- From: W3C Webmaster via GitHub API <sysbot+gh@w3.org>
- Date: Mon, 14 Apr 2025 17:00:26 +0000
- To: public-webappsec@w3.org
- Message-Id: <E1u4NAY-005BAE-0X@janus.w3.internal>
Issues
------
* w3c/webappsec (+0/-1/💬0)
1 issues closed:
- Planning 2025-04-16. https://github.com/w3c/webappsec/issues/670
* w3c/webappsec-csp (+0/-0/💬4)
2 issues received 4 new comments:
- #683 Introduce 'connect-certificate-hash' for WebTransport (3 by annevk, jan-ivar, vasilvv)
https://github.com/w3c/webappsec-csp/issues/683 [needs concrete proposal]
- #291 Consider hiding content attribute of meta tag CSP (1 by dveditz)
https://github.com/w3c/webappsec-csp/issues/291 [editorial]
* w3c/webappsec-credential-management (+3/-0/💬0)
3 issues created:
- Not all paths resolve/reject the promise in the `Request a Credential` algorithm (by devgianlu)
https://github.com/w3c/webappsec-credential-management/issues/271
- `PasswordCredential`'s partial `CredentialRequestOptions` has bogus default value (by devgianlu)
https://github.com/w3c/webappsec-credential-management/issues/270
- Task source to use when getting credentials (by marcoscaceres)
https://github.com/w3c/webappsec-credential-management/issues/269
* w3c/webappsec-trusted-types (+0/-0/💬6)
3 issues received 6 new comments:
- #584 navigation requests blocked by require-trusted-types-for don't set a violation sample (2 by annevk, fred-wang)
https://github.com/w3c/trusted-types/issues/584
- #566 Rely on WedIDL's "implements" definition for isHTML/isScript/isScriptURL? (2 by annevk, fred-wang)
https://github.com/w3c/trusted-types/issues/566
- #534 Should "Get Trusted Type compliant string" check `isHTML`/`isScript`/`isScriptURL`? (2 by annevk, fred-wang)
https://github.com/w3c/trusted-types/issues/534
Pull requests
-------------
* w3c/webappsec-trusted-types (+1/-0/💬1)
1 pull requests submitted:
- Add missing parameter name for algorithm (by TimvdLippe)
https://github.com/w3c/trusted-types/pull/585
1 pull requests received 1 new comments:
- #585 Add missing parameter name for algorithm (1 by TimvdLippe)
https://github.com/w3c/trusted-types/pull/585
Repositories tracked by this digest:
-----------------------------------
* https://github.com/w3c/webappsec
* https://github.com/w3c/webappsec-subresource-integrity
* https://github.com/w3c/webappsec-csp
* https://github.com/w3c/webappsec-mixed-content
* https://github.com/w3c/webappsec-upgrade-insecure-requests
* https://github.com/w3c/webappsec-credential-management
* https://github.com/w3c/permissions
* https://github.com/w3c/permissions-registry
* https://github.com/w3c/webappsec-referrer-policy
* https://github.com/w3c/webappsec-secure-contexts
* https://github.com/w3c/webappsec-clear-site-data
* https://github.com/w3c/webappsec-cowl
* https://github.com/w3c/webappsec-epr
* https://github.com/w3c/webappsec-suborigins
* https://github.com/w3c/webappsec-cspee
* https://github.com/w3c/webappsec-permissions-policy
* https://github.com/w3c/webappsec-fetch-metadata
* https://github.com/w3c/webappsec-trusted-types
* https://github.com/w3c/webappsec-change-password-url
* https://github.com/w3c/webappsec-post-spectre-webdev
--
Sent via github-notify-ml as configured in https://github.com/w3c/github-notify-ml-config
Received on Monday, 14 April 2025 17:00:27 UTC