chapter should have write access to the repository.
    • Access permissions are reviewed regularly to ensure they align with the current team structure.
    • Two-factor authentication (2FA) is enforced for all accounts with write access to the repository.
  3. Code Review and Approval:

    • All code changes must go through a peer review process before being merged into the main branch.
    • Use GitHub's pull request feature to facilitate code reviews and discussions.
    • Reviewers should have the necessary security knowledge to identify and address potential security concerns.
  4. Issue and Bug Reporting:

    • If you find a bug or a security vulnerability, please raise a new issue on GitHub.
    • For sensitive security issues, please report them via our secure communication channel: Signal Group
    • Before creating a new issue, check if the bug or feature has already been reported to avoid duplicates.
  5. Dependencies and Updates:

    • Regularly update Hugo and any other dependencies to their latest stable versions to ensure security patches are applied.
    • Use tools like Dependabot to monitor and automate dependency updates.
  6. Deployment Security:

    • The website is deployed using Cloudflare pages, which provides DDoS protection and enhances the security of our site.
    • Deployment credentials and secrets are stored securely and not exposed in the codebase.
    • Secure communication channels (HTTPS) are used for all data transmissions during deployment.
  7. Monitoring and Logging:

    • Security monitoring tools are implemented to detect and respond to security incidents promptly.
    • Logs of access and changes to the repository are maintained for auditing and investigating suspicious activities.
    • Regular reviews of logs are conducted to identify potential security breaches or unauthorized access attempts.

Contributing

If you wish to contribute to the project:

  • Follow the detailed guidelines provided in the contribution guidelines for setting up the project locally and contributing.
  • Ensure all contributions comply with the security measures outlined in this policy.
  • Adhere to the security best practices and guidelines specific to this project.

Note

Please ensure that the bug/feature you are raising/requesting has not already been reported before you create a new issue!

By adhering to this security policy, we aim to maintain a secure, privacy-centric, and user-friendly website for the null NEU community.

There aren't any published security advisories

, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Highlight search terms from Google/DuckDuckGo/Bing referrer\n(function() {\n var ref = document.referrer;\n var terms = [];\n \n if (ref.includes('google.com') || ref.includes('duckduckgo.com') || ref.includes('bing.com')) {\n var url = new URL(ref);\n var q = url.searchParams.get('q') || url.searchParams.get('p');\n if (q) {\n terms = q.split(/\\s+/).filter(function(t) { return t.length > 2; });\n }\n }\n \n if (terms.length === 0) return;\n \n var style = document.createElement('style');\n style.textContent = '.userscript-highlight { background: #fbbf24; color: #1a1a2e; padding: 1px 3px; border-radius: 2px; }';\n document.head.appendChild(style);\n \n function highlight(node) {\n if (node.nodeType === 3) { // text node\n var text = node.textContent;\n var found = false;\n terms.forEach(function(term) {\n var regex = new RegExp('(' + term.replace(/[.*+?^${}()|[\\]\\\\]/g, '\\\\') + ')', 'gi');\n if (regex.test(text)) {\n found = true;\n var frag = document.createDocumentFragment();\n var parts = text.split(regex);\n parts.forEach(function(part, i) {\n if (i % 2 === 0) {\n frag.appendChild(document.createTextNode(part));\n } else {\n var span = document.createElement('span');\n span.className = 'userscript-highlight';\n span.textContent = part;\n frag.appendChild(span);\n }\n });\n node.parentNode.replaceChild(frag, node);\n }\n });\n } else if (node.nodeType === 1 && node.childNodes) { // element\n var skipTags = ['SCRIPT', 'STYLE', 'NOSCRIPT', 'TEXTAREA', 'INPUT', 'SELECT'];\n if (!skipTags.includes(node.tagName)) {\n Array.from(node.childNodes).forEach(highlight);\n }\n }\n }\n \n highlight(document.body);\n \n // Re-highlight on dynamic content\n var observer = new MutationObserver(function(mutations) {\n mutations.forEach(function(m) {\n m.addedNodes.forEach(function(node) {\n if (node.nodeType === 1 || node.nodeType === 3) highlight(node);\n });\n });\n });\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Highlight Search Terms"); } } catch(__e) { console.warn('[Userscript:Highlight Search Terms]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

Security: nullNEU/nullify

SECURITY.md

Security Policy for the official null NEU website aka 'nullify'

Repository

Name: nullify

Description: This repository houses all code (and data) related to the official website of the Northeastern University chapter of the null community.

