Show HN: GitHub Repository Card for Every Web Site
github.com
github.com
Only big money can be trusted.
(i'm obviously not serious here, but i do find it sad how people are fine trusting projects by FAANG, Microsoft, IBM and others of similar scale but once something is made by someone with a human face it suddenly is a problem unless it is a toy)
If the product was released by some self-sustaining entity like a business, foundation or otherwise bankrolled and staffed by parties with an interest in keeping it up then it would be much less of an issue.
The value in almost all software is the maintenance. React being good software is one thing, but what makes it so attractive is that Facebook and (and these days many others) have a financial interest in keeping it maintained.
If you're using the hosted version, you have no idea whether or not the modules are being updated, which versions are in use, etc.
Having control of your environment gives you the opportunity to be more (or even less) secure. It's important to fully understand the risk / potential harm that outsourcing that responsibility to random persons can have.
I suppose you could parse that SVG in an insecure way (if for some reason you were parsing it) but that's not a problem with using the service.
Also, try to find if user pasted the complete github.com url; & strip it before processing it.
But a question - once the SVG/PNG is generated, is it updated when the repo stats change?
---
By the way, I'm a huge fan of your work!
I'm sure others would find it enjoyable to see the creative and minimalist software: https://nwtgck.github.io/portfolio/
Hmm, perhaps the SVG can be regenerated on the server-side during a build step or static site generation. That might remove the dependency at least on the client side.
From the title, I thought this was cataloging every web site.