Weekly github digest (WebAppSec specs)

Issues
------
* w3c/webappsec (+1/-0/💬1)
  1 issues created:
  - Request for feedback: /.well-known/recover-account proposal (by felipecpaiva)
    https://github.com/w3c/webappsec/issues/701 

  1 issues received 1 new comments:
  - #701 Request for feedback: /.well-known/recover-account proposal (1 by miketaylr)
    https://github.com/w3c/webappsec/issues/701 

* w3c/webappsec-csp (+1/-0/💬3)
  1 issues created:
  - `frame-src` WPT test expects path to be stripped when loading cross-origin URL (by TimvdLippe)
    https://github.com/w3c/webappsec-csp/issues/809 

  2 issues received 3 new comments:
  - #809 `frame-src` WPT test expects path to be stripped when loading cross-origin URL (1 by antosart)
    https://github.com/w3c/webappsec-csp/issues/809 
  - #735 Implementation differences with "Strip URL for use in reports" (2 by TimvdLippe, annevk)
    https://github.com/w3c/webappsec-csp/issues/735 

* w3c/webappsec-credential-management (+0/-1/💬0)
  1 issues closed:
  - Disallow multiple types via navigator.credentials's methods https://github.com/w3c/webappsec-credential-management/issues/244 



Pull requests
-------------
* w3c/webappsec-csp (+0/-0/💬1)
  1 pull requests received 1 new comments:
  - #799 Add WebDriver BiDi CSP bypass checks (1 by juliandescottes)
    https://github.com/w3c/webappsec-csp/pull/799 

* w3c/webappsec-credential-management (+0/-0/💬2)
  1 pull requests received 2 new comments:
  - #261 Define with types are allowed in the same get() request (2 by marcoscaceres, mohamedamir)
    https://github.com/w3c/webappsec-credential-management/pull/261 [type:technical] 

* w3c/webappsec-permissions-policy (+0/-0/💬1)
  1 pull requests received 1 new comments:
  - #582 Rename PermissionsPolicy interface back to FeaturePolicy (1 by marcoscaceres)
    https://github.com/w3c/webappsec-permissions-policy/pull/582 


Repositories tracked by this digest:
-----------------------------------
* https://github.com/w3c/webappsec
* https://github.com/w3c/webappsec-subresource-integrity
* https://github.com/w3c/webappsec-csp
* https://github.com/w3c/webappsec-mixed-content
* https://github.com/w3c/webappsec-upgrade-insecure-requests
* https://github.com/w3c/webappsec-credential-management
* https://github.com/w3c/permissions
* https://github.com/w3c/permissions-registry
* https://github.com/w3c/webappsec-referrer-policy
* https://github.com/w3c/webappsec-secure-contexts
* https://github.com/w3c/webappsec-clear-site-data
* https://github.com/w3c/webappsec-cowl
* https://github.com/w3c/webappsec-epr
* https://github.com/w3c/webappsec-suborigins
* https://github.com/w3c/webappsec-cspee
* https://github.com/w3c/webappsec-permissions-policy
* https://github.com/w3c/webappsec-fetch-metadata
* https://github.com/w3c/webappsec-trusted-types
* https://github.com/w3c/webappsec-change-password-url
* https://github.com/w3c/webappsec-post-spectre-webdev


-- 
Sent via github-notify-ml as configured in https://github.com/w3c/github-notify-ml-config

Received on Monday, 30 March 2026 17:00:41 UTC