$ cat colophon.md

How this site is made

This site is served as static files by nginx in a container. It documents its software stack, build pipeline, quality gates, performance budget, correction policy, and public disclosures.

Software Stack and Hosting

The site is built with Astro and TypeScript, using playwright-core for browser verification.

The server sets HTTP security and cache headers including Content-Security-Policy, Permissions-Policy, Referrer-Policy, Strict-Transport-Security, X-Content-Type-Options, and X-Frame-Options.

Build Pipeline

The build pipeline executes prebuild steps, the Astro build, and postbuild steps.

Prebuild steps generate data, validate claims, and run the source, freshness and publication gates.

The build step executes astro build.

Postbuild steps generate preview pages, the sitemap and the page list in llms.txt, followed by verification gates over the built output.

Quality Gates

The pipeline runs quality gates before the build to verify sources and after the build to verify the built pages.

validate-claims.mjs
Blocks published claims that do not trace to the source profile; when the profile is unavailable it warns instead of failing.
check-saco-sources.mjs
Blocks numbers not found in their primary source files and sections without mapped sources.
check-bench-sources.mjs
Blocks benchmark entries that do not cite their bench version and spec, or whose evidence snippets do not appear verbatim in that spec.
check-field-sources.mjs
Blocks reference rows missing keys or links and numbers that drift from the frozen snapshot.
check-crispr-sources.mjs
Blocks unverified numbers from paper pages and prevents enrollment e-mails from appearing in page data.
check-trading-sources.mjs
Blocks unverified numbers, missing line citations, and disclosures of monetary results, accounts, brokers, servers, file names, or host details.
check-freshness.mjs
Blocks the build when reviewed sources contain newer commits that have not been reviewed and stamped.
check-publications.mjs
Blocks publication event acronyms and dates that fail to match the registry record of the DOI.
check-a11y.mjs
Blocks structural accessibility regressions including missing language attributes, duplicate h1 headings, skipped heading levels, unlabelled controls, and lost landmarks.
check-seo.mjs
Blocks missing or duplicate meta descriptions, missing social metadata tags, and preview cards pointing to unresolved images.
check-csp.mjs
Blocks a release when an inline script the build ships, such as the speculation rules, is not allowed by its hash in the Content-Security-Policy that nginx sends with every page, or when that policy still allows a hash no script has.
check-opsec.mjs
Blocks disclosures of host machine details, container ports, and network access paths in published text assets.
check-budget.mjs
Blocks pages and critical paths that exceed compressed transfer size limits at gzip level 1.
check-e2e.mjs
Blocks functional regressions in explorer and header navigation menus by testing built pages in real Chromium.
check-mobile.mjs
Blocks horizontal scrolling, elements wider than the viewport, text below 12px, tap targets outside the viewport, and interactive targets smaller than 24×24 CSS px.
check-contrast.mjs
Blocks visible text elements that fail WCAG 2.2 AA contrast ratios of 4.5:1 for normal text or 3:1 for large text across light and dark themes.
check-readability.mjs
Blocks running text lines wider than 80 characters or line spacing below 1.5 in main content elements.
check-redirects.mjs
Blocks retired routes lacking 301 redirects, redirect targets that do not exist, and redirect sources that conflict with built pages.

Performance Budget

The performance budget caps compressed transfer sizes per page and per critical path rather than raw file sizes.

Per-page limits require HTML gzip at or below 40 KB, total JavaScript gzip at or below 30 KB, and critical path transfer size at or below 100 KB.

They keep the critical path well under the 170 KB compressed guideline from web.dev.

Every build runs check-perf, which loads eight pages cold on a desktop and a phone profile under 4x CPU and Slow 4G throttling and fails on LCP above 2.5 s, CLS above 0.1, more than 12 requests or more than 500 KB transferred.

URL Structure, Redirects, and Sitemaps

Retired routes issue permanent 301 redirects configured with and without trailing slashes in nginx.

Every redirect target must resolve to a page that exists in the build output.

The sitemap is generated from the build output during postbuild rather than maintained by hand.

Every shipped directory index is listed in the generated sitemap, and unbuilt pages cannot appear.

Correction Policy

Every shipped change is recorded in the project log.

Public corrections remain in place next to the claims they retract instead of being edited away.

Disclosures

No built page loads a third-party script.

No analytics or tracking script is included in the build.

Three scripts use localStorage: menu.js and theme.js keep the theme preference, and explorer.js remembers which Explorer folders are open. None of them sets a cookie.

Text on this site is drafted and reviewed with the help of AI models.

Every number that reaches a page is checked by quality gates against its primary source, and pages are reviewed against their sources by a separate model before publishing.

Model names are not published.