GitHub / github/secure_headers issues and pull requests
#573 - Bump ruby/setup-ruby from 1.275.0 to 1.276.0
Pull Request -
State: closed - Opened by dependabot[bot] about 2 months ago
Labels: dependencies, github_actions
#566 - 7.2 release
Pull Request -
State: open - Opened by rei-moo about 2 months ago
#560 - Add explicit dependency to 'cgi' for ruby 4.0 support
Pull Request -
State: open - Opened by vcsjones 2 months ago
#557 - Kyfast/report to directive
Pull Request -
State: open - Opened by KyFaSt 3 months ago
#556 - Add support for W3C Reporting API
Pull Request -
State: open - Opened by tmaier 4 months ago
#555 - fix(514): fix compatibility with rack 3
Pull Request -
State: open - Opened by deril 9 months ago
#554 - Bump ruby/setup-ruby from 1.207.0 to 1.230.0
Pull Request -
State: open - Opened by dependabot[bot] 10 months ago
Labels: dependencies, github_actions
#553 - Bump ruby/setup-ruby from 1.207.0 to 1.229.0
Pull Request -
State: closed - Opened by dependabot[bot] 11 months ago
- 1 comment
Labels: dependencies, github_actions
#553 - Bump ruby/setup-ruby from 1.207.0 to 1.229.0
Pull Request -
State: closed - Opened by dependabot[bot] 11 months ago
- 1 comment
Labels: dependencies, github_actions
#552 - Bump ruby/setup-ruby from 1.207.0 to 1.227.0
Pull Request -
State: closed - Opened by dependabot[bot] 11 months ago
- 1 comment
Labels: dependencies, github_actions
#552 - Bump ruby/setup-ruby from 1.207.0 to 1.227.0
Pull Request -
State: open - Opened by dependabot[bot] 11 months ago
Labels: dependencies, github_actions
#551 - Remove non-lowercase headers in Rails default configuration (fixes #541)
Pull Request -
State: open - Opened by obrie 11 months ago
#550 - Bump ruby/setup-ruby from 1.207.0 to 1.226.0
Pull Request -
State: closed - Opened by dependabot[bot] 11 months ago
- 1 comment
Labels: dependencies, github_actions
#550 - Bump ruby/setup-ruby from 1.207.0 to 1.226.0
Pull Request -
State: closed - Opened by dependabot[bot] 11 months ago
- 1 comment
Labels: dependencies, github_actions
#549 - Bump ruby/setup-ruby from 1.207.0 to 1.222.0
Pull Request -
State: closed - Opened by dependabot[bot] 11 months ago
- 1 comment
Labels: dependencies, github_actions
#549 - Bump ruby/setup-ruby from 1.207.0 to 1.222.0
Pull Request -
State: closed - Opened by dependabot[bot] 11 months ago
- 1 comment
Labels: dependencies, github_actions
#548 - Bump ruby/setup-ruby from 1.207.0 to 1.221.0
Pull Request -
State: closed - Opened by dependabot[bot] 12 months ago
- 1 comment
Labels: dependencies
#547 - Bump ruby/setup-ruby from 1.207.0 to 1.218.0
Pull Request -
State: open - Opened by dependabot[bot] about 1 year ago
Labels: dependencies
#547 - Bump ruby/setup-ruby from 1.207.0 to 1.218.0
Pull Request -
State: closed - Opened by dependabot[bot] about 1 year ago
- 1 comment
Labels: dependencies
#546 - fix: Fix typos
Pull Request -
State: open - Opened by myersg86 about 1 year ago
#546 - fix: Fix typos
Pull Request -
State: open - Opened by myersg86 about 1 year ago
#545 - "Configuration already exists" error
Issue -
State: open - Opened by owen2345 about 1 year ago
#544 - Bump ruby/setup-ruby from 1.207.0 to 1.215.0
Pull Request -
State: closed - Opened by dependabot[bot] about 1 year ago
- 1 comment
Labels: dependencies
#544 - Bump ruby/setup-ruby from 1.207.0 to 1.215.0
