- From: W3C Webmaster via GitHub API <sysbot+gh@w3.org>
- Date: Mon, 30 Nov 2020 17:00:17 +0000
- To: public-webappsec@w3.org
- Message-Id: <E1kjmXB-0001zU-CA@uranus.w3.org>
Issues ------ * w3c/webappsec-csp (+0/-0/💬2) 2 issues received 2 new comments: - #433 Are nonces allowed/supported in frame-src? (1 by egranty) https://github.com/w3c/webappsec-csp/issues/433 - #411 Parsing multiple sources when one of them is 'none'? (1 by egranty) https://github.com/w3c/webappsec-csp/issues/411 * w3c/permissions (+0/-0/💬1) 1 issues received 1 new comments: - #150 Media autoplay permission (1 by t1gor) https://github.com/w3c/permissions/issues/150 * w3c/webappsec-referrer-policy (+0/-0/💬1) 1 issues received 1 new comments: - #143 Possible Version 2 (1 by Malvoz) https://github.com/w3c/webappsec-referrer-policy/issues/143 * w3c/webappsec-secure-contexts (+1/-0/💬2) 1 issues created: - about:blank" or "about:srcdoc" with query string or fragment should be potentially trustworthy (by fred-wang) https://github.com/w3c/webappsec-secure-contexts/issues/81 1 issues received 2 new comments: - #81 about:blank" or "about:srcdoc" with query string or fragment should be potentially trustworthy (2 by annevk, fred-wang) https://github.com/w3c/webappsec-secure-contexts/issues/81 * w3c/webappsec-permissions-policy (+0/-2/💬2) 2 issues received 2 new comments: - #238 [Proposal] Different script contexts with different feature policy. (1 by clelland) https://github.com/w3c/webappsec-permissions-policy/issues/238 [proposed feature] - #163 Proposal: Parameterized features (1 by clelland) https://github.com/w3c/webappsec-permissions-policy/issues/163 [proposed feature] 2 issues closed: - Proposal: Parameterized features https://github.com/w3c/webappsec-permissions-policy/issues/163 [proposed feature] - [Proposal] Different script contexts with different feature policy. https://github.com/w3c/webappsec-permissions-policy/issues/238 [proposed feature] * w3c/webappsec-trusted-types (+0/-0/💬1) 1 issues received 1 new comments: - #207 Finalize the integrations that guard eval & Function.constructor (1 by koto) https://github.com/w3c/webappsec-trusted-types/issues/207 [tc39] Pull requests ------------- * w3c/webappsec-permissions-policy (+1/-3/💬2) 1 pull requests submitted: - Client hints explainer (by clelland) https://github.com/w3c/webappsec-permissions-policy/pull/413 2 pull requests received 2 new comments: - #409 Allow header to enable features. (1 by clelland) https://github.com/w3c/webappsec-permissions-policy/pull/409 - #407 s/feature-policy/permissions-policy in urls (1 by clelland) https://github.com/w3c/webappsec-permissions-policy/pull/407 3 pull requests merged: - Client hints explainer https://github.com/w3c/webappsec-permissions-policy/pull/413 - Update all links to webappsec-permissions-policy https://github.com/w3c/webappsec-permissions-policy/pull/400 - s/feature-policy/permissions-policy in urls https://github.com/w3c/webappsec-permissions-policy/pull/407 * w3c/webappsec-fetch-metadata (+1/-1/💬1) 1 pull requests submitted: - Update iframe example in README.md (by Malvoz) https://github.com/w3c/webappsec-fetch-metadata/pull/60 1 pull requests received 1 new comments: - #60 Update iframe example in README.md (1 by w3cbot) https://github.com/w3c/webappsec-fetch-metadata/pull/60 1 pull requests merged: - Update iframe example in README.md https://github.com/w3c/webappsec-fetch-metadata/pull/60 * w3c/webappsec-trusted-types (+1/-3/💬7) 1 pull requests submitted: - Changed the default policy arguments. (by koto) https://github.com/w3c/webappsec-trusted-types/pull/302 6 pull requests received 7 new comments: - #293 Bump http-proxy from 1.17.0 to 1.18.1 (1 by dependabot) https://github.com/w3c/webappsec-trusted-types/pull/293 [dependencies] - #292 Correct reference to HTMLScriptElement (1 by koto) https://github.com/w3c/webappsec-trusted-types/pull/292 - #285 Bump elliptic from 6.5.0 to 6.5.3 (1 by dependabot) https://github.com/w3c/webappsec-trusted-types/pull/285 [dependencies] - #284 Bump lodash from 4.17.11 to 4.17.19 (1 by dependabot) https://github.com/w3c/webappsec-trusted-types/pull/284 [dependencies] - #282 Fix invalid Web IDL syntax (2 by koto, saschanaz) https://github.com/w3c/webappsec-trusted-types/pull/282 - #276 Bump https-proxy-agent from 2.2.1 to 2.2.4 (1 by dependabot) https://github.com/w3c/webappsec-trusted-types/pull/276 [dependencies] 3 pull requests merged: - Changed the default policy arguments. https://github.com/w3c/webappsec-trusted-types/pull/302 - Correct return value in example code https://github.com/w3c/webappsec-trusted-types/pull/291 - Correct reference to HTMLScriptElement https://github.com/w3c/webappsec-trusted-types/pull/292 Repositories tracked by this digest: ----------------------------------- * https://github.com/w3c/webappsec * https://github.com/w3c/webappsec-subresource-integrity * https://github.com/w3c/webappsec-csp * https://github.com/w3c/webappsec-mixed-content * https://github.com/w3c/webappsec-upgrade-insecure-requests * https://github.com/w3c/webappsec-credential-management * https://github.com/w3c/permissions * https://github.com/w3c/webappsec-referrer-policy * https://github.com/w3c/webappsec-secure-contexts * https://github.com/w3c/webappsec-clear-site-data * https://github.com/w3c/webappsec-cowl * https://github.com/w3c/webappsec-epr * https://github.com/w3c/webappsec-suborigins * https://github.com/w3c/webappsec-cspee * https://github.com/w3c/webappsec-permissions-policy * https://github.com/w3c/webappsec-fetch-metadata * https://github.com/w3c/webappsec-trusted-types * https://github.com/w3c/webappsec-change-password-url * https://github.com/w3c/webappsec-unofficial-drafts -- Sent via github-notify-ml as configured in https://github.com/w3c/github-notify-ml-config
Received on Monday, 30 November 2020 17:00:20 UTC