diff --git a/js/reading-list.js b/js/reading-list.js
index e7a94e4..7c1657f 100644
--- a/js/reading-list.js
+++ b/js/reading-list.js
@@ -64,9 +64,11 @@ function renderEntry(entry) {
const note = entry.note
? `
${escapeHtml(entry.note)}
`
: "";
+ // Every reading link points at an external http(s) URL (isValidUrl), so it
+ // carries rel="noopener noreferrer" as a hardening best practice.
return (
`` +
- `${escapeHtml(entry.title)}` +
+ `${escapeHtml(entry.title)}` +
note +
``
);
diff --git a/tests/reading-list.test.js b/tests/reading-list.test.js
index 760d685..388b98e 100644
--- a/tests/reading-list.test.js
+++ b/tests/reading-list.test.js
@@ -18,7 +18,7 @@ const indexHtml = readFileSync(join(root, "index.html"), "utf8");
const contactHtml = readFileSync(join(root, "contact.html"), "utf8");
const rendererSource = readFileSync(join(root, "js/reading-list.js"), "utf8");
-const ANCHOR_RE = /([^<]*)<\/a>/g;
+const ANCHOR_RE = /]*>([^<]*)<\/a>/g;
const ENTRY_LI_RE = //g;
const SECTION_RE = /