public-webappsec@w3.org from January 2016 by subject

[CSP] "sri" source expression to enforce SRI

[powerful features] Secure Contexts and Framed Documents

[SRI] Increasing Cacheable Content as a goal

[SRI] Re: Security / Technical feedback on subresource integrity specification

[sritest.io] New Website SRI Scanner Service

[webappsec] Face to Face meeting survey

[webappsec] Teleconference Agenda 13-Jan-2016

[webappsec] Teleconference Agenda: 27-Jan-2016

Allow auto-resize on iframe

Call for Consensus: Mixed Content to Proposed Recommendation

Call for Consensus: SRI to Proposed Recommendation

Call for Exclusions (Update): Confinement with Origin Web Labels

Call for Exclusions: Content Security Policy Level 3

CfC: CSP3 to FPWD; deadline January 15th.

Fwd: HTTPS/HSTS support on www.w3.org servers

Header size and policy delivery

HSTS priming vs preloading

In-browser sanitization vs. a “Safe Node” in the DOM

Limiting requests from the internet to the intranet.

new CSP draft.

PDF alternative using HTML (proposal)

Permissions work - status and intent to update

preflighted CORS requests and redirects: principally impossible?

Proposal to add a browsing context named "_private"

Proposal: Marking HTTP As Non-Secure

Request for input on Foreign Fetch

Secure Contexts to CR? (Re: [webappsec] Teleconference Agenda: 27-Jan-2016)

Security / Technical feedback on subresource integrity specification

Signed JavaScript/JSON using ES6 + Google V8

Summary of major differences between COWL and Suborigins

Last message date: Sunday, 31 January 2016 19:02:13 UTC