Pull Request -
State: closed - Opened by dependabot[bot] about 1 year ago
- 1 comment
Labels: dependencies
#543 - Bump ruby/setup-ruby from 1.207.0 to 1.214.0
Pull Request -
State: closed - Opened by dependabot[bot] about 1 year ago
- 1 comment
Labels: dependencies
#542 - Bump ruby/setup-ruby from 1.207.0 to 1.213.0
Pull Request -
State: closed - Opened by dependabot[bot] about 1 year ago
- 1 comment
Labels: dependencies
#542 - Bump ruby/setup-ruby from 1.207.0 to 1.213.0
Pull Request -
State: closed - Opened by dependabot[bot] about 1 year ago
- 1 comment
Labels: dependencies
#541 - Lowercase header issue: SecureHeaders::OPT_OUT Fails to Remove Non-Lowercase Headers in Rails Default Config
Issue -
State: open - Opened by GabDesilets about 1 year ago
#540 - Bump ruby/setup-ruby from 1.204.0 to 1.207.0
Pull Request -
State: open - Opened by dependabot[bot] about 1 year ago
Labels: dependencies
#540 - Bump ruby/setup-ruby from 1.204.0 to 1.207.0
Pull Request -
State: closed - Opened by dependabot[bot] about 1 year ago
Labels: dependencies
#539 - Bump ruby/setup-ruby from 1.204.0 to 1.206.0
Pull Request -
State: open - Opened by dependabot[bot] about 1 year ago
Labels: dependencies
#539 - Bump ruby/setup-ruby from 1.204.0 to 1.206.0
Pull Request -
State: closed - Opened by dependabot[bot] about 1 year ago
- 1 comment
Labels: dependencies
#538 - Bump ruby/setup-ruby from 1.203.0 to 1.204.0
Pull Request -
State: closed - Opened by dependabot[bot] about 1 year ago
Labels: dependencies
#538 - Bump ruby/setup-ruby from 1.203.0 to 1.204.0
Pull Request -
State: closed - Opened by dependabot[bot] about 1 year ago
Labels: dependencies
#537 - Bump ruby/setup-ruby from 1.202.0 to 1.203.0
Pull Request -
State: open - Opened by dependabot[bot] about 1 year ago
Labels: dependencies
#537 - Bump ruby/setup-ruby from 1.202.0 to 1.203.0
Pull Request -
State: closed - Opened by dependabot[bot] about 1 year ago
Labels: dependencies
#536 - Cleanup Repository files and Gem build
Pull Request -
State: closed - Opened by rzhade3 about 1 year ago
#536 - Cleanup Repository files and Gem build
Pull Request -
State: closed - Opened by rzhade3 about 1 year ago
#535 - Bump ruby/setup-ruby from 1.197.0 to 1.202.0
Pull Request -
State: closed - Opened by dependabot[bot] over 1 year ago
Labels: dependencies
#535 - Bump ruby/setup-ruby from 1.197.0 to 1.202.0
Pull Request -
State: closed - Opened by dependabot[bot] over 1 year ago
Labels: dependencies
#534 - Bump ruby/setup-ruby from 1.197.0 to 1.199.0
Pull Request -
State: closed - Opened by dependabot[bot] over 1 year ago
- 1 comment
Labels: dependencies
#534 - Bump ruby/setup-ruby from 1.197.0 to 1.199.0
Pull Request -
State: closed - Opened by dependabot[bot] over 1 year ago
- 1 comment
Labels: dependencies
#533 - Lowercase headers
Pull Request -
State: closed - Opened by arashnd over 1 year ago
- 2 comments
#533 - Lowercase headers
Pull Request -
State: closed - Opened by arashnd over 1 year ago
- 2 comments
#532 - Set default `frame-ancestors` on default Content-Security-Policy
Issue -
State: open - Opened by rzhade3 over 1 year ago
#531 - Remove non necessary files from bundled Ruby Gem
Issue -
State: closed - Opened by rzhade3 over 1 year ago
- 1 comment
Labels: good first issue
#530 - Bump ruby/setup-ruby from 1.196.0 to 1.197.0
Pull Request -
