- From: W3C Webmaster via GitHub API <sysbot+gh@w3.org>
- Date: Mon, 19 Jul 2021 17:00:31 +0000
- To: public-webappsec@w3.org
- Message-Id: <E1m5Wd5-0007xN-3f@uranus.w3.org>
Issues ------ * w3c/webappsec (+1/-0/💬11) 1 issues created: - [meta] Adopting the Sanitizer API (by mozfreddyb) https://github.com/w3c/webappsec/issues/596 [charter] 2 issues received 11 new comments: - #596 [meta] Adopting the Sanitizer API (9 by annevk, mikewest, mozfreddyb, otherdaniel, samuelweiler) https://github.com/w3c/webappsec/issues/596 [charter] - #595 2021-2023 charter feedback (2 by mozfreddyb, samuelweiler) https://github.com/w3c/webappsec/issues/595 [charter] * w3c/webappsec-subresource-integrity (+1/-0/💬3) 1 issues created: - Add recommendation to use SRI for versioned & stable resources (by mozfreddyb) https://github.com/w3c/webappsec-subresource-integrity/issues/102 1 issues received 3 new comments: - #102 Add recommendation to use SRI for versioned & stable resources (3 by mikewest, robinwhittleton) https://github.com/w3c/webappsec-subresource-integrity/issues/102 * w3c/webappsec-csp (+1/-0/💬5) 1 issues created: - Consider adding import-src (by shhnjk) https://github.com/w3c/webappsec-csp/issues/506 1 issues received 5 new comments: - #506 Consider adding import-src (5 by koto, mikewest, shhnjk) https://github.com/w3c/webappsec-csp/issues/506 * w3c/permissions (+0/-0/💬2) 2 issues received 2 new comments: - #162 Granting permission to non-fully-active documents is weird and should be disallowed (1 by rakina) https://github.com/w3c/permissions/issues/162 - #150 Media autoplay permission (1 by ndvbd) https://github.com/w3c/permissions/issues/150 [question] * w3c/webappsec-trusted-types (+1/-0/💬9) 1 issues created: - Bypass using execCommand (by apple502j) https://github.com/w3c/webappsec-trusted-types/issues/345 3 issues received 9 new comments: - #345 Bypass using execCommand (3 by apple502j, koto) https://github.com/w3c/webappsec-trusted-types/issues/345 - #343 Consider allowing `innerHTML = ''` (3 by arturjanc, koto, shhnjk) https://github.com/w3c/webappsec-trusted-types/issues/343 - #342 CfC to publish as an FPWD. (3 by mikewest, samuelweiler, shhnjk) https://github.com/w3c/webappsec-trusted-types/issues/342 * w3c/webappsec-post-spectre-webdev (+0/-1/💬1) 1 issues received 1 new comments: - #2 Make recommendations around local-schemed frames. (1 by mikewest) https://github.com/w3c/webappsec-post-spectre-webdev/issues/2 1 issues closed: - Make recommendations around local-schemed frames. https://github.com/w3c/webappsec-post-spectre-webdev/issues/2 Pull requests ------------- * w3c/webappsec (+1/-0/💬1) 1 pull requests submitted: - add doc policy; remove CSP:EE, SRI, Suborigins, Origin Policy (by samuelweiler) https://github.com/w3c/webappsec/pull/597 1 pull requests received 1 new comments: - #597 [charter] add doc policy; remove CSP:EE, SRI, Suborigins, Origin Policy (1 by samuelweiler) https://github.com/w3c/webappsec/pull/597 * w3c/webappsec-subresource-integrity (+1/-0/💬0) 1 pull requests submitted: - Add some information for authors about the intent of the spec (by robinwhittleton) https://github.com/w3c/webappsec-subresource-integrity/pull/103 * w3c/webappsec-csp (+0/-0/💬1) 1 pull requests received 1 new comments: - #293 Minimal specification of 'wasm-eval' source directive (1 by annevk) https://github.com/w3c/webappsec-csp/pull/293 * w3c/permissions (+0/-0/💬2) 1 pull requests received 2 new comments: - #249 Handle not fully active documents when querying Permissions API (2 by marcoscaceres, rakina) https://github.com/w3c/permissions/pull/249 * w3c/webappsec-fetch-metadata (+1/-0/💬1) 1 pull requests submitted: - Clean up the integration with HTML and Fetch. (by mikewest) https://github.com/w3c/webappsec-fetch-metadata/pull/75 1 pull requests received 1 new comments: - #75 Clean up the integration with HTML and Fetch. (1 by mikewest) https://github.com/w3c/webappsec-fetch-metadata/pull/75 * w3c/webappsec-trusted-types (+2/-1/💬1) 2 pull requests submitted: - fix typos (by 0xedward) https://github.com/w3c/webappsec-trusted-types/pull/346 - typo: compliment => complement (by paulirish) https://github.com/w3c/webappsec-trusted-types/pull/344 1 pull requests received 1 new comments: - #344 typo: compliment => complement (1 by koto) https://github.com/w3c/webappsec-trusted-types/pull/344 1 pull requests merged: - typo: compliment => complement https://github.com/w3c/webappsec-trusted-types/pull/344 Repositories tracked by this digest: ----------------------------------- * https://github.com/w3c/webappsec * https://github.com/w3c/webappsec-subresource-integrity * https://github.com/w3c/webappsec-csp * https://github.com/w3c/webappsec-mixed-content * https://github.com/w3c/webappsec-upgrade-insecure-requests * https://github.com/w3c/webappsec-credential-management * https://github.com/w3c/permissions * https://github.com/w3c/webappsec-referrer-policy * https://github.com/w3c/webappsec-secure-contexts * https://github.com/w3c/webappsec-clear-site-data * https://github.com/w3c/webappsec-cowl * https://github.com/w3c/webappsec-epr * https://github.com/w3c/webappsec-suborigins * https://github.com/w3c/webappsec-cspee * https://github.com/w3c/webappsec-permissions-policy * https://github.com/w3c/webappsec-fetch-metadata * https://github.com/w3c/webappsec-trusted-types * https://github.com/w3c/webappsec-change-password-url * https://github.com/w3c/webappsec-post-spectre-webdev -- Sent via github-notify-ml as configured in https://github.com/w3c/github-notify-ml-config
Received on Monday, 19 July 2021 17:00:33 UTC