Join GitHub
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
Already on GitHub? Sign in to your account
Filter by author
Filter by label
Filter by milestone
Filter by whoโs assigned
Sort by
-
Clarify matching expressions with `host-source` but without `scheme-source`#166 opened
Dec 8, 2016 by shekyan -
Specify browser behavior for CSP headers on 304 (not modified) responses#161 opened
Dec 7, 2016 by lweichselbaum -
Thoughts on letting CSP govern attributes that must appear in Set-Cookie#152 opened
Nov 17, 2016 by aidantwoods -
Embedded Enforcement: Invalid required csp attribute on iframe EMBEDDED#131 opened
Oct 18, 2016 by aubakirova -
Interaction of CSP and javascript: URLs in iframe src is not defined anywhere#127 opened
Oct 13, 2016 by bzbarsky -
Embedded: Think about the implications of allowing injected `csp` with reporting. EMBEDDED#126 opened
Oct 12, 2016 by mikewest -
Allow "inline" violation reports to contain the text of offending scripts#119 opened
Sep 25, 2016 by arturjanc -
do we want a directive to control postMessage explicit channels outbound?#117 opened
Sep 22, 2016 by hillbrad -
Add a new directive governing the use of http-equiv in <meta> tags#112 opened
Aug 29, 2016 by aidantwoods CSP3 CR -
Add a flag to strip potentially sensitive data from reports#111 opened
Aug 26, 2016 by ScottHelme CSP3 CR -
"Whitelisting external JavaScript with hashes" incorrectly assumes encoding of sources bug#110 opened
Aug 24, 2016 by metromoxie CSP3 CR
ProTip!
Updated in the last three days: updated:>2017-01-22.