The following URL (usually /.git/config) is publicly accessible and is leaking source code and repository configuration.
Severity: medium
Fingerprint: 2580fa947178c88602b1737db148c044b81b03713d63bb82370a65228c90bd0e
[core] repositoryformatversion = 0 filemode = true bare = false logallrefupdates = true symlinks = true ignorecase = false precomposeunicode = false [remote "origin"] url = git@git.sr.ht:~sircmpwn/builtwithhare.org fetch = +refs/heads/*:refs/remotes/origin/*
Open service 46.23.81.157:443 · builtwithhare.org
2026-01-23 13:01
HTTP/1.1 200 OK Access-Control-Allow-Origin: * Access-Control-Request-Methods: GET, HEAD, OPTIONS Content-Length: 1525 Content-Security-Policy: default-src 'self' data: blob:; script-src 'self' 'unsafe-eval' 'unsafe-inline'; style-src 'self' 'unsafe-inline'; worker-src 'self' 'unsafe-eval' 'unsafe-inline' data: blob:; frame-src https:; img-src data: https:; media-src https:; object-src 'none'; sandbox allow-downloads allow-forms allow-modals allow-pointer-lock allow-popups allow-presentation allow-same-origin allow-scripts; Content-Type: text/html; charset=utf-8 Last-Modified: Sun, 21 Sep 2025 09:19:25 GMT Vary: Accept-Encoding Date: Fri, 23 Jan 2026 13:01:36 GMT Connection: close <!doctype html> <html lang="en"> <meta charset="utf-8" /> <link rel="stylesheet" type="text/css" href="styles.css"> <link rel="icon" type="image/png" href="/mascot.png"> <img src="mascot.png" alt="The Hare mascot, a cute fuzzy bunny" /> <h1>Built With Hare</h1> <p> builtwithhare.org hosts subdomains for various projects built with the <a href="https://harelang.org">Hare programming language</a>. If you want a builtwithhare.org subdomain to host your Hare project's website and documentation, please write to the <a href="https://lists.sr.ht/~sircmpwn/hare-users">hare-users</a> mailing list to request one! </p> <h2>Projects hosted here</h2> <ul> <li> <a href="https://bonsai.builtwithhare.org">bonsai</a>: a finite state machine to trigger complex workflows of commands </li> <li> <a href="https://git.builtwithhare.org">hare-git</a>: git library </li> <li> <a href="https://mcron.builtwithhare.org">mcron</a>: an interruptable cron daemon for frequently-suspended devices such as mobile phones </li> <li> <a href="https://splitter.builtwithhare.org">splitter</a>: The Linux speedrun companion </li> <li> <a href="https://sxmobar.builtwithhare.org">sxmobar</a>: A status line manager for i3, sway, etc </li> <li> <a href="https://wren.builtwithhare.org">hare-wren</a>: Hare support for the Wren embedded scripting language </li> </ul> <hr /> <p> Looking for more Hare projects? Check out the <a href="https://harelang.org/project-library/">project library</a>! </p>
Open service 46.23.81.157:443 · builtwithhare.org
2026-01-10 01:38
HTTP/1.1 200 OK Access-Control-Allow-Origin: * Access-Control-Request-Methods: GET, HEAD, OPTIONS Content-Length: 1525 Content-Security-Policy: default-src 'self' data: blob:; script-src 'self' 'unsafe-eval' 'unsafe-inline'; style-src 'self' 'unsafe-inline'; worker-src 'self' 'unsafe-eval' 'unsafe-inline' data: blob:; frame-src https:; img-src data: https:; media-src https:; object-src 'none'; sandbox allow-downloads allow-forms allow-modals allow-pointer-lock allow-popups allow-presentation allow-same-origin allow-scripts; Content-Type: text/html; charset=utf-8 Last-Modified: Sun, 21 Sep 2025 09:19:25 GMT Vary: Accept-Encoding Date: Sat, 10 Jan 2026 01:38:13 GMT Connection: close <!doctype html> <html lang="en"> <meta charset="utf-8" /> <link rel="stylesheet" type="text/css" href="styles.css"> <link rel="icon" type="image/png" href="/mascot.png"> <img src="mascot.png" alt="The Hare mascot, a cute fuzzy bunny" /> <h1>Built With Hare</h1> <p> builtwithhare.org hosts subdomains for various projects built with the <a href="https://harelang.org">Hare programming language</a>. If you want a builtwithhare.org subdomain to host your Hare project's website and documentation, please write to the <a href="https://lists.sr.ht/~sircmpwn/hare-users">hare-users</a> mailing list to request one! </p> <h2>Projects hosted here</h2> <ul> <li> <a href="https://bonsai.builtwithhare.org">bonsai</a>: a finite state machine to trigger complex workflows of commands </li> <li> <a href="https://git.builtwithhare.org">hare-git</a>: git library </li> <li> <a href="https://mcron.builtwithhare.org">mcron</a>: an interruptable cron daemon for frequently-suspended devices such as mobile phones </li> <li> <a href="https://splitter.builtwithhare.org">splitter</a>: The Linux speedrun companion </li> <li> <a href="https://sxmobar.builtwithhare.org">sxmobar</a>: A status line manager for i3, sway, etc </li> <li> <a href="https://wren.builtwithhare.org">hare-wren</a>: Hare support for the Wren embedded scripting language </li> </ul> <hr /> <p> Looking for more Hare projects? Check out the <a href="https://harelang.org/project-library/">project library</a>! </p>