Seguridad

Esta página, auditada

Aquí no hay ni una cifra escrita a mano. Todas salen del lockfile, del package.json, de la política de pnpm, de los workflows o de git, en tiempo de build.

En el build

  • Commita5ea414
  • Firmaválida
  • Build2026-09-16 06:11 UTC
  • Node24.20.0
  • pnpm11.26.0
  • Dependencias directas11
  • Total resueltas478
  • Versiones sin fijar0
  • Cuarentena7 días
  • Scripts permitidosesbuild, lefthook, sharp, workerd
  • Actions fijadas por SHA6/6

En tu navegador, ahora

  • Hashes CSP
  • JS externo
  • Cabeceras

Las cabeceras las sirve Cloudflare desde public/_headers, así que en local no aparecen. Es lo esperado, no un fallo.

Scan de Prowler

Prowler audita la configuración de este mismo repo en GitHub. Los resultados de abajo son reales y sin tocar, del último scan.

67%controles en verde
  • En verde 12
  • En rojo 6
  • Repo danibarranqueroo/portfolio
  • Prowler v5.42.0
  • Fecha 2026-09-11

Lo que falla, y por qué sigue fallando

  • altaRepository default branch dismisses stale pull request approvals
    repository_default_branch_dismisses_stale_reviews

    riesgo asumidoDepends on a pull-request review workflow, which a solo repository does not run.

  • altaRepository default branch requires code owner approval for changes to owned code
    repository_default_branch_requires_codeowners_review

    riesgo asumidoCode owner review means reviewing your own code on a solo repository. CODEOWNERS exists so ownership is explicit, but enforcing self-review would be theatre.

  • altaRepository default branch requires status checks
    repository_default_branch_status_checks_required

    pendienteCI already runs lint, typecheck, build, audit, gitleaks and a SHA-pin check on every push. Making them a merge gate requires moving to a pull-request workflow.

  • altaRepository has secret scanning enabled to detect sensitive data
    repository_secret_scanning_enabled

    bloqueadoGitHub only offers secret scanning for public repositories or paid plans. The GitHub API rejects it here with a 422. Gitleaks runs on every pull request instead, which covers the same ground from CI.

  • mediaRepository default branch requires conversation resolution before merging
    repository_default_branch_requires_conversation_resolution

    riesgo asumidoDepends on a pull-request review workflow, which a solo repository does not run.

  • mediaRepository default branch requires at least 2 approvals for code changes
    repository_default_branch_requires_multiple_approvals

    riesgo asumidoRequires two approving reviews. This is a one-person repository, so a second approver does not exist. Stated rather than hidden.

En verde

  • Repository default branch denies force pushes
  • Repository default branch protection applies to administrators
  • Repository enforces branch protection on the default branch
  • Repository default branch requires signed commits
  • Repository grants workflows a read-only default GITHUB_TOKEN
  • Repository has package vulnerability scanning (Dependabot alerts) enabled
  • Repository has immutable releases enabled
  • Repository denies default branch deletion
  • Repository has a CODEOWNERS file
  • Repository is archived or active within the configured inactivity threshold
  • Repository deletes branches after pull request merge
  • Repository default branch requires linear history

Nada de esto está escrito a mano: el JSON-OCSF de Prowler se normaliza en el build. Los fallos se muestran tal cual, con su motivo; esconderlos dejaría la página sin sentido.

Encuentra la mala configuración

Tres configuraciones reales. Haz clic en la línea peligrosa de cada una.0/3

Política de bucket S3

Política IAM

Grupo de seguridad