- From: W3C Webmaster via GitHub API <sysbot+gh@w3.org>
- Date: Mon, 22 Apr 2024 17:00:22 +0000
- To: public-webappsec@w3.org
- Message-Id: <E1ryx1i-0031Og-1J@janus.w3.internal>
Issues ------ * w3c/webappsec-csp (+1/-0/💬2) 1 issues created: - host-part match doesn't handle * (by evilpie) https://github.com/w3c/webappsec-csp/issues/656 2 issues received 2 new comments: - #656 host-part match doesn't handle * (1 by mikewest) https://github.com/w3c/webappsec-csp/issues/656 - #487 CSP script-src self and blobs (1 by evilpie) https://github.com/w3c/webappsec-csp/issues/487 * w3c/webappsec-trusted-types (+3/-3/💬8) 3 issues created: - Script element protection model (by lukewarlow) https://github.com/w3c/trusted-types/issues/507 - faq.md outdated (by lukewarlow) https://github.com/w3c/trusted-types/issues/505 - `createPolicy`'s permitted policy names are inconsistent with CSP's permitted policy names (by mbrodesser-Igalia) https://github.com/w3c/trusted-types/issues/504 5 issues received 8 new comments: - #507 Script element protection model (1 by lukewarlow) https://github.com/w3c/trusted-types/issues/507 - #505 faq.md outdated (1 by lukewarlow) https://github.com/w3c/trusted-types/issues/505 - #504 `createPolicy`'s permitted policy names are inconsistent with CSP's permitted policy names (3 by annevk, lukewarlow, mbrodesser-Igalia) https://github.com/w3c/trusted-types/issues/504 - #500 `execCommand` spec won't work (2 by annevk, lukewarlow) https://github.com/w3c/trusted-types/issues/500 [spec] - #492 Get trusted type compliant attribute value sink (1 by lukewarlow) https://github.com/w3c/trusted-types/issues/492 3 issues closed: - Get trusted type compliant attribute value sink https://github.com/w3c/trusted-types/issues/492 - Integration with DOM APIs https://github.com/w3c/trusted-types/issues/438 [spec] - faq.md outdated https://github.com/w3c/trusted-types/issues/505 Pull requests ------------- * w3c/webappsec-csp (+1/-0/💬2) 1 pull requests submitted: - Correctly match `*` as a `host-part`. (by mikewest) https://github.com/w3c/webappsec-csp/pull/657 1 pull requests received 2 new comments: - #657 Correctly match `*` as a `host-part`. (2 by mikewest) https://github.com/w3c/webappsec-csp/pull/657 * w3c/webappsec-trusted-types (+3/-3/💬5) 3 pull requests submitted: - Link to spec PRs for in-progress upstreams (by lukewarlow) https://github.com/w3c/trusted-types/pull/506 - Fix links to innerHTML property. (by lukewarlow) https://github.com/w3c/trusted-types/pull/503 - Update slot syntax to remove square brackets. (by lukewarlow) https://github.com/w3c/trusted-types/pull/502 3 pull requests received 5 new comments: - #502 Update slots (2 by lukewarlow) https://github.com/w3c/trusted-types/pull/502 - #484 Update IDL for script enforcement (2 by lukewarlow) https://github.com/w3c/trusted-types/pull/484 - #457 Rewrite metadata functions (1 by lukewarlow) https://github.com/w3c/trusted-types/pull/457 3 pull requests merged: - Update spec to match latest ECMA262 proposal shape. https://github.com/w3c/trusted-types/pull/501 - Update slots https://github.com/w3c/trusted-types/pull/502 - Fix links to innerHTML property. https://github.com/w3c/trusted-types/pull/503 Repositories tracked by this digest: ----------------------------------- * https://github.com/w3c/webappsec * https://github.com/w3c/webappsec-subresource-integrity * https://github.com/w3c/webappsec-csp * https://github.com/w3c/webappsec-mixed-content * https://github.com/w3c/webappsec-upgrade-insecure-requests * https://github.com/w3c/webappsec-credential-management * https://github.com/w3c/permissions * https://github.com/w3c/permissions-registry * https://github.com/w3c/webappsec-referrer-policy * https://github.com/w3c/webappsec-secure-contexts * https://github.com/w3c/webappsec-clear-site-data * https://github.com/w3c/webappsec-cowl * https://github.com/w3c/webappsec-epr * https://github.com/w3c/webappsec-suborigins * https://github.com/w3c/webappsec-cspee * https://github.com/w3c/webappsec-permissions-policy * https://github.com/w3c/webappsec-fetch-metadata * https://github.com/w3c/webappsec-trusted-types * https://github.com/w3c/webappsec-change-password-url * https://github.com/w3c/webappsec-post-spectre-webdev -- Sent via github-notify-ml as configured in https://github.com/w3c/github-notify-ml-config
Received on Monday, 22 April 2024 17:00:23 UTC