* Add rel=noopener to the github link to prevent window.opener attacks. * Add no-referrer referrer policy to prevent leakage of sensitive info such as private domain names.