- From: W3C Webmaster via GitHub API <sysbot+gh@w3.org>
- Date: Mon, 31 Mar 2025 17:00:26 +0000
- To: public-webappsec@w3.org
- Message-Id: <E1tzIUs-000VHa-1s@janus.w3.internal>
Issues ------ * w3c/webappsec (+0/-2/💬2) 2 issues received 2 new comments: - #672 CfC to publish WebCryptoAPI2 as a FPWD. (1 by mikewest) https://github.com/w3c/webappsec/issues/672 - #671 CfC to publish SRI2 as a FPWD. (1 by mikewest) https://github.com/w3c/webappsec/issues/671 2 issues closed: - CfC to publish SRI2 as a FPWD. https://github.com/w3c/webappsec/issues/671 - CfC to publish WebCryptoAPI2 as a FPWD. https://github.com/w3c/webappsec/issues/672 * w3c/webappsec-csp (+0/-2/💬4) 3 issues received 4 new comments: - #707 "source file" lacks a real defintion (1 by dveditz) https://github.com/w3c/webappsec-csp/issues/707 [clarification] [interop] - #694 Allow RFC3986 scheme relative URIs in host-source (2 by Mahoney, dveditz) https://github.com/w3c/webappsec-csp/issues/694 - #682 CSP headers are incorrect with multiple rules (1 by dveditz) https://github.com/w3c/webappsec-csp/issues/682 2 issues closed: - CSP headers are incorrect with multiple rules https://github.com/w3c/webappsec-csp/issues/682 - How to prevent an iframe with srcdoc and defined csp from inheriting the parent page's CSP policies https://github.com/w3c/webappsec-csp/issues/700 [wontfix] * w3c/webappsec-clear-site-data (+0/-0/💬1) 1 issues received 1 new comments: - #68 Drop cache (1 by miketaylr) https://github.com/w3c/webappsec-clear-site-data/issues/68 * w3c/webappsec-trusted-types (+0/-0/💬7) 3 issues received 7 new comments: - #580 CSP syntax for `require-trusted-types-for` should be forgiving (3 by fred-wang, lukewarlow) https://github.com/w3c/trusted-types/issues/580 - #504 `createPolicy`'s permitted policy names are inconsistent with CSP's permitted policy names (2 by fred-wang) https://github.com/w3c/trusted-types/issues/504 [spec] - #466 Creating a policy with policyName="" is possible, but can't be referred to by the "trusted-types" CSP directive (2 by fred-wang) https://github.com/w3c/trusted-types/issues/466 Pull requests ------------- * w3c/webappsec-subresource-integrity (+0/-0/💬11) 1 pull requests received 11 new comments: - #129 Revive require-sri-for for scripts (11 by annevk, mozfreddyb, tomrittervg, yoavweiss) https://github.com/w3c/webappsec-subresource-integrity/pull/129 Repositories tracked by this digest: ----------------------------------- * https://github.com/w3c/webappsec * https://github.com/w3c/webappsec-subresource-integrity * https://github.com/w3c/webappsec-csp * https://github.com/w3c/webappsec-mixed-content * https://github.com/w3c/webappsec-upgrade-insecure-requests * https://github.com/w3c/webappsec-credential-management * https://github.com/w3c/permissions * https://github.com/w3c/permissions-registry * https://github.com/w3c/webappsec-referrer-policy * https://github.com/w3c/webappsec-secure-contexts * https://github.com/w3c/webappsec-clear-site-data * https://github.com/w3c/webappsec-cowl * https://github.com/w3c/webappsec-epr * https://github.com/w3c/webappsec-suborigins * https://github.com/w3c/webappsec-cspee * https://github.com/w3c/webappsec-permissions-policy * https://github.com/w3c/webappsec-fetch-metadata * https://github.com/w3c/webappsec-trusted-types * https://github.com/w3c/webappsec-change-password-url * https://github.com/w3c/webappsec-post-spectre-webdev -- Sent via github-notify-ml as configured in https://github.com/w3c/github-notify-ml-config
Received on Monday, 31 March 2025 17:00:27 UTC