State: closed - Opened by dependabot[bot] over 1 year ago
Labels: dependencies
#530 - Bump ruby/setup-ruby from 1.196.0 to 1.197.0
Pull Request -
State: closed - Opened by dependabot[bot] over 1 year ago
Labels: dependencies
#529 - Add report-to CSP directive
Pull Request -
State: open - Opened by loremotta33 over 1 year ago
- 4 comments
#529 - Add report-to CSP directive
Pull Request -
State: open - Opened by loremotta33 over 1 year ago
#528 - Upgrade version and docs to 7.0
Pull Request -
State: closed - Opened by rzhade3 over 1 year ago
#528 - Upgrade version and docs to 7.0
Pull Request -
State: closed - Opened by rzhade3 over 1 year ago
#527 - Bump ruby/setup-ruby from 1.195.0 to 1.196.0
Pull Request -
State: closed - Opened by dependabot[bot] over 1 year ago
Labels: dependencies
#527 - Bump ruby/setup-ruby from 1.195.0 to 1.196.0
Pull Request -
State: closed - Opened by dependabot[bot] over 1 year ago
Labels: dependencies
#526 - Bump ruby/setup-ruby from 1.190.0 to 1.195.0
Pull Request -
State: closed - Opened by dependabot[bot] over 1 year ago
Labels: dependencies
#525 - Bump ruby/setup-ruby from 1.190.0 to 1.194.0
Pull Request -
State: closed - Opened by dependabot[bot] over 1 year ago
- 1 comment
Labels: dependencies
#525 - Bump ruby/setup-ruby from 1.190.0 to 1.194.0
Pull Request -
State: open - Opened by dependabot[bot] over 1 year ago
Labels: dependencies
#524 - Bump ruby/setup-ruby from 1.190.0 to 1.193.0
Pull Request -
State: closed - Opened by dependabot[bot] over 1 year ago
- 1 comment
Labels: dependencies
#524 - Bump ruby/setup-ruby from 1.190.0 to 1.193.0
Pull Request -
State: closed - Opened by dependabot[bot] over 1 year ago
- 1 comment
Labels: dependencies
#523 - Bump ruby/setup-ruby from 1.190.0 to 1.192.0
Pull Request -
State: closed - Opened by dependabot[bot] over 1 year ago
- 1 comment
Labels: dependencies
#523 - Bump ruby/setup-ruby from 1.190.0 to 1.192.0
Pull Request -
State: closed - Opened by dependabot[bot] over 1 year ago
- 1 comment
Labels: dependencies
#522 - Bump ruby/setup-ruby from 1.190.0 to 1.191.0
Pull Request -
State: closed - Opened by dependabot[bot] over 1 year ago
- 1 comment
Labels: dependencies
#522 - Bump ruby/setup-ruby from 1.190.0 to 1.191.0
Pull Request -
State: closed - Opened by dependabot[bot] over 1 year ago
- 1 comment
Labels: dependencies
#521 - [Housekeeping] Add permissions to build workflow and pin ruby
Pull Request -
State: closed - Opened by vcsjones over 1 year ago
#521 - [Housekeeping] Add permissions to build workflow and pin ruby
Pull Request -
State: closed - Opened by vcsjones over 1 year ago
#520 - Update build.yml
Pull Request -
State: closed - Opened by boveus over 1 year ago
#520 - Update build.yml
Pull Request -
State: closed - Opened by boveus over 1 year ago
#517 - yajsahdas
Issue -
State: open - Opened by lasgdbahsdghas over 1 year ago
#516 - fix: Avoid throwing cookie headers when encountering an empty cookie-av
Pull Request -
State: closed - Opened by MrLukeSmith over 1 year ago
- 1 comment
#516 - fix: Avoid throwing cookie headers when encountering an empty cookie-av
Pull Request -
State: closed - Opened by MrLukeSmith over 1 year ago
- 1 comment
#515 - hvhjmh
Pull Request -
State: open - Opened by kkakhsdvash over 1 year ago
#514 - SecureHeaders middleware erases all cookies in Rack 3 due to \n joining
