Weekly github digest (WebAppSec specs)

Issues
------
* w3c/webappsec (+0/-0/💬1)
  1 issues received 1 new comments:
  - #652 Planning 2024-06-19 (1 by marcoscaceres)
    https://github.com/w3c/webappsec/issues/652 

* w3c/webappsec-csp (+2/-0/💬2)
  2 issues created:
  - Add new CSP sandbox directive to allow SameSite=None cookies on top-level frames (by DCtheTall)
    https://github.com/w3c/webappsec-csp/issues/664 
  - frame-src is not effective in restricting the possible origins of subframes (by antosart)
    https://github.com/w3c/webappsec-csp/issues/662 

  1 issues received 2 new comments:
  - #664 Add new CSP sandbox directive to allow SameSite=None cookies on top-level frames (2 by annevk, johannhof)
    https://github.com/w3c/webappsec-csp/issues/664 

* w3c/webappsec-mixed-content (+1/-0/💬1)
  1 issues created:
  - Mixed content terms - confusing English (by hamishwillee)
    https://github.com/w3c/webappsec-mixed-content/issues/70 

  1 issues received 1 new comments:
  - #70 Mixed content terms - confusing English (1 by hamishwillee)
    https://github.com/w3c/webappsec-mixed-content/issues/70 

* w3c/webappsec-credential-management (+1/-4/💬4)
  1 issues created:
  - Can we drop the "webappsec-" from the rep name (by marcoscaceres)
    https://github.com/w3c/webappsec-credential-management/issues/229 

  2 issues received 4 new comments:
  - #229 Can we drop the "webappsec-" from the rep name (3 by clelland, marcoscaceres)
    https://github.com/w3c/webappsec-credential-management/issues/229 
  - #227 Fully active checks? (1 by marcoscaceres)
    https://github.com/w3c/webappsec-credential-management/issues/227 

  4 issues closed:
  - Fully active checks? https://github.com/w3c/webappsec-credential-management/issues/227 
  - Replace "a priori authenticated URL" with "potentially trustworthy URL" https://github.com/w3c/webappsec-credential-management/issues/166 [editorial] 
  - update all <a ...> anchors to use bikeshed shortcuts like [= https://github.com/w3c/webappsec-credential-management/issues/180 [editorial] 
  - Replace iff https://github.com/w3c/webappsec-credential-management/issues/222 [editorial] 

* w3c/webappsec-permissions-policy (+0/-0/💬2)
  1 issues received 2 new comments:
  - #444 Permissions Policy unload (2 by alexsch01, fergald)
    https://github.com/w3c/webappsec-permissions-policy/issues/444 

* w3c/webappsec-trusted-types (+1/-0/💬10)
  1 issues created:
  - Should all 3 script IDL setters change the associated script text value identically (by lukewarlow)
    https://github.com/w3c/trusted-types/issues/517 [spec] 

  1 issues received 10 new comments:
  - #517 Should all 3 script IDL setters change the associated script text value identically (10 by annevk, koto, lukewarlow)
    https://github.com/w3c/trusted-types/issues/517 [spec] 



Pull requests
-------------
* w3c/webappsec-csp (+1/-0/💬0)
  1 pull requests submitted:
  - Fix check of request initiator being "fetch" (by antosart)
    https://github.com/w3c/webappsec-csp/pull/663 

* w3c/webappsec-credential-management (+9/-7/💬11)
  9 pull requests submitted:
  - Chore: Update Ubuntu version (by marcoscaceres)
    https://github.com/w3c/webappsec-credential-management/pull/238 
  - Do fully active check on Prevent Silent Access (by marcoscaceres)
    https://github.com/w3c/webappsec-credential-management/pull/237 
  - Full active check should happen before AbortSignal check (by marcoscaceres)
    https://github.com/w3c/webappsec-credential-management/pull/236 
  - Editorial: fixup prevent silent access xrefs (by marcoscaceres)
    https://github.com/w3c/webappsec-credential-management/pull/235 
  - Editorial: Replace "a priori authenticated URL" with "potentially trustworthy URL (by marcoscaceres)
    https://github.com/w3c/webappsec-credential-management/pull/234 
  - Editorial: use bikeshed shorthands (by marcoscaceres)
    https://github.com/w3c/webappsec-credential-management/pull/233 
  - Editorial: expand iff to if and only if (by marcoscaceres)
    https://github.com/w3c/webappsec-credential-management/pull/232 
  - chore: add PULL_REQUEST_TEMPLATE (by marcoscaceres)
    https://github.com/w3c/webappsec-credential-management/pull/231 
  - Add fully active checks (by marcoscaceres)
    https://github.com/w3c/webappsec-credential-management/pull/230 

  3 pull requests received 11 new comments:
  - #236 Full active check should happen before AbortSignal check (1 by marcoscaceres)
    https://github.com/w3c/webappsec-credential-management/pull/236 
  - #235 Editorial: fixup prevent silent access xrefs (1 by nsatragno)
    https://github.com/w3c/webappsec-credential-management/pull/235 
  - #230 Add fully active checks (9 by marcoscaceres, nsatragno)
    https://github.com/w3c/webappsec-credential-management/pull/230 

  7 pull requests merged:
  - Full active check should happen before AbortSignal check
    https://github.com/w3c/webappsec-credential-management/pull/236 
  - Add fully active checks
    https://github.com/w3c/webappsec-credential-management/pull/230 
  - Editorial: fixup prevent silent access xrefs
    https://github.com/w3c/webappsec-credential-management/pull/235 
  - Editorial: Replace "a priori authenticated URL" with "potentially trustworthy URL
    https://github.com/w3c/webappsec-credential-management/pull/234 
  - Editorial: use bikeshed shorthands
    https://github.com/w3c/webappsec-credential-management/pull/233 
  - Editorial: expand iff to if and only if
    https://github.com/w3c/webappsec-credential-management/pull/232 
  - chore: add PULL_REQUEST_TEMPLATE
    https://github.com/w3c/webappsec-credential-management/pull/231 


Repositories tracked by this digest:
-----------------------------------
* https://github.com/w3c/webappsec
* https://github.com/w3c/webappsec-subresource-integrity
* https://github.com/w3c/webappsec-csp
* https://github.com/w3c/webappsec-mixed-content
* https://github.com/w3c/webappsec-upgrade-insecure-requests
* https://github.com/w3c/webappsec-credential-management
* https://github.com/w3c/permissions
* https://github.com/w3c/permissions-registry
* https://github.com/w3c/webappsec-referrer-policy
* https://github.com/w3c/webappsec-secure-contexts
* https://github.com/w3c/webappsec-clear-site-data
* https://github.com/w3c/webappsec-cowl
* https://github.com/w3c/webappsec-epr
* https://github.com/w3c/webappsec-suborigins
* https://github.com/w3c/webappsec-cspee
* https://github.com/w3c/webappsec-permissions-policy
* https://github.com/w3c/webappsec-fetch-metadata
* https://github.com/w3c/webappsec-trusted-types
* https://github.com/w3c/webappsec-change-password-url
* https://github.com/w3c/webappsec-post-spectre-webdev


-- 
Sent via github-notify-ml as configured in https://github.com/w3c/github-notify-ml-config

Received on Monday, 27 May 2024 17:00:20 UTC