Weekly github digest (WebAppSec specs)

Issues
------
* w3c/webappsec-subresource-integrity (+0/-1/💬7)
  2 issues received 7 new comments:
  - #108 Use : as a separator for hash format (2 by abitrolly, mozfreddyb)
    https://github.com/w3c/webappsec-subresource-integrity/issues/108 
  - #36 Consider alternative src value for integrity supported resources (5 by annevk, chucklu, mozfreddyb)
    https://github.com/w3c/webappsec-subresource-integrity/issues/36 [enhancement] [SRI-next] 

  1 issues closed:
  - Consider alternative src value for integrity supported resources https://github.com/w3c/webappsec-subresource-integrity/issues/36 [enhancement] [SRI-next] 

* w3c/webappsec-csp (+3/-0/💬11)
  3 issues created:
  - unsafe-eval and WebAssembly (by fgmccabe)
    https://github.com/w3c/webappsec-csp/issues/512 
  - Scope of navigate-to and form-action (by annevk)
    https://github.com/w3c/webappsec-csp/issues/510 
  - frame-src can leak cross origin information (by antosart)
    https://github.com/w3c/webappsec-csp/issues/509 

  4 issues received 11 new comments:
  - #512 unsafe-eval and WebAssembly (2 by annevk, shhnjk)
    https://github.com/w3c/webappsec-csp/issues/512 
  - #510 Scope of navigate-to and form-action (2 by ArthurSonzogni, annevk)
    https://github.com/w3c/webappsec-csp/issues/510 
  - #509 frame-src can leak cross origin information (5 by annevk, antosart)
    https://github.com/w3c/webappsec-csp/issues/509 
  - #8 CSP: form-action and redirects (2 by Sora2455, jub0bs)
    https://github.com/w3c/webappsec-csp/issues/8 [CSP] 

* w3c/webappsec-mixed-content (+1/-0/💬2)
  1 issues created:
  - References to [mixed-content] don't point to the level 1 spec (by jyasskin)
    https://github.com/w3c/webappsec-mixed-content/issues/58 

  1 issues received 2 new comments:
  - #58 References to [mixed-content] don't point to the level 1 spec (2 by annevk, jyasskin)
    https://github.com/w3c/webappsec-mixed-content/issues/58 




Repositories tracked by this digest:
-----------------------------------
* https://github.com/w3c/webappsec
* https://github.com/w3c/webappsec-subresource-integrity
* https://github.com/w3c/webappsec-csp
* https://github.com/w3c/webappsec-mixed-content
* https://github.com/w3c/webappsec-upgrade-insecure-requests
* https://github.com/w3c/webappsec-credential-management
* https://github.com/w3c/permissions
* https://github.com/w3c/webappsec-referrer-policy
* https://github.com/w3c/webappsec-secure-contexts
* https://github.com/w3c/webappsec-clear-site-data
* https://github.com/w3c/webappsec-cowl
* https://github.com/w3c/webappsec-epr
* https://github.com/w3c/webappsec-suborigins
* https://github.com/w3c/webappsec-cspee
* https://github.com/w3c/webappsec-permissions-policy
* https://github.com/w3c/webappsec-fetch-metadata
* https://github.com/w3c/webappsec-trusted-types
* https://github.com/w3c/webappsec-change-password-url
* https://github.com/w3c/webappsec-post-spectre-webdev


-- 
Sent via github-notify-ml as configured in https://github.com/w3c/github-notify-ml-config

Received on Monday, 27 September 2021 17:00:37 UTC