Weekly github digest (WebAppSec specs)

Issues
------
* w3c/webappsec-csp (+0/-2/💬0)
  2 issues closed:
  - EnsureCSPDoesNotBlockStringCompilation uses incorrect compilationSink for Eval https://github.com/w3c/webappsec-csp/issues/695 
  - EnsureCSPDoesNotBlockStringCompilation uses incorrect compilationSink for Eval https://github.com/w3c/webappsec-csp/issues/695 

* w3c/permissions (+0/-6/💬16)
  9 issues received 16 new comments:
  - #454 Bring this document to CR (2 by marcoscaceres)
    https://github.com/w3c/permissions/issues/454 
  - #349 Automation: "Get Permission" (1 by marcoscaceres)
    https://github.com/w3c/permissions/issues/349 
  - #348 Automation: "set permission" granularity (1 by marcoscaceres)
    https://github.com/w3c/permissions/issues/348 
  - #347 Automation: Need two more steps to handle closed browsing context and user prompts (1 by marcoscaceres)
    https://github.com/w3c/permissions/issues/347 
  - #189 Conditional permissions (1 by miketaylr)
    https://github.com/w3c/permissions/issues/189 
  - #185 Allow Permissions Policy-based permission models (3 by jan-ivar, jyasskin, marcoscaceres)
    https://github.com/w3c/permissions/issues/185 [editorial] 
  - #178 describe implicitly-granted (chooser-based) permissions (2 by marcoscaceres, miketaylr)
    https://github.com/w3c/permissions/issues/178 
  - #153 "Requesting more permission" algorithms are tightly coupled to prompts (3 by jyasskin, marcoscaceres)
    https://github.com/w3c/permissions/issues/153 
  - #135 Permission query algorithm should be able to fail (2 by marcoscaceres, miketaylr)
    https://github.com/w3c/permissions/issues/135 [later] 

  6 issues closed:
  - Conditional permissions https://github.com/w3c/permissions/issues/189 
  - Automation: Need two more steps to handle closed browsing context and user prompts https://github.com/w3c/permissions/issues/347 
  - Automation: "set permission" granularity https://github.com/w3c/permissions/issues/348 
  - Automation: "Get Permission" https://github.com/w3c/permissions/issues/349 
  - describe implicitly-granted (chooser-based) permissions https://github.com/w3c/permissions/issues/178 
  - "Requesting more permission" algorithms are tightly coupled to prompts https://github.com/w3c/permissions/issues/153 

* w3c/webappsec-permissions-policy (+2/-0/💬0)
  2 issues created:
  - W3C ODRL (by riannella)
    https://github.com/w3c/webappsec-permissions-policy/issues/557 
  - Integrate with policy container (by annevk)
    https://github.com/w3c/webappsec-permissions-policy/issues/556 

* w3c/webappsec-trusted-types (+1/-1/💬7)
  1 issues created:
  - mXSS: should `createHTML` get information about the context? (by mozfreddyb)
    https://github.com/w3c/trusted-types/issues/569 

  2 issues received 7 new comments:
  - #569 mXSS: should `createHTML` get information about the context? (5 by Sora2455, lukewarlow, mozfreddyb)
    https://github.com/w3c/trusted-types/issues/569 
  - #567 Add tests for worker constructors called from worker global scope (2 by mbrodesser-Igalia)
    https://github.com/w3c/trusted-types/issues/567 

  1 issues closed:
  - Add tests for worker constructors called from worker global scope https://github.com/w3c/trusted-types/issues/567 



Pull requests
-------------
* w3c/webappsec-csp (+0/-2/💬1)
  1 pull requests received 1 new comments:
  - #435 Fix match-ports to handle a null input port (1 by antosart)
    https://github.com/w3c/webappsec-csp/pull/435 [clarification] 

  2 pull requests merged:
  - Fix eval compilationSink in EnsureCSPDoesNotBlockStringCompilation.
    https://github.com/w3c/webappsec-csp/pull/699 [editorial] 
  - Fix match-ports to handle a null input port
    https://github.com/w3c/webappsec-csp/pull/435 [clarification] 

* w3c/permissions (+3/-3/💬4)
  3 pull requests submitted:
  - Editorial: Prepare for CR (by marcoscaceres)
    https://github.com/w3c/permissions/pull/457 
  - Tidied up document using tidy-html5 (by github-actions)
    https://github.com/w3c/permissions/pull/456 
  - Use `<code>` for references to a CDDL type (by tidoust)
    https://github.com/w3c/permissions/pull/455 

  4 pull requests received 4 new comments:
  - #457 Editorial: Prepare for CR (1 by miketaylr)
    https://github.com/w3c/permissions/pull/457 
  - #456 Tidied up document using tidy-html5 (1 by w3cbot)
    https://github.com/w3c/permissions/pull/456 
  - #452 Editorial: Fix sentences around permission states (1 by miketaylr)
    https://github.com/w3c/permissions/pull/452 
  - #407 Export permissions task source (1 by marcoscaceres)
    https://github.com/w3c/permissions/pull/407 

  3 pull requests merged:
  - Editorial: Fix sentences around permission states
    https://github.com/w3c/permissions/pull/452 
  - Tidied up document using tidy-html5
    https://github.com/w3c/permissions/pull/456 
  - Use `<code>` for references to a CDDL type
    https://github.com/w3c/permissions/pull/455 


Repositories tracked by this digest:
-----------------------------------
* https://github.com/w3c/webappsec
* https://github.com/w3c/webappsec-subresource-integrity
* https://github.com/w3c/webappsec-csp
* https://github.com/w3c/webappsec-mixed-content
* https://github.com/w3c/webappsec-upgrade-insecure-requests
* https://github.com/w3c/webappsec-credential-management
* https://github.com/w3c/permissions
* https://github.com/w3c/permissions-registry
* https://github.com/w3c/webappsec-referrer-policy
* https://github.com/w3c/webappsec-secure-contexts
* https://github.com/w3c/webappsec-clear-site-data
* https://github.com/w3c/webappsec-cowl
* https://github.com/w3c/webappsec-epr
* https://github.com/w3c/webappsec-suborigins
* https://github.com/w3c/webappsec-cspee
* https://github.com/w3c/webappsec-permissions-policy
* https://github.com/w3c/webappsec-fetch-metadata
* https://github.com/w3c/webappsec-trusted-types
* https://github.com/w3c/webappsec-change-password-url
* https://github.com/w3c/webappsec-post-spectre-webdev


-- 
Sent via github-notify-ml as configured in https://github.com/w3c/github-notify-ml-config

Received on Monday, 23 December 2024 17:00:25 UTC