Tech Stack

The website is built with Hugo, a popular static site generator written in Go. All the data displayed on the website is stored in .md files or .yaml files. The website is deployed using Cloudflare pages, ensuring high security, availability in different regions, and improved performance.

Privacy and Security Highlights

  • User Privacy Centric: Our website is designed with user privacy as a top priority, ensuring minimal data collection and usage.
  • Minimalistic Design: The site is intentionally minimalistic, making it easy for users to navigate and understand our content.
  • No JavaScript Dependency: We have avoided using JavaScript in our codebase, ensuring that the website remains fully functional even if all scripts are blocked on a user's browser.

Security Measures

  1. Data Integrity and Confidentiality:

    • All data files (.md and .yaml) are regularly reviewed to ensure they do not contain sensitive information.
    • Sensitive information should never be hardcoded into the codebase or configuration files.
    • Sensitive data, if required, should be encrypted and stored securely.
  2. Access Control:

    • Only authorized members of the null NEU chapter should have write access to the repository.
    • Access permissions are reviewed regularly to ensure they align with the current team structure.
    • Two-factor authentication (2FA) is enforced for all accounts with write access to the repository.
  3. Code Review and Approval:

    • All code changes must go through a peer review process before being merged into the main branch.
    • Use GitHub's pull request feature to facilitate code reviews and discussions.
    • Reviewers should have the necessary security knowledge to identify and address potential security concerns.
  4. Issue and Bug Reporting:

    • If you find a bug or a security vulnerability, please raise a new issue on GitHub.
    • For sensitive security issues, please report them via our secure communication channel: Signal Group
    • Before creating a new issue, check if the bug or feature has already been reported to avoid duplicates.
  5. Dependencies and Updates:

    • Regularly update Hugo and any other dependencies to their latest stable versions to ensure security patches are applied.
    • Use tools like Dependabot to monitor and automate dependency updates.
  6. Deployment Security:

    • The website is deployed using Cloudflare pages, which provides DDoS protection and enhances the security of our site.
    • Deployment credentials and secrets are stored securely and not exposed in the codebase.
    • Secure communication channels (HTTPS) are used for all data transmissions during deployment.
  7. Monitoring and Logging:

    • Security monitoring tools are implemented to detect and respond to security incidents promptly.
    • Logs of access and changes to the repository are maintained for auditing and investigating suspicious activities.
    • Regular reviews of logs are conducted to identify potential security breaches or unauthorized access attempts.

Contributing

If you wish to contribute to the project:

  • Follow the detailed guidelines provided in the contribution guidelines for setting up the project locally and contributing.
  • Ensure all contributions comply with the security measures outlined in this policy.
  • Adhere to the security best practices and guidelines specific to this project.

Note

Please ensure that the bug/feature you are raising/requesting has not already been reported before you create a new issue!

By adhering to this security policy, we aim to maintain a secure, privacy-centric, and user-friendly website for the null NEU community.

There aren't any published security advisories

, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Strip utm_, fbclid, gclid, etc. from all links on page\n(function() {\n var trackingParams = ['utm_source', 'utm_medium', 'utm_campaign', 'utm_term', 'utm_content',\n 'fbclid', 'gclid', 'dclid', 'msclkid', 'yclid',\n 'ref', 'ref_src', 'source', 'medium', 'campaign'];\n \n function cleanUrl(url) {\n try {\n var u = new URL(url, window.location.origin);\n var changed = false;\n trackingParams.forEach(function(p) {\n if (u.searchParams.has(p)) {\n u.searchParams.delete(p);\n changed = true;\n }\n });\n return changed ? u.toString() : url;\n } catch (e) {\n return url;\n }\n }\n \n function cleanLinks() {\n document.querySelectorAll('a[href]').forEach(function(a) {\n var clean = cleanUrl(a.href);\n if (clean !== a.href) a.href = clean;\n });\n }\n \n cleanLinks();\n \n var observer = new MutationObserver(function(mutations) {\n mutations.forEach(function(m) {\n m.addedNodes.forEach(function(node) {\n if (node.nodeType === 1) {\n if (node.tagName === 'A') cleanLinks();\n node.querySelectorAll('a[href]').forEach(function(a) {\n var clean = cleanUrl(a.href);\n if (clean !== a.href) a.href = clean;\n });\n }\n });\n });\n });\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Remove Tracking Parameters from Links"); } } catch(__e) { console.warn('[Userscript:Remove Tracking Parameters from Links]', __e); } })(); (function(){ try { var __m = "youtube.com"; var __re = new RegExp('^' + "youtube\\.com" + '
Skip to content

Security: nullNEU/nullify

SECURITY.md

Security Policy for the official null NEU website aka 'nullify'

Repository

Name: nullify

Description: This repository houses all code (and data) related to the official website of the Northeastern University chapter of the null community.

