Weekly github digest (WebAppSec specs)

Issues
------
* w3c/webappsec (+1/-1/💬0)
  1 issues created:
  - Planning 2026-05-20. (by mikewest)
    https://github.com/w3c/webappsec/issues/702 

  1 issues closed:
  - Planning 2026-04-15 https://github.com/w3c/webappsec/issues/700 

* w3c/webappsec-csp (+1/-0/💬2)
  1 issues created:
  - Embedded enforcement links are broken (by domfarolino)
    https://github.com/w3c/webappsec-csp/issues/811 

  1 issues received 2 new comments:
  - #735 Implementation differences with "Strip URL for use in reports" (2 by annevk, antosart)
    https://github.com/w3c/webappsec-csp/issues/735 

* w3c/webappsec-credential-management (+1/-1/💬0)
  1 issues created:
  - Fix TypeError exception type in "Request a Credential" algorithm (by marcoscaceres)
    https://github.com/w3c/webappsec-credential-management/issues/293 

  1 issues closed:
  - Fix TypeError exception type in "Request a Credential" algorithm https://github.com/w3c/webappsec-credential-management/issues/293 

* w3c/permissions (+2/-0/💬1)
  2 issues created:
  - Permission state constraints don't always seem to be ensured (by antosart)
    https://github.com/w3c/permissions/issues/476 
  - Add more permissions into the registry (by saschanaz)
    https://github.com/w3c/permissions/issues/475 

  1 issues received 1 new comments:
  - #475 Add more permissions into the registry (1 by saschanaz)
    https://github.com/w3c/permissions/issues/475 

* w3c/webappsec-trusted-types (+0/-0/💬2)
  1 issues received 2 new comments:
  - #594 Streaming support (2 by lukewarlow, noamr)
    https://github.com/w3c/trusted-types/issues/594 [enhancement] [spec] [future] 

* w3c/webappsec-change-password-url (+1/-1/💬1)
  1 issues created:
  - Suggestion: return JSON containing the URL (breaking change) (by irew)
    https://github.com/w3c/webappsec-change-password-url/issues/51 

  1 issues received 1 new comments:
  - #51 Suggestion: return JSON containing the URL (breaking change) (1 by irew)
    https://github.com/w3c/webappsec-change-password-url/issues/51 

  1 issues closed:
  - Suggestion: return JSON containing the URL (breaking change) https://github.com/w3c/webappsec-change-password-url/issues/51 



Pull requests
-------------
* w3c/webappsec-csp (+1/-0/💬2)
  1 pull requests submitted:
  - 810  (by mikewest)
    https://github.com/w3c/webappsec-csp/pull/810 

  1 pull requests received 2 new comments:
  - #810 Update nonceable attribute checks for link elements (2 by annevk, mikewest)
    https://github.com/w3c/webappsec-csp/pull/810 

* w3c/webappsec-credential-management (+2/-0/💬0)
  2 pull requests submitted:
  - 294  (by marcoscaceres)
    https://github.com/w3c/webappsec-credential-management/pull/294 
  - 292  (by marcoscaceres)
    https://github.com/w3c/webappsec-credential-management/pull/292 


Repositories tracked by this digest:
-----------------------------------
* https://github.com/w3c/webappsec
* https://github.com/w3c/webappsec-subresource-integrity
* https://github.com/w3c/webappsec-csp
* https://github.com/w3c/webappsec-mixed-content
* https://github.com/w3c/webappsec-upgrade-insecure-requests
* https://github.com/w3c/webappsec-credential-management
* https://github.com/w3c/permissions
* https://github.com/w3c/permissions-registry
* https://github.com/w3c/webappsec-referrer-policy
* https://github.com/w3c/webappsec-secure-contexts
* https://github.com/w3c/webappsec-clear-site-data
* https://github.com/w3c/webappsec-cowl
* https://github.com/w3c/webappsec-epr
* https://github.com/w3c/webappsec-suborigins
* https://github.com/w3c/webappsec-cspee
* https://github.com/w3c/webappsec-permissions-policy
* https://github.com/w3c/webappsec-fetch-metadata
* https://github.com/w3c/webappsec-trusted-types
* https://github.com/w3c/webappsec-change-password-url
* https://github.com/w3c/webappsec-post-spectre-webdev


-- 
Sent via github-notify-ml as configured in https://github.com/w3c/github-notify-ml-config

Received on Monday, 13 April 2026 17:00:43 UTC