- From: W3C Webmaster via GitHub API <sysbot+gh@w3.org>
- Date: Mon, 08 Jul 2024 17:00:23 +0000
- To: public-webappsec@w3.org
- Message-Id: <E1sQrix-002ahv-1z@janus.w3.internal>
Issues ------ * w3c/webappsec-csp (+1/-0/💬1) 1 issues created: - Even though I have domains specified in the CSP policy violations still appear (by Blason) https://github.com/w3c/webappsec-csp/issues/670 1 issues received 1 new comments: - #199 CSP3: Consider adding a 'clone-src' directive (1 by evilpie) https://github.com/w3c/webappsec-csp/issues/199 * w3c/webappsec-mixed-content (+1/-0/💬0) 1 issues created: - References to "Does Not (Prohibit|Restrict) Mixed Security Contexts" are inconsistent (by shanehandley) https://github.com/w3c/webappsec-mixed-content/issues/72 * w3c/webappsec-credential-management (+1/-0/💬5) 1 issues created: - Consider not running internal methods in parallel or add "consumes user activation" to registry? (by marcoscaceres) https://github.com/w3c/webappsec-credential-management/issues/243 1 issues received 5 new comments: - #243 Consider not running internal methods in parallel or add "consumes user activation" to registry? (5 by marcoscaceres, nsatragno, stephenmcgruer) https://github.com/w3c/webappsec-credential-management/issues/243 * w3c/webappsec-permissions-policy (+0/-0/💬1) 1 issues received 1 new comments: - #552 PP header inheritance for local schemes (1 by annevk) https://github.com/w3c/webappsec-permissions-policy/issues/552 * w3c/webappsec-trusted-types (+1/-1/💬9) 1 issues created: - Is "code updating a script before it finishes parsing" within the threat model of Trusted Types? (by lukewarlow) https://github.com/w3c/trusted-types/issues/532 3 issues received 9 new comments: - #532 Is "code updating a script before it finishes parsing" within the threat model of Trusted Types? (4 by lukewarlow, otherdaniel) https://github.com/w3c/trusted-types/issues/532 - #525 Script element mid-parse protection mechanism (4 by lukewarlow, mbrodesser-Igalia, smaug----) https://github.com/w3c/trusted-types/issues/525 [spec] - #521 getPropertyType and SVGScriptElement href baseVal property (1 by lukewarlow) https://github.com/w3c/trusted-types/issues/521 [spec] 1 issues closed: - Is "code updating a script before it finishes parsing" within the threat model of Trusted Types? https://github.com/w3c/trusted-types/issues/532 Pull requests ------------- * w3c/webappsec-csp (+0/-0/💬1) 1 pull requests received 1 new comments: - #659 Upstream Trusted Types enforcement in EnsureCSPDoesNotBlockStringCompilation (1 by lukewarlow) https://github.com/w3c/webappsec-csp/pull/659 * w3c/webappsec-permissions-policy (+0/-0/💬2) 1 pull requests received 2 new comments: - #549 Add digital-credential-get experimental permission to features.md (2 by clelland, pkotwicz) https://github.com/w3c/webappsec-permissions-policy/pull/549 * w3c/webappsec-trusted-types (+1/-0/💬0) 1 pull requests submitted: - Change Script Enforcement Mechanism to use flags (by lukewarlow) https://github.com/w3c/trusted-types/pull/533 Repositories tracked by this digest: ----------------------------------- * https://github.com/w3c/webappsec * https://github.com/w3c/webappsec-subresource-integrity * https://github.com/w3c/webappsec-csp * https://github.com/w3c/webappsec-mixed-content * https://github.com/w3c/webappsec-upgrade-insecure-requests * https://github.com/w3c/webappsec-credential-management * https://github.com/w3c/permissions * https://github.com/w3c/permissions-registry * https://github.com/w3c/webappsec-referrer-policy * https://github.com/w3c/webappsec-secure-contexts * https://github.com/w3c/webappsec-clear-site-data * https://github.com/w3c/webappsec-cowl * https://github.com/w3c/webappsec-epr * https://github.com/w3c/webappsec-suborigins * https://github.com/w3c/webappsec-cspee * https://github.com/w3c/webappsec-permissions-policy * https://github.com/w3c/webappsec-fetch-metadata * https://github.com/w3c/webappsec-trusted-types * https://github.com/w3c/webappsec-change-password-url * https://github.com/w3c/webappsec-post-spectre-webdev -- Sent via github-notify-ml as configured in https://github.com/w3c/github-notify-ml-config
Received on Monday, 8 July 2024 17:00:24 UTC