Tech Stack

The website is built with Hugo, a popular static site generator written in Go. All the data displayed on the website is stored in .md files or .yaml files. The website is deployed using Cloudflare pages, ensuring high security, availability in different regions, and improved performance.

Privacy and Security Highlights

  • User Privacy Centric: Our website is designed with user privacy as a top priority, ensuring minimal data collection and usage.
  • Minimalistic Design: The site is intentionally minimalistic, making it easy for users to navigate and understand our content.
  • No JavaScript Dependency: We have avoided using JavaScript in our codebase, ensuring that the website remains fully functional even if all scripts are blocked on a user's browser.

Security Measures

  1. Data Integrity and Confidentiality:

    • All data files (.md and .yaml) are regularly reviewed to ensure they do not contain sensitive information.
    • Sensitive information should never be hardcoded into the codebase or configuration files.
    • Sensitive data, if required, should be encrypted and stored securely.
  2. Access Control:

    • Only authorized members of the null NEU chapter should have write access to the repository.
    • Access permissions are reviewed regularly to ensure they align with the current team structure.
    • Two-factor authentication (2FA) is enforced for all accounts with write access to the repository.
  3. Code Review and Approval:

    • All code changes must go through a peer review process before being merged into the main branch.
    • Use GitHub's pull request feature to facilitate code reviews and discussions.
    • Reviewers should have the necessary security knowledge to identify and address potential security concerns.
  4. Issue and Bug Reporting:

    • If you find a bug or a security vulnerability, please raise a new issue on GitHub.
    • For sensitive security issues, please report them via our secure communication channel: Signal Group
    • Before creating a new issue, check if the bug or feature has already been reported to avoid duplicates.
  5. Dependencies and Updates:

    • Regularly update Hugo and any other dependencies to their latest stable versions to ensure security patches are applied.
    • Use tools like Dependabot to monitor and automate dependency updates.
  6. Deployment Security:

    • The website is deployed using Cloudflare pages, which provides DDoS protection and enhances the security of our site.
    • Deployment credentials and secrets are stored securely and not exposed in the codebase.
    • Secure communication channels (HTTPS) are used for all data transmissions during deployment.
  7. Monitoring and Logging:

    • Security monitoring tools are implemented to detect and respond to security incidents promptly.
    • Logs of access and changes to the repository are maintained for auditing and investigating suspicious activities.
    • Regular reviews of logs are conducted to identify potential security breaches or unauthorized access attempts.

Contributing

If you wish to contribute to the project:

  • Follow the detailed guidelines provided in the contribution guidelines for setting up the project locally and contributing.
  • Ensure all contributions comply with the security measures outlined in this policy.
  • Adhere to the security best practices and guidelines specific to this project.

Note

Please ensure that the bug/feature you are raising/requesting has not already been reported before you create a new issue!

By adhering to this security policy, we aim to maintain a secure, privacy-centric, and user-friendly website for the null NEU community.

There aren't any published security advisories

, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Auto-enable theater mode on YouTube\n(function() {\n function tryTheater() {\n var btn = document.querySelector('button[aria-label=\"Theater mode\"], ytd-player #player button[title=\"Theater mode\"]');\n if (btn && !btn.classList.contains('activated')) {\n btn.click();\n }\n }\n \n // Try immediately\n tryTheater();\n \n // Try after navigation (SPA)\n var lastUrl = location.href;\n setInterval(function() {\n if (location.href !== lastUrl) {\n lastUrl = location.href;\n setTimeout(tryTheater, 500);\n }\n }, 1000);\n \n // Also try on player load\n var observer = new MutationObserver(tryTheater);\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "YouTube Theater Mode Default"); } } catch(__e) { console.warn('[Userscript:YouTube Theater Mode Default]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

Security: nullNEU/nullify

SECURITY.md

Security Policy for the official null NEU website aka 'nullify'

Repository

Name: nullify

Description: This repository houses all code (and data) related to the official website of the Northeastern University chapter of the null community.

