- From: W3C Webmaster via GitHub API <sysbot+gh@w3.org>
- Date: Mon, 08 Jul 2019 17:00:13 +0000
- To: public-webappsec@w3.org
- Message-Id: <E1hkWzt-0004Es-Nt@uranus.w3.org>
Issues
------
* w3c/webappsec-subresource-integrity (+0/-5/💬5)
3 issues received 5 new comments:
- #76 What about RDF ? (3 by mozfreddyb, akuckartz)
https://github.com/w3c/webappsec-subresource-integrity/issues/76
- #60 Require that proxies do not modify integrity checked assets (1 by mozfreddyb)
https://github.com/w3c/webappsec-subresource-integrity/issues/60
- #23 Add an SRI control as either a CSP directive or a new header (1 by mozfreddyb)
https://github.com/w3c/webappsec-subresource-integrity/issues/23 [enhancement]
5 issues closed:
- Consider feature detection https://github.com/w3c/webappsec-subresource-integrity/issues/37 [SRI-next] [enhancement] [feature-request]
- What about RDF ? https://github.com/w3c/webappsec-subresource-integrity/issues/76
- Add an SRI control as either a CSP directive or a new header https://github.com/w3c/webappsec-subresource-integrity/issues/23 [enhancement]
- JavaScript crossorigin vs crossOrigin attribute https://github.com/w3c/webappsec-subresource-integrity/issues/24 [enhancement]
- The design fails to make a secure guarantee https://github.com/w3c/webappsec-subresource-integrity/issues/80
* w3c/webappsec-csp (+1/-0/💬0)
1 issues created:
- CSP domain.com vs domain.com/ with slash (by laukstein)
https://github.com/w3c/webappsec-csp/issues/403
* w3c/permissions (+1/-0/💬4)
1 issues created:
- Consider making `request-permission-to-use` aware of user activation (by engedy)
https://github.com/w3c/permissions/issues/194
1 issues received 4 new comments:
- #194 Consider making `request-permission-to-use` aware of user activation (4 by jyasskin, engedy, mustaqahmed)
https://github.com/w3c/permissions/issues/194
* w3c/webappsec-feature-policy (+0/-0/💬1)
1 issues received 1 new comments:
- #230 Need to define how 'src' works with sandboxed frames (1 by clelland)
https://github.com/w3c/webappsec-feature-policy/issues/230 [definition]
* w3c/webappsec-fetch-metadata (+1/-0/💬0)
1 issues created:
- Sec-Fetch-Site for service worker update request (by makotoshimazu)
https://github.com/w3c/webappsec-fetch-metadata/issues/36
* WICG/trusted-types (+0/-0/💬5)
5 issues received 5 new comments:
- #64 Bypass via HTMLAnchorElement properties (1 by mikesamuel)
https://github.com/WICG/trusted-types/issues/64 [security]
- #169 Cover missing sinks (1 by koto)
https://github.com/WICG/trusted-types/issues/169 [spec]
- #172 Consider adding a type for base.href (1 by mikesamuel)
https://github.com/WICG/trusted-types/issues/172 [spec]
- #177 Rename the factory as available on window to window.trustedTypes. (1 by mikesamuel)
https://github.com/WICG/trusted-types/issues/177 [spec]
- #178 Define rules for TT when multiple headers are present (1 by mikesamuel)
https://github.com/WICG/trusted-types/issues/178 [spec]
Pull requests
-------------
* w3c/webappsec-subresource-integrity (+1/-1/💬4)
1 pull requests submitted:
- Revert `require-sri-for` (by mozfreddyb)
https://github.com/w3c/webappsec-subresource-integrity/pull/82
1 pull requests received 4 new comments:
- #82 Revert `require-sri-for` (4 by mozfreddyb, MaceWindu, devd)
https://github.com/w3c/webappsec-subresource-integrity/pull/82
1 pull requests merged:
- Revert `require-sri-for`
https://github.com/w3c/webappsec-subresource-integrity/pull/82
* WICG/trusted-types (+1/-1/💬2)
1 pull requests submitted:
- Update demo (by Siegrift)
https://github.com/WICG/trusted-types/pull/186
1 pull requests received 2 new comments:
- #170 Rewrote CSP & EcmaScript integration (2 by mikesamuel)
https://github.com/WICG/trusted-types/pull/170
1 pull requests merged:
- Update demo
https://github.com/WICG/trusted-types/pull/186
Repositories tracked by this digest:
-----------------------------------
* https://github.com/w3c/webappsec
* https://github.com/w3c/webappsec-subresource-integrity
* https://github.com/w3c/webappsec-csp
* https://github.com/w3c/webappsec-mixed-content
* https://github.com/w3c/webappsec-upgrade-insecure-requests
* https://github.com/w3c/webappsec-credential-management
* https://github.com/w3c/permissions
* https://github.com/w3c/webappsec-referrer-policy
* https://github.com/w3c/webappsec-secure-contexts
* https://github.com/w3c/webappsec-clear-site-data
* https://github.com/w3c/webappsec-cowl
* https://github.com/w3c/webappsec-epr
* https://github.com/w3c/webappsec-suborigins
* https://github.com/w3c/webappsec-cspee
* https://github.com/w3c/webappsec-feature-policy
* https://github.com/w3c/webappsec-fetch-metadata
* https://github.com/WICG/trusted-types
Received on Monday, 8 July 2019 17:00:15 UTC