5 ms·
Show HN: GitHub Repository Card for Every Web Site
- davchana 7y agoIt outputs an not-found image if we click the button Generate with nothing in the text box. Also, try to find if user pasted the complete github.com url; & strip it before processing it.
- floatingatoll 7y agoSecurity note: Please remember that, while this is a great idea, it’s also an excellent platform for causing havoc such as phishing if the operator’s account is ever hacked or turns malicious. For demo purposes it’s obviously fine but do not make this live without hosting your own, or consider the risk of it sending users to e.g. “glthub.com” someday.
- deleted 7y ago[deleted]
- ly 7y agoThe link to the github repo is located in the code you paste on your own website, so you already host that part yourself. The only thing someone could change if the account is hacked is the contents of the image.
- oarsinsync 7y agoIf gh-card.dev ever changes, you might find javascript being injected via the SVG instead of it just being an image. That's what the GP is alluding to, and recommending you host the gh-card code yourself rather than using their hosted instance.
- TazeTSchnitzel 7y agoSVGs used as the src= of an <img> tag can't run scripts.
- btown 7y agoYep: https://www.w3.org/wiki/SVG_Security https://www.w3.org/wiki/SVG_Security
- jbverschoor 7y agoWhat about all the npm modules?
- floatingatoll 7y agoIt’s turtles all the way down. The point here is that people don’t consider third-party content inclusion to be more of a risk than “completely harmless”, which is generally false: the risk may or may not be slight, but it’s never non-zero.
- oarsinsync 7y agoAnd to follow up specifically to the npm modules, if you're self hosted, you can (but probably wont) audit the contents of what's been deployed when you deploy. You can then also keep that snapshot frozen in time, so you wont necessarily be impacted by any changes to those modules in future. If you're using the hosted version, you have no idea whether or not the modules are being updated, which versions are in use, etc. Having control of your environment gives you the opportunity to be more (or even less) secure. It's important to fully understand the risk / potential harm that outsourcing that responsibility to random persons can have.
- albertgoeswoof 7y agoHow is this any different from hotlinking an image? I don't understand the security risk here? If a bad actor gets control of the domain all they can do is change the svg that you render. I suppose you could parse that SVG in an insecure way (if for some reason you were parsing it) but that's not a problem with using the service.
- devbat8712 7y agoI agree that it's probably safe, but SVG can contain script tags.
- ecares 7y agoSeems that private repos trigger a 500 error ;)
- teknologist 7y agoPlease, please wrap that text box and button in a <form> so that when we press "enter" the form submits. HTML 101.
- reimertz 7y agoFYI, this comment would’ve been completely fine without “HTML 101”.
- brogrammernot 7y agoPlease submit a PR. Open source 101
- philshem 7y agoThe images don't work for me: Internal error in the request But a question - once the SVG/PNG is generated, is it updated when the repo stats change?
- t0astbread 7y agoWhy is everyone so negative again? This is cool!
- Crinus 7y agoBecause since it wasn't made by a big multibillion corporation, it is inherently unsafe, like every other thing not made by big multibillion corporations. Only big money can be trusted. (i'm obviously not serious here, but i do find it sad how people are fine trusting projects by FAANG, Microsoft, IBM and others of similar scale but once something is made by someone with a human face it suddenly is a problem unless it is a toy)
- oauea 7y agoMicrosoft owns GitHub. So this was created by Microsoft.
- Crinus 7y agoIs this some joke i didn't understood? The linked project doesn't look like it was created by Microsoft or GitHub. Is the author working at Microsoft?
- deleted 7y ago[deleted]
- Spivak 7y agoBecause single humans are busy, get bored, get distracted, stop wanting to maintain servers, stop wanting to pay for servers etc.. If the product was released by some self-sustaining entity like a business, foundation or otherwise bankrolled and staffed by parties with an interest in keeping it up then it would be much less of an issue. The value in almost all software is the maintenance. React being good software is one thing, but what makes it so attractive is that Facebook and (and these days many others) have a financial interest in keeping it maintained.
- Crinus 7y ago
- dotdi 7y agoThis would be awesome with a dark theme.
- chiefalchemist 7y agoSomething similar for GitLab? Please??
- MH15 7y agoMake it.
- captn3m0 7y agoI was thinking of doing something similar with auto-generated SVG files for open graph images. Does anyone know if FB/Twitter etc support SVG images for open graph content?
- deleted 7y ago[deleted]
- bytematic 7y agoShould make the ability to do dark mode on that card, I would but I have no experience with that stack
- weka 7y agoThis is really cool. One could easily put these into other repos to show stats.
- pronoiac 7y agoAh. GitHub repo cards, for embedding anywhere. From the title, I thought this was cataloging every web site.
- lioeters 7y agoI wonder, is it necessary to depend on a third-party server (gh-cards.dev)? The SVG file could be embedded inline, or downloaded and served locally. --- By the way, I'm a huge fan of your work! I'm sure others would find it enjoyable to see the creative and minimalist software: https://nwtgck.github.io/portfolio/ https://nwtgck.github.io/portfolio/
- cosmic_quanta 7y agoIf the SVG was embedded, you would have to periodically re-upload a file to update the stars/fork stats no?
- lioeters 7y agoAhh, I see what you mean. You're right, so the card server does have a purpose. Hmm, perhaps the SVG can be regenerated on the server-side during a build step or static site generation. That might remove the dependency at least on the client side.
- kevinzg 7y agoThe star and fork counter wouldn't update
- vipref 7y agoThis is cool!