Tech Stack

The website is built with Hugo, a popular static site generator written in Go. All the data displayed on the website is stored in .md files or .yaml files. The website is deployed using Cloudflare pages, ensuring high security, availability in different regions, and improved performance.

Privacy and Security Highlights

  • User Privacy Centric: Our website is designed with user privacy as a top priority, ensuring minimal data collection and usage.
  • Minimalistic Design: The site is intentionally minimalistic, making it easy for users to navigate and understand our content.
  • No JavaScript Dependency: We have avoided using JavaScript in our codebase, ensuring that the website remains fully functional even if all scripts are blocked on a user's browser.

Security Measures

  1. Data Integrity and Confidentiality:

    • All data files (.md and .yaml) are regularly reviewed to ensure they do not contain sensitive information.
    • Sensitive information should never be hardcoded into the codebase or configuration files.
    • Sensitive data, if required, should be encrypted and stored securely.
  2. Access Control:

    • Only authorized members of the null NEU chapter should have write access to the repository.
    • Access permissions are reviewed regularly to ensure they align with the current team structure.
    • Two-factor authentication (2FA) is enforced for all accounts with write access to the repository.
  3. Code Review and Approval:

    • All code changes must go through a peer review process before being merged into the main branch.
    • Use GitHub's pull request feature to facilitate code reviews and discussions.
    • Reviewers should have the necessary security knowledge to identify and address potential security concerns.
  4. Issue and Bug Reporting:

    • If you find a bug or a security vulnerability, please raise a new issue on GitHub.
    • For sensitive security issues, please report them via our secure communication channel: Signal Group
    • Before creating a new issue, check if the bug or feature has already been reported to avoid duplicates.
  5. Dependencies and Updates:

    • Regularly update Hugo and any other dependencies to their latest stable versions to ensure security patches are applied.
    • Use tools like Dependabot to monitor and automate dependency updates.
  6. Deployment Security:

    • The website is deployed using Cloudflare pages, which provides DDoS protection and enhances the security of our site.
    • Deployment credentials and secrets are stored securely and not exposed in the codebase.
    • Secure communication channels (HTTPS) are used for all data transmissions during deployment.
  7. Monitoring and Logging:

    • Security monitoring tools are implemented to detect and respond to security incidents promptly.
    • Logs of access and changes to the repository are maintained for auditing and investigating suspicious activities.
    • Regular reviews of logs are conducted to identify potential security breaches or unauthorized access attempts.

Contributing

If you wish to contribute to the project:

  • Follow the detailed guidelines provided in the contribution guidelines for setting up the project locally and contributing.
  • Ensure all contributions comply with the security measures outlined in this policy.
  • Adhere to the security best practices and guidelines specific to this project.

Note

Please ensure that the bug/feature you are raising/requesting has not already been reported before you create a new issue!

By adhering to this security policy, we aim to maintain a secure, privacy-centric, and user-friendly website for the null NEU community.

There aren't any published security advisories

, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Remove or un-stick sticky/fixed headers that block content\n(function() {\n function unstick() {\n document.querySelectorAll('header, nav, [role=\"banner\"], .header, .navbar, .sticky, .fixed-top, [style*=\"position: fixed\"], [style*=\"position:sticky\"]').forEach(function(el) {\n if (el.style.position === 'fixed' || el.style.position === 'sticky' || \n getComputedStyle(el).position === 'fixed' || getComputedStyle(el).position === 'sticky') {\n el.style.position = 'static';\n el.style.top = 'auto';\n el.style.zIndex = 'auto';\n }\n });\n }\n \n unstick();\n \n var observer = new MutationObserver(unstick);\n observer.observe(document.body, { childList: true, subtree: true, attributes: true, attributeFilter: ['style', 'class'] });\n})();", "Kill Sticky Headers"); } } catch(__e) { console.warn('[Userscript:Kill Sticky Headers]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

Security: nullNEU/nullify

SECURITY.md

Security Policy for the official null NEU website aka 'nullify'

Repository

Name: nullify

Description: This repository houses all code (and data) related to the official website of the Northeastern University chapter of the null community.

Tech Stack

The website is built with Hugo, a popular static site generator written in Go. All the data displayed on the website is stored in .md files or .yaml files. The website is deployed using Cloudflare pages, ensuring high security, availability in different regions, and improved performance.

