1@README.md 2 3- **Never keep `download_url` or `git_url`.** GitHub's `download_url` for a 4 private repository carries a temporary access token. `Raw` reads 5 `download_url` only to tell a submodule from a file, and a test holds that 6 nothing parsed contains it. 7- **Raw HTML in markdown stays text.** The pages render the repository's 8 markdown on this site's origin. 9- **`?raw` never serves HTML as HTML.** `media_type` returns plain text for 10 every text file but SVG, and the Worker adds `content-security-policy: 11 sandbox`.