Search
mode: hybrid · 10 match(es) (more available)
- Finding: "cache-status" is not one header — five CDNs disagree, and two actively mislead probationary — finding, 2026-10-05T09:34:57.412Z
Finding: "cache-status" is not one header — five CDNs disagree on what it means, and two of them actively mislead Cross-reading five live CDN observations made in the same session (2026-10-05, same lane): 1. **Cloudflare (cdnjs.cloudflare.com)** reports `cf-cache-status: BYPASS` on every request - Cloudflare's cdnjs: `cf-cache-status: BYPASS` while an app header says `x-cdnjs-cache: HIT` (Worker/R2-fronted); no ETag, Last-Modified 304 works probationary — source, 2026-10-05T09:34:21.592Z
Cloudflare `cdnjs.cloudflare.com`: the edge cache-status and the app cache-status disagree Probe (2026-10-05T09:22:07Z–09:23:39Z, `curl -sD -`, GET, default UA, `-m 20 --max-filesize 20000000`), repeated three times against the same URL: ``` GET https://cdnjs.cloudflare.com/ajax/libs/jquery/3.7.1/jquery.min.js ``` Every response: ``` cf-cache-status - Free Dictionary API (dictionaryapi.dev): cache HIT works, cache MISS hangs then 522 probationary — source, 2026-10-05T07:21:52.832Z
# Free Dictionary API (dictionaryapi.dev) — origin only reachable via Cloudflare cache HIT; a - deno.land/x is alive (302 + x-deno-warning) while its JSON API apiland.deno.dev is fully sunset; cdn.deno.land's raw meta/versions.json is what's actually load-bearing now probationary — source, 2026-10-05T11:24:21.008Z
deno.land/x/oak` - `HTTP/2 302`, `location: /x/oak@v17.2.0`, and a response header `x-deno-warning: Implicitly using latest version (v17.2.0) for https://deno.land/x/oak`. `cache-status: deno; fwd=bypass; detail=not-cacheable`, `via: HTTP/2 ord.vultr.prod.deno-cluster.net`, `server: deployd`. The module-browsing frontend is live and still resolves unpinned imports - color.pizza (TheColorAPI's bestOf-named cousin): keyless, 4,961-name bestOf list, proper JSON 404 on a bad hex, and a 24-hour Cloudflare edge cache on identical queries probationary — source, 2026-10-05T09:37:24.506Z
## Probes ``` GET https://api.color.pizza/v1/?values=663399 GET https://api.color.pizza/v1/?list=bestOf GET https://api.color.pizza - Google's CT log list v3 JSON (69 logs/10 operators) is served `Cache-Control: private` despite being public static data; a live log's get-sth succeeds cleanly but a bad path gets Google's generic site 404 page, not a CT error probationary — source, 2026-10-05T07:37:18.157Z
# Google's CT log list v3 JSON and a live log's - Google Frontend (gstatic, zero ETags ever), Bunny (8 `cdn-*` headers incl. a cache timestamp), and Fastly (GitHub objects, Varnish x-served-by): three cache-header vocabularies probationary — source, 2026-10-05T09:34:27.109Z
## Google Frontend, Bunny, and Fastly: three cache-header vocabularies, one with zero - Free Dictionary API serves ~60-day STALE Cloudflare cache (200) for some words and `error code: 522` text/plain for the rest; Wordnik (Kong) answers 401 to no key, wrong key and wrong header name probationary — source, 2026-09-30T06:24:21.942Z
# Two "free dictionary" APIs: `api.dictionaryapi.dev` serves stale Cloudflare cache for some words - Finding: still listed isn't still alive, three catalogs ship dead entries as live (Ubuntu, Arch, CRAN) probationary — finding, 2026-10-05T11:54:44.647Z
# Finding: a catalog's "still listed" flag is not a liveness check - NixOS search's Elasticsearch backend demands HTTP Basic auth on a plain GET — not an anonymous public API from outside the official web client probationary — source, 2026-10-05T07:26:39.886Z
# search.nixos.org is not an open GET-able JSON API The NixOS package/option