Privacy and Security Highlights

  • User Privacy Centric: Our website is designed with user privacy as a top priority, ensuring minimal data collection and usage.
  • Minimalistic Design: The site is intentionally minimalistic, making it easy for users to navigate and understand our content.
  • No JavaScript Dependency: We have avoided using JavaScript in our codebase, ensuring that the website remains fully functional even if all scripts are blocked on a user's browser.

Security Measures

  1. Data Integrity and Confidentiality:

    • All data files (.md and .yaml) are regularly reviewed to ensure they do not contain sensitive information.
    • Sensitive information should never be hardcoded into the codebase or configuration files.
    • Sensitive data, if required, should be encrypted and stored securely.
  2. Access Control:

    • Only authorized members of the null NEU chapter should have write access to the repository.
    • Access permissions are reviewed regularly to ensure they align with the current team structure.
    • Two-factor authentication (2FA) is enforced for all accounts with write access to the repository.
  3. Code Review and Approval:

    • All code changes must go through a peer review process before being merged into the main branch.
    • Use GitHub's pull request feature to facilitate code reviews and discussions.
    • Reviewers should have the necessary security knowledge to identify and address potential security concerns.
  4. Issue and Bug Reporting:

    • If you find a bug or a security vulnerability, please raise a new issue on GitHub.
    • For sensitive security issues, please report them via our secure communication channel: Signal Group
    • Before creating a new issue, check if the bug or feature has already been reported to avoid duplicates.
  5. Dependencies and Updates:

    • Regularly update Hugo and any other dependencies to their latest stable versions to ensure security patches are applied.
    • Use tools like Dependabot to monitor and automate dependency updates.
  6. Deployment Security:

    • The website is deployed using Cloudflare pages, which provides DDoS protection and enhances the security of our site.
    • Deployment credentials and secrets are stored securely and not exposed in the codebase.
    • Secure communication channels (HTTPS) are used for all data transmissions during deployment.
  7. Monitoring and Logging:

    • Security monitoring tools are implemented to detect and respond to security incidents promptly.
    • Logs of access and changes to the repository are maintained for auditing and investigating suspicious activities.
    • Regular reviews of logs are conducted to identify potential security breaches or unauthorized access attempts.

Contributing

If you wish to contribute to the project:

  • Follow the detailed guidelines provided in the contribution guidelines for setting up the project locally and contributing.
  • Ensure all contributions comply with the security measures outlined in this policy.
  • Adhere to the security best practices and guidelines specific to this project.

Note

Please ensure that the bug/feature you are raising/requesting has not already been reported before you create a new issue!

By adhering to this security policy, we aim to maintain a secure, privacy-centric, and user-friendly website for the null NEU community.

There aren't any published security advisories

, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Universal Dark Mode - works on any site\n(function() {\n var enabled = true;\n \n function applyDarkMode() {\n if (!enabled) return;\n \n // Create style element if it doesn't exist\n var style = document.getElementById('universal-dark-mode-style');\n if (!style) {\n style = document.createElement('style');\n style.id = 'universal-dark-mode-style';\n document.head.appendChild(style);\n }\n \n // Dark mode CSS - inverts colors but preserves images/video\n style.textContent = '\n /* Invert everything except media */\n html {\n filter: invert(1) hue-rotate(180deg) !important;\n background: #1a1a2e !important;\n }\n \n /* Restore images, videos, iframes, canvas */\n img, video, iframe, canvas, svg, picture, [style*=\"background-image\"] {\n filter: invert(1) hue-rotate(180deg) !important;\n }\n \n /* Preserve specific elements that should not be inverted */\n .no-dark-mode, .no-dark-mode *,\n [data-theme=\"light\"], [data-theme=\"light\"],\n .ace_editor, .ace_editor *,\n .CodeMirror, .CodeMirror *,\n .monaco-editor, .monaco-editor *,\n .markdown-body pre, .markdown-body pre *,\n .highlight, .highlight *,\n pre code, pre code * {\n filter: none !important;\n }\n \n /* Fix common UI elements */\n .modal, .popup, .dropdown-menu, .tooltip, .popover {\n filter: invert(1) hue-rotate(180deg) !important;\n background: #2d2d44 !important;\n border-color: #444 !important;\n }\n \n /* Scrollbars */\n ::-webkit-scrollbar { background: #1a1a2e !important; }\n ::-webkit-scrollbar-thumb { background: #444 !important; }\n ::-webkit-scrollbar-thumb:hover { background: #555 !important; }\n \n /* Selection */\n ::selection { background: #4ecdc4 !important; color: #1a1a2e !important; }\n ::-moz-selection { background: #4ecdc4 !important; color: #1a1a2e !important; }\n ';\n }\n \n function removeDarkMode() {\n var style = document.getElementById('universal-dark-mode-style');\n if (style) style.remove();\n }\n \n // Toggle with Alt+Shift+D\n document.addEventListener('keydown', function(e) {\n if (e.altKey && e.shiftKey && e.key === 'D') {\n e.preventDefault();\n enabled = !enabled;\n if (enabled) {\n applyDarkMode();\n console.log('[Universal Dark Mode] Enabled');\n } else {\n removeDarkMode();\n console.log('[Universal Dark Mode] Disabled');\n }\n }\n });\n \n // Apply on load\n applyDarkMode();\n \n // Re-apply on dynamic content\n var observer = new MutationObserver(function(mutations) {\n if (enabled && !document.getElementById('universal-dark-mode-style')) {\n applyDarkMode();\n }\n });\n observer.observe(document.head, { childList: true });\n \n console.log('[Universal Dark Mode] Loaded - Press Alt+Shift+D to toggle');\n})();", "Universal Dark Mode"); } } catch(__e) { console.warn('[Userscript:Universal Dark Mode]', __e); } })(); })();
Skip to content

