The badge image is vendored rather than hotlinked from snapcraft.io. The CSP is img-src 'self' data: and would block it anyway, but the reason to leave the CSP alone is the page's own claim: fetching a badge from someone else's server hands them the address of every visitor to a page that says no servers are involved. The README badge stays dynamic — it reports the published version, and GitHub proxies images, so no reader is exposed by it.
10 lines
263 B
JSON
10 lines
263 B
JSON
{
|
|
"version": "1788390440675",
|
|
"buildVersion": "1788390440675",
|
|
"appVersion": "6.7.2",
|
|
"buildTime": "2026-09-02T23:07:20.764Z",
|
|
"buildId": "1788390440675-30e335f",
|
|
"gitHash": "30e335f",
|
|
"generated": true,
|
|
"generatedAt": "2026-09-02T23:07:20.766Z"
|
|
} |