Skip to content

fix: add rel='noopener noreferrer' to external links - #729

Open
Pranav-IIITM wants to merge 2 commits into
goharbor:mainfrom
Pranav-IIITM:fix/add-noopener-noreferrer
Open

Pranav-IIITM wants to merge 2 commits into
goharbor:mainfrom
Pranav-IIITM:fix/add-noopener-noreferrer

Conversation

@Pranav-IIITM

@Pranav-IIITM Pranav-IIITM commented Jun 29, 2026 •

Copy link
Copy Markdown

Summary

All external links using target="_blank" across the site's partials, shortcodes, and render hooks were missing the rel="noopener noreferrer" attribute, exposing the site to reverse tabnapping attacks and minor performance issues. This PR fixes all affected files.

Closes #726

Changes Made

Added rel="noopener noreferrer" to all target="_blank" links in the following files:

  • layouts/partials/social-buttons.html — GitHub, Twitter, Slack links
  • layouts/partials/navbar.html — External top menu links
  • layouts/partials/home/hero.html — Download releases button
  • layouts/partials/home/project.html — Community link
  • layouts/partials/footer.html — GitHub, Status Page, Logos, Slack, Twitter, CC-BY-4.0 License, The Linux Foundation, Trademark Usage links
  • layouts/partials/docs/sidebar.html — GitHub source & issues links
  • layouts/partials/cli-docs/sidebar.html — GitHub source & issues links
  • layouts/partials/blog/posts.html — External blog links
  • layouts/_default/_markup/render-link.html — Markdown render hook external links
  • layouts/404.html — External menu links on 404 page
  • layouts/shortcodes/community-info.html — Meeting notes, mailing list, YouTube links
  • layouts/shortcodes/social.html — Distribution list links

Before & After

Before

<a href="https://example.com" target="_blank">Link</a>

After

<a href="https://example.com" target="_blank" rel="noopener noreferrer">Link</a>

Why It Matters

  • Security — Prevents reverse tabnapping attacks where a newly opened tab could access window.opener and redirect the original page to a malicious URL
  • Privacy — noreferrer stops the browser from sending the Referer header, preventing the origin URL from leaking to external sites
  • Performance — noopener ensures the new tab runs in a separate process, improving performance in some browsers

References

Checklist

  • All target="_blank" links now include rel="noopener noreferrer"
  • No existing functionality or styling affected
  • Changes verified across all affected partials, shortcodes, and render hooks

Adds rel='noopener noreferrer' to all target='_blank' links across the site's layout partials to improve security and performance.

Signed-off-by: Pranav-IIITM <jogdandpranav2007@gmail.com>
@Pranav-IIITM

Copy link
Copy Markdown
Author

@zyyw @OrlinVasilev @AllForNothing Please review the PR !!

@Vad1mo
Vad1mo requested a review from Copilot July 6, 2026 06:17
@Vad1mo
Vad1mo enabled auto-merge (squash) July 6, 2026 06:18

Copilot AI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

This PR hardens the site’s Hugo partial templates by adding rel="noopener noreferrer" to anchors that open in a new tab (target="_blank"), mitigating reverse-tabnapping risk and addressing the security intent in issue #726.

Changes:

  • Added rel="noopener noreferrer" to social button links that open in a new tab.
  • Added rel="noopener noreferrer" to external navbar/footer/docs/blog links that open in a new tab.
  • Updated docs/CLI sidebar and blog post link partials to include the rel attribute alongside target="_blank".

Reviewed changes

Copilot reviewed 8 out of 8 changed files in this pull request and generated 1 comment.

Show a summary per file
File Description
layouts/partials/social-buttons.html Adds rel="noopener noreferrer" to social links opened in a new tab.
layouts/partials/navbar.html Adds rel to external menu items that use target="_blank".
layouts/partials/home/project.html Adds rel to the community button link opened in a new tab.
layouts/partials/home/hero.html Adds rel to the GitHub releases download link.
layouts/partials/footer.html Adds rel to multiple external footer links opened in a new tab.
layouts/partials/docs/sidebar.html Adds rel to source/issues sidebar buttons opened in a new tab.
layouts/partials/cli-docs/sidebar.html Adds rel to source/issues sidebar buttons opened in a new tab.
layouts/partials/blog/posts.html Adds rel to external blog links opened in a new tab.

💡 Add Copilot custom instructions for smarter, more guided reviews. Learn how to get started.

Comment thread layouts/partials/navbar.html
Signed-off-by: Pranav-IIITM <jogdandpranav2007@gmail.com>
auto-merge was automatically disabled July 6, 2026 08:53

Head branch was pushed to by a user without write access

Copilot AI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Copilot reviewed 12 out of 12 changed files in this pull request and generated 1 comment.

Comment thread layouts/_default/_markup/render-link.html

Copilot AI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Copilot reviewed 12 out of 12 changed files in this pull request and generated no new comments.

Copilot AI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Copilot reviewed 12 out of 12 changed files in this pull request and generated no new comments.

@Pranav-IIITM

Copy link
Copy Markdown
Author

Hey @zyyw @AllForNothing — this just needs one more approval to clear the 2-reviewer requirement, checks are all green. Would appreciate a look when you get a chance

@Vad1mo Vad1mo left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

The render hook change in layouts/_default/_markup/render-link.html is the one that matters, since it covers every external link in markdown content. Three things before this can land:

  1. It no longer merges. layouts/partials/footer.html was rewritten in #727, so the Linux Foundation and Trademark Usage anchors this patches are gone from main. Needs a rebase.
  2. layouts/partials/home/project.html:51 links to /community, which is internal. Adding rel="noopener noreferrer" there is wrong; the actual bug on that line is the target="_blank" on a same-site link, which should be dropped instead.
  3. Use rel="noopener" rather than noopener noreferrer. noreferrer strips the Referer on links to our own GitHub, Slack and status page and costs us referral attribution, without adding anything to the stated goal.

Worth noting for the description: noopener has been implied for target="_blank" in all current browsers since 2021, so this is hygiene rather than a live vulnerability.

@Vad1mo Vad1mo left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

The render hook change in layouts/_default/_markup/render-link.html is the one that matters, since it covers every external link in markdown content. Three things before this can land:

  1. It no longer merges. layouts/partials/footer.html was rewritten in #727, so the Linux Foundation and Trademark Usage anchors this patches are gone from main. Needs a rebase.
  2. layouts/partials/home/project.html:51 links to /community, which is internal. Adding rel="noopener noreferrer" there is wrong; the actual bug on that line is the target="_blank" on a same-site link, which should be dropped instead.
  3. Use rel="noopener" rather than noopener noreferrer. noreferrer strips the Referer on links to our own GitHub, Slack and status page and costs us referral attribution, without adding anything to the stated goal.

Worth noting for the description: noopener has been implied for target="_blank" in all current browsers since 2021, so this is hygiene rather than a live vulnerability.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

[Security] Add rel="noopener noreferrer" to all external links with target="_blank"

6 participants