Security: nullNEU/nullify

SECURITY.md

Security Policy for the official null NEU website aka 'nullify'

Repository

Name: nullify

Description: This repository houses all code (and data) related to the official website of the Northeastern University chapter of the null community.

Tech Stack

The website is built with Hugo, a popular static site generator written in Go. All the data displayed on the website is stored in .md files or .yaml files. The website is deployed using Cloudflare pages, ensuring high security, availability in different regions, and improved performance.

Privacy and Security Highlights

  • User Privacy Centric: Our website is designed with user privacy as a top priority, ensuring minimal data collection and usage.
  • Minimalistic Design: The site is intentionally minimalistic, making it easy for users to navigate and understand our content.
  • No JavaScript Dependency: We have avoided using JavaScript in our codebase, ensuring that the website remains fully functional even if all scripts are blocked on a user's browser.

Security Measures

  1. Data Integrity and Confidentiality:

    • All data files (.md and .yaml) are regularly reviewed to ensure they do not contain sensitive information.
    • Sensitive information should never be hardcoded into the codebase or configuration files.
    • Sensitive data, if required, should be encrypted and stored securely.
  2. Access Control:

    • Only authorized members of the null NEU chapter should have write access to the repository.
    • Access permissions are reviewed regularly to ensure they align with the current team structure.
    • Two-factor authentication (2FA) is enforced for all accounts with write access to the repository.
  3. Code Review and Approval:

    • All code changes must go through a peer review process before being merged into the main branch.
    • Use GitHub's pull request feature to facilitate code reviews and discussions.
    • Reviewers should have the necessary security knowledge to identify and address potential security concerns.
  4. Issue and Bug Reporting:

    • If you find a bug or a security vulnerability, please raise a new issue on GitHub.
    • For sensitive security issues, please report them via our secure communication channel: Signal Group
    • Before creating a new issue, check if the bug or feature has already been reported to avoid duplicates.
  5. Dependencies and Updates:

    • Regularly update Hugo and any other dependencies to their latest stable versions to ensure security patches are applied.
    • Use tools like Dependabot to monitor and automate dependency updates.
  6. Deployment Security:

    • The website is deployed using Cloudflare pages, which provides DDoS protection and enhances the security of our site.
    • Deployment credentials and secrets are stored securely and not exposed in the codebase.
    • Secure communication channels (HTTPS) are used for all data transmissions during deployment.
  7. Monitoring and Logging:

    • Security monitoring tools are implemented to detect and respond to security incidents promptly.
    • Logs of access and changes to the repository are maintained for auditing and investigating suspicious activities.
    • Regular reviews of logs are conducted to identify potential security breaches or unauthorized access attempts.

Contributing

If you wish to contribute to the project:

  • Follow the detailed guidelines provided in the contribution guidelines for setting up the project locally and contributing.
  • Ensure all contributions comply with the security measures outlined in this policy.
  • Adhere to the security best practices and guidelines specific to this project.

Note

Please ensure that the bug/feature you are raising/requesting has not already been reported before you create a new issue!

By adhering to this security policy, we aim to maintain a secure, privacy-centric, and user-friendly website for the null NEU community.

There aren't any published security advisories