Weekly github digest (WebAppSec specs)

Issues
------
* w3c/webappsec (+5/-0/💬4)
  5 issues created:
  - CfC to move CSP-3 to CR (by simoneonofri)
    https://github.com/w3c/webappsec/issues/682 
  - CfC to move Fetch Metadata  to CR (by simoneonofri)
    https://github.com/w3c/webappsec/issues/681 
  - CfC to move SRI-2 to CR (by simoneonofri)
    https://github.com/w3c/webappsec/issues/680 
  - CfC to move WebCrypto-2 to CR (by simoneonofri)
    https://github.com/w3c/webappsec/issues/679 
  - CfC to publish Well-Known URL for Relying Party Passkey Endpoints as a FPWD (by simoneonofri)
    https://github.com/w3c/webappsec/issues/678 

  2 issues received 4 new comments:
  - #675 Planning 2025-07-16. (3 by drubery, evilpie, mikewest)
    https://github.com/w3c/webappsec/issues/675 
  - #656 CSP and data exfiltration (1 by shivanigithub)
    https://github.com/w3c/webappsec/issues/656 

* w3c/webappsec-subresource-integrity (+0/-0/💬1)
  1 issues received 1 new comments:
  - #143 Integrity-Policy - multiple observed reports (1 by ezzak)
    https://github.com/w3c/webappsec-subresource-integrity/issues/143 [question] 

* w3c/webappsec-csp (+3/-2/💬2)
  3 issues created:
  - `report-multiple-violations-{01,02}` don't conform with the spec (by TimvdLippe)
    https://github.com/w3c/webappsec-csp/issues/781 
  - Alllo (by xabo81)
    https://github.com/w3c/webappsec-csp/issues/780 
  - FF (by xabo81)
    https://github.com/w3c/webappsec-csp/issues/779 

  1 issues received 2 new comments:
  - #774 setting cssText rather than style (2 by johanneswilm, mxxk)
    https://github.com/w3c/webappsec-csp/issues/774 

  2 issues closed:
  - Alllo https://github.com/w3c/webappsec-csp/issues/780 
  - FF https://github.com/w3c/webappsec-csp/issues/779 



Pull requests
-------------
* w3c/webappsec (+1/-1/💬0)
  1 pull requests submitted:
  - Update 2025-07-16-agenda.md (by simoneonofri)
    https://github.com/w3c/webappsec/pull/683 

  1 pull requests merged:
  - Update 2025-07-16-agenda.md
    https://github.com/w3c/webappsec/pull/683 

* w3c/webappsec-subresource-integrity (+6/-4/💬14)
  6 pull requests submitted:
  - [Editorial] Export the parse-metadata algorithm (by antosart)
    https://github.com/w3c/webappsec-subresource-integrity/pull/152 
  - reduce complexity of get strongest metadata (by Uzlopak)
    https://github.com/w3c/webappsec-subresource-integrity/pull/151 
  - avoid strict splitting in parseMetada to allow base64url (by Uzlopak)
    https://github.com/w3c/webappsec-subresource-integrity/pull/150 
  - Add issue & pull request template (by mozfreddyb)
    https://github.com/w3c/webappsec-subresource-integrity/pull/149 
  - Add style to possible destinations list (by FKLC)
    https://github.com/w3c/webappsec-subresource-integrity/pull/148 
  - parseMetadata: first check algorithm validity (by Uzlopak)
    https://github.com/w3c/webappsec-subresource-integrity/pull/147 

  3 pull requests received 14 new comments:
  - #151 reduce complexity of get strongest metadata (5 by Uzlopak, annevk, mozfreddyb)
    https://github.com/w3c/webappsec-subresource-integrity/pull/151 
  - #150 avoid strict splitting in parseMetada to allow base64url (3 by Uzlopak, mozfreddyb)
    https://github.com/w3c/webappsec-subresource-integrity/pull/150 
  - #147 parseMetadata: first check algorithm validity (6 by Uzlopak, evilpie, mozfreddyb, w3cbot)
    https://github.com/w3c/webappsec-subresource-integrity/pull/147 

  4 pull requests merged:
  - parseMetadata: first check algorithm validity
    https://github.com/w3c/webappsec-subresource-integrity/pull/147 
  - Add issue & pull request template
    https://github.com/w3c/webappsec-subresource-integrity/pull/149 
  - Add style to possible destinations list
    https://github.com/w3c/webappsec-subresource-integrity/pull/148 
  - Extend integrity policy's coverage to include stylesheets
    https://github.com/w3c/webappsec-subresource-integrity/pull/146 

* w3c/webappsec-csp (+0/-1/💬0)
  1 pull requests merged:
  - [Editorial] Reference algorithm instead of section for parse-metadata in SRI
    https://github.com/w3c/webappsec-csp/pull/778 


Repositories tracked by this digest:
-----------------------------------
* https://github.com/w3c/webappsec
* https://github.com/w3c/webappsec-subresource-integrity
* https://github.com/w3c/webappsec-csp
* https://github.com/w3c/webappsec-mixed-content
* https://github.com/w3c/webappsec-upgrade-insecure-requests
* https://github.com/w3c/webappsec-credential-management
* https://github.com/w3c/permissions
* https://github.com/w3c/permissions-registry
* https://github.com/w3c/webappsec-referrer-policy
* https://github.com/w3c/webappsec-secure-contexts
* https://github.com/w3c/webappsec-clear-site-data
* https://github.com/w3c/webappsec-cowl
* https://github.com/w3c/webappsec-epr
* https://github.com/w3c/webappsec-suborigins
* https://github.com/w3c/webappsec-cspee
* https://github.com/w3c/webappsec-permissions-policy
* https://github.com/w3c/webappsec-fetch-metadata
* https://github.com/w3c/webappsec-trusted-types
* https://github.com/w3c/webappsec-change-password-url
* https://github.com/w3c/webappsec-post-spectre-webdev


-- 
Sent via github-notify-ml as configured in https://github.com/w3c/github-notify-ml-config

Received on Monday, 14 July 2025 17:00:27 UTC