Weekly github digest (WebAppSec specs)

Issues
------
* w3c/webappsec-csp (+1/-0/💬0)
  1 issues created:
  - "Is element nonceable" not applied to non-<script> elements in Chrome? (by evilpie)
    https://github.com/w3c/webappsec-csp/issues/643 

* w3c/webappsec-credential-management (+1/-0/💬0)
  1 issues created:
  - Mediation parameter for credential creation (by pascoej)
    https://github.com/w3c/webappsec-credential-management/issues/225 

* w3c/permissions (+1/-1/💬0)
  1 issues created:
  - Disambiguate "parameters" in Set Permission steps (by saschanaz)
    https://github.com/w3c/permissions/issues/440 

  1 issues closed:
  - Disambiguate "parameters" in Set Permission steps https://github.com/w3c/permissions/issues/440 

* w3c/webappsec-secure-contexts (+0/-0/💬1)
  1 issues received 1 new comments:
  - #60 Using secure-context gated features with local devices (1 by drzraf)
    https://github.com/w3c/webappsec-secure-contexts/issues/60 

* w3c/webappsec-permissions-policy (+0/-1/💬9)
  3 issues received 9 new comments:
  - #537 Send reports for Permissions Policy violations in iframe to parent frame's endpoint (6 by arturjanc, clelland)
    https://github.com/w3c/webappsec-permissions-policy/issues/537 
  - #536 Permissions Policy report missing a document URL (2 by clelland, shhnjk)
    https://github.com/w3c/webappsec-permissions-policy/issues/536 
  - #410 Proposal: Transition 'sync-xhr' feature to Document Policy (1 by RByers)
    https://github.com/w3c/webappsec-permissions-policy/issues/410 

  1 issues closed:
  - Permissions Policy report missing a document URL https://github.com/w3c/webappsec-permissions-policy/issues/536 

* w3c/webappsec-trusted-types (+3/-3/💬12)
  3 issues created:
  - Should the "default" policy be called when `setAttributeNode` is called with a node from the same realm? (by mbrodesser-Igalia)
    https://github.com/w3c/trusted-types/issues/434 
  - TrustedTypePolicyFactory getTypeMapping() missing from spec. (by lukewarlow)
    https://github.com/w3c/trusted-types/issues/432 
  - Discrepency between tests and Get Trusted Type Compliant string algorithm (by lukewarlow)
    https://github.com/w3c/trusted-types/issues/431 

  4 issues received 12 new comments:
  - #434 Should the "default" policy be called when `setAttributeNode` is called with a node from the same realm? (3 by koto, mbrodesser-Igalia)
    https://github.com/w3c/trusted-types/issues/434 
  - #432 TrustedTypePolicyFactory getTypeMapping() missing from spec. (3 by lukewarlow, petervanderbeken)
    https://github.com/w3c/trusted-types/issues/432 [proposed-removal] 
  - #431 Discrepency between tests and Get Trusted Type Compliant string algorithm (5 by koto, lukewarlow)
    https://github.com/w3c/trusted-types/issues/431 
  - #384 Are `getAttributeType` and `getPropertyType` methods neccessary? (1 by lukewarlow)
    https://github.com/w3c/trusted-types/issues/384 [proposed-removal] 

  3 issues closed:
  - Should the "default" policy be called when `setAttributeNode` is called with a node from the same realm? https://github.com/w3c/trusted-types/issues/434 
  - Discrepency between tests and Get Trusted Type Compliant string algorithm https://github.com/w3c/trusted-types/issues/431 
  - Figure out what to do with `script.setAttribute('src')` https://github.com/w3c/trusted-types/issues/402 



Pull requests
-------------
* w3c/permissions (+2/-1/💬0)
  2 pull requests submitted:
  - Tidied up document using tidy-html5 (by github-actions)
    https://github.com/w3c/permissions/pull/442 
  - Editorial: Disambiguate `parameters` in Set Permission steps (by saschanaz)
    https://github.com/w3c/permissions/pull/441 

  1 pull requests merged:
  - Editorial: Disambiguate `parameters` in Set Permission steps
    https://github.com/w3c/permissions/pull/441 

* w3c/webappsec-clear-site-data (+1/-0/💬3)
  1 pull requests submitted:
  - Add compression dictionary clearing support (by horo-t)
    https://github.com/w3c/webappsec-clear-site-data/pull/80 

  1 pull requests received 3 new comments:
  - #80 Add compression dictionary clearing support (3 by horo-t, pmeenan)
    https://github.com/w3c/webappsec-clear-site-data/pull/80 

* w3c/webappsec-permissions-policy (+1/-0/💬1)
  1 pull requests submitted:
  - Add `documentUrl` to Permissions Policy report (by shhnjk)
    https://github.com/w3c/webappsec-permissions-policy/pull/541 

  1 pull requests received 1 new comments:
  - #541 Add `documentUrl` to Permissions Policy report (1 by shhnjk)
    https://github.com/w3c/webappsec-permissions-policy/pull/541 

* w3c/webappsec-trusted-types (+2/-2/💬0)
  2 pull requests submitted:
  - Fix issue with default policy handling when callback function is missing (by lukewarlow)
    https://github.com/w3c/trusted-types/pull/433 
  - Remove outdated inline issue (by lukewarlow)
    https://github.com/w3c/trusted-types/pull/430 

  2 pull requests merged:
  - Fix issue with default policy handling when callback function is missing
    https://github.com/w3c/trusted-types/pull/433 
  - Remove outdated inline issue
    https://github.com/w3c/trusted-types/pull/430 


Repositories tracked by this digest:
-----------------------------------
* https://github.com/w3c/webappsec
* https://github.com/w3c/webappsec-subresource-integrity
* https://github.com/w3c/webappsec-csp
* https://github.com/w3c/webappsec-mixed-content
* https://github.com/w3c/webappsec-upgrade-insecure-requests
* https://github.com/w3c/webappsec-credential-management
* https://github.com/w3c/permissions
* https://github.com/w3c/permissions-registry
* https://github.com/w3c/webappsec-referrer-policy
* https://github.com/w3c/webappsec-secure-contexts
* https://github.com/w3c/webappsec-clear-site-data
* https://github.com/w3c/webappsec-cowl
* https://github.com/w3c/webappsec-epr
* https://github.com/w3c/webappsec-suborigins
* https://github.com/w3c/webappsec-cspee
* https://github.com/w3c/webappsec-permissions-policy
* https://github.com/w3c/webappsec-fetch-metadata
* https://github.com/w3c/webappsec-trusted-types
* https://github.com/w3c/webappsec-change-password-url
* https://github.com/w3c/webappsec-post-spectre-webdev


-- 
Sent via github-notify-ml as configured in https://github.com/w3c/github-notify-ml-config

Received on Monday, 12 February 2024 17:00:32 UTC