Issue -
State: open - Opened by collinsauve almost 2 years ago
- 1 comment
#513 - RubyGems doesn't have latest version of this gem
Issue -
State: closed - Opened by zmariscal over 2 years ago
- 3 comments
#512 - CSP Report-uri deprecated, replaced by report-to
Issue -
State: open - Opened by martindaehn23 over 2 years ago
- 1 comment
#511 - `content_security_policy_nonce` calls Rails method so CSP does not contain nonce
Issue -
State: open - Opened by jdudley1123 over 2 years ago
- 2 comments
#509 - deprecate block-all-mixed-content
Pull Request -
State: closed - Opened by KyFaSt over 2 years ago
#508 - test issue
Issue -
State: closed - Opened by KyFaSt over 2 years ago
#507 - test issue
Issue -
State: closed - Opened by KyFaSt over 2 years ago
#506 - Make SecureSecurityPolicyConfig significantly faster
Pull Request -
State: closed - Opened by jhawthorn almost 3 years ago
#505 - How can I disable 'unsafe-inline' from script-src?
Issue -
State: closed - Opened by josemateuss almost 3 years ago
- 1 comment
#504 - Adds Ruby 3.2 to the CI matrix
Pull Request -
State: closed - Opened by petergoldstein about 3 years ago
- 1 comment
#503 - jekyll integration
Issue -
State: closed - Opened by LeoWebSEO over 3 years ago
- 3 comments
#502 - Update `.ruby-version` to `3.1.1`
Pull Request -
State: closed - Opened by lgarron over 3 years ago
#501 - v6.5.0
Pull Request -
State: closed - Opened by lgarron over 3 years ago
#500 - CI changes: run on push, drop Ruby 2.5
Pull Request -
State: closed - Opened by lgarron over 3 years ago
#499 - Remove source expression deduplication.
Pull Request -
State: closed - Opened by lgarron over 3 years ago
#498 - Semantically parse and deduplicate source expressions
Pull Request -
State: closed - Opened by lgarron over 3 years ago
- 3 comments
#497 - Semantically parse source expressions.
Pull Request -
State: closed - Opened by lgarron over 3 years ago
#496 - Set license code in metadata to MIT
Pull Request -
State: closed - Opened by ekohl over 3 years ago
#495 - Trusted types: Use single-quoted `'script'`.
Pull Request -
State: closed - Opened by lgarron over 3 years ago
#494 - update version and changelog
Pull Request -
State: closed - Opened by KyFaSt over 3 years ago
#493 - Use SPDX license code and swap summary & description
Pull Request -
State: closed - Opened by ekohl over 3 years ago
#492 - Installation instructions unclear
Issue -
State: closed - Opened by TravisSpangle over 3 years ago
- 1 comment
#491 - URI::InvalidURIError: Invalid data URI
Issue -
State: closed - Opened by istana over 3 years ago
- 1 comment
#490 - fix source dedup breaking with port wildcards
Pull Request -
State: closed - Opened by machisuji over 3 years ago
- 7 comments
#489 - Add Ruby 3.1 to the CI configuration
Pull Request -
State: closed - Opened by petergoldstein over 3 years ago
- 1 comment
#488 - Add Dependabot for GitHub Actions
Pull Request -
State: closed - Opened by petergoldstein over 3 years ago
- 2 comments
#487 - Update changelog and version for v6.3.4.
Pull Request -
State: closed - Opened by lgarron over 3 years ago
#486 - Add trusted-types and require-trusted-types-for CSP Directive
Pull Request -
State: closed - Opened by KyFaSt over 3 years ago
#485 - Add tests for hash generation
Pull Request -
State: open - Opened by rahearn over 3 years ago