Hacktoberfest 2026:维护者为十月标记出来的 issue,仍然开放、适合新手。 浏览 Hacktoberfest issue

Resolve "Potentially unsafe external link" for Carbon Five in `_includes/about-page/about-card-sponsors.html`

未关闭 适合新手
#8,824 0 条评论 0 个 reaction 已指派 0 人 在 GitHub 查看

维护者通常 1 天内回复

还没有人认领这个 Issue。

评估

难度
1/5
预计耗时
1-3 小时
新手友好度
88/100
Issue 类型
缺陷
描述清晰度
描述清楚
活跃度
活跃
技术栈
docker, html
领域
security

调研方向

打开 _includes/about-page/about-card-sponsors.html,找到 issue 中显示的 Carbon Five 链接。添加指定的 rel 属性,然后使用 Docker 检查 /about 在移动端、平板和桌面视图下的显示。确认链接仍然有效,并按预期打开。安全属性存在且这些检查均通过后,即可完成。

由索引模型根据 Issue 内容生成。

描述

Feature: Code Alerts good first issue P-Feature: Project Info and Page role: back end/devOps role: front end size: 0.25pt
Prerequisite
  1. Be a member of Hack for LA. (There are no fees to join.) If you have not joined yet, please follow the steps on our Getting Started page.
  2. Before you claim or start working on an issue, please make sure you have read our How to Contribute to Hack for LA Guide.
Overview

We need to fix a potentially unsafe external link by adding the attribute rel="noopener noreferrer". The problem and solution are similar to those detailed in the CodeQL alerts tracked in #5129; however, the instance addressed by this issue did not result in a CodeQL alert.

Action Items
  • Open the file _includes/about-page/about-card-sponsors.html in your IDE
  • Replace
<a href="https://www.carbonfive.com" target="_blank" alt="Carbon Five">

with

<a href="https://www.carbonfive.com" target="_blank" alt="Carbon Five" rel="noopener noreferrer">
  • Using Docker, check the /about page and confirm that the page remains the same in mobile, tablet, and desktop views as on the current website.
  • Confirm that the Carbon Five link still works and opens as expected.
Merge Team
  • When this issue is completed, check off the corresponding item in #5129
Resources/Instructions
  1. GitHub CodeQL documentation
  2. Webpage: https://www.hackforla.org/about/
  3. This issue is part of #5129
主要语言
JavaScript
星标
364
派生
871
平均合并
4 天 7 小时
30 天内合并 PR
13

环境准备

从这里开始

  1. 先读完整个 Issue,再读项目的贡献指南。
  2. 在 Issue 下留言说明你要接手 —— 这能避免两个人做同样的事。
  3. Fork 仓库,在一个分支上完成修改。
  4. 提交 Pull Request,并在描述里引用这个 Issue 编号。

hackforla/website 的其他 Issue

查看 hackforla/website 的全部 Issue

相似的 Issue

更多 JavaScript Issue

把新 issue 发到你的邮箱

精选适合新手参与的 GitHub issue 摘要。