Weekly github digest (WebAppSec specs)

Issues
------
* w3c/webappsec-csp (+2/-0/💬3)
  2 issues created:
  - Percent-decode is used incorrectly (by annevk)
    https://github.com/w3c/webappsec-csp/issues/448 
  - Address Bikeshed warnings (by annevk)
    https://github.com/w3c/webappsec-csp/issues/446 

  2 issues received 3 new comments:
  - #444 Make user's the driver of the user-agent again: bookmarklets, userscripts (1 by dveditz)
    https://github.com/w3c/webappsec-csp/issues/444 
  - #256 Add way to define all country code top-level domain. (2 by KristianH, koto)
    https://github.com/w3c/webappsec-csp/issues/256 

* w3c/webappsec-mixed-content (+0/-0/💬1)
  1 issues received 1 new comments:
  - #25 Move MIX2 to FPWD (1 by carlosjoan91)
    https://github.com/w3c/webappsec-mixed-content/issues/25 

* w3c/webappsec-permissions-policy (+0/-1/💬6)
  1 issues received 6 new comments:
  - #408 Header should be sufficient in some cases to delegate features (esp. Client Hints) (6 by annevk, clelland, yoavweiss)
    https://github.com/w3c/webappsec-permissions-policy/issues/408 

  1 issues closed:
  - Header should be sufficient in some cases to delegate features (esp. Client Hints) https://github.com/w3c/webappsec-permissions-policy/issues/408 



Pull requests
-------------
* w3c/webappsec-csp (+2/-5/💬2)
  2 pull requests submitted:
  - Meta: correct percent-decode reference (by annevk)
    https://github.com/w3c/webappsec-csp/pull/447 
  - Meta: export algorithms used by Fetch (by annevk)
    https://github.com/w3c/webappsec-csp/pull/445 

  1 pull requests received 2 new comments:
  - #436 Trim input parameters to HTML hooks (2 by annevk, domenic)
    https://github.com/w3c/webappsec-csp/pull/436 

  5 pull requests merged:
  - Drop mention of obsolete require-sri-for directive
    https://github.com/w3c/webappsec-csp/pull/417 
  - typo: s/thich/which/
    https://github.com/w3c/webappsec-csp/pull/393 
  - Meta: correct percent-decode reference
    https://github.com/w3c/webappsec-csp/pull/447 
  - Meta: export algorithms used by Fetch
    https://github.com/w3c/webappsec-csp/pull/445 
  - Trim input parameters to HTML hooks
    https://github.com/w3c/webappsec-csp/pull/436 

* w3c/permissions (+1/-0/💬0)
  1 pull requests submitted:
  - Use media device permission revocation algorithm. (by jan-ivar)
    https://github.com/w3c/permissions/pull/225 


Repositories tracked by this digest:
-----------------------------------
* https://github.com/w3c/webappsec
* https://github.com/w3c/webappsec-subresource-integrity
* https://github.com/w3c/webappsec-csp
* https://github.com/w3c/webappsec-mixed-content
* https://github.com/w3c/webappsec-upgrade-insecure-requests
* https://github.com/w3c/webappsec-credential-management
* https://github.com/w3c/permissions
* https://github.com/w3c/webappsec-referrer-policy
* https://github.com/w3c/webappsec-secure-contexts
* https://github.com/w3c/webappsec-clear-site-data
* https://github.com/w3c/webappsec-cowl
* https://github.com/w3c/webappsec-epr
* https://github.com/w3c/webappsec-suborigins
* https://github.com/w3c/webappsec-cspee
* https://github.com/w3c/webappsec-permissions-policy
* https://github.com/w3c/webappsec-fetch-metadata
* https://github.com/w3c/webappsec-trusted-types
* https://github.com/w3c/webappsec-change-password-url
* https://github.com/w3c/webappsec-unofficial-drafts


-- 
Sent via github-notify-ml as configured in https://github.com/w3c/github-notify-ml-config

Received on Monday, 9 November 2020 17:00:22 UTC