Displaying 1 - 50 of 129
Title Status Priority Category Version Component Replies Last updatedsort ascending Assigned to Created
text about drupal 6 Reviewed & tested by the community Minor Bug report 2.0.3 Documentation 7 4 days 11 hours 9 months 1 week
Changing configuration should invalidate http_response cache tag Active Normal Feature request 2.x-dev Code 1 1 month 1 week 1 month 1 week
Add support for the Cross-Origin-Opener-Policy (COOP) header Reviewed & tested by the community Normal Feature request 2.x-dev Code 8 1 month 1 week 1 year 1 month
Automated Drupal 12 compatibility fixes for seckit 2.x-dev Needs review Normal Task 2.x-dev Code 5 1 month 2 weeks 2 months 1 week
Add Permissions Policy to configurable options Reviewed & tested by the community Normal Feature request 2.x-dev Code 39 2 months 2 weeks 5 years 9 months
[META] Roadmap to new release Active Normal Feature request 2.x-dev Code 2 2 months 2 weeks 4 months 3 weeks
Avoid using document.write('<!--'); Reviewed & tested by the community Normal Task 2.x-dev Code 42 3 months 11 hours 5 years 7 months
Breaks sitemap.xml when JS +CSS + Noscript protection is enabled Needs review Normal Bug report 2.0.0 Code 11 3 months 14 hours 5 years 2 months
Add support for the CSP worker-src directive Reviewed & tested by the community Normal Feature request 2.0.3 Code 9 3 months 1 day 2 years 5 months
Implement a "semi automatic" Nonce settings Needs review Normal Feature request 2.x-dev Miscellaneous 30 3 months 4 weeks 4 years 10 months
Add form-action directive Reviewed & tested by the community Normal Feature request 2.x-dev Code 23 4 months 1 week 5 years 2 months
Add Tugboat support Needs review Normal Task 2.x-dev Code 3 4 months 3 weeks 4 months 3 weeks
fix gaps in automated test coverage Needs review Normal Task 2.0.3 Code 3 5 months 4 days 5 months 4 days
Add missing config schema definitions for X-XSS-Protection options in Seckit Reviewed & tested by the community Normal Bug report 2.0.3 Code 3 5 months 6 days 8 months 1 week
Support for configuring script-src-elem Active Normal Feature request 2.x-dev Code 6 5 months 1 week 1 year 5 months
ALLOW-FROM directive in x-frame-options is obsolete Active Normal Bug report 2.0.0 Code 5 5 months 2 weeks 3 years 9 months
Remove the term whitelist* from the module Needs review Normal Task 2.0.3 Code 13 6 months 2 weeks 1 year 2 weeks
Add trusted-type and require-trusted-type-for directives to the CSP Needs review Normal Feature request 2.x-dev Code 3 6 months 3 weeks 6 months 3 weeks
Support flood control for CSP violation reports Needs work Major Task 8.x-1.x-dev Code 66 7 months 2 days kmoll 10 years 5 months
Enabling "Enable JavaScript + CSS + Noscript protection" causes invalid HTML Needs work Normal Bug report 2.x-dev Code 24 7 months 1 week 7 years 2 months
noscript in head tag causing HTML Validation issues Active Major Bug report 2.0.0 Code 2 7 months 1 week 4 years 3 months
report-uri is deprecated Needs work Normal Bug report 2.x-dev Code 14 7 months 3 weeks 3 years 4 months
Add manifest-src Needs work Normal Feature request 2.0.0 Code 4 7 months 3 weeks 5 years 5 months
The base-uri policy is missing Needs review Normal Bug report 2.x-dev Code 42 7 months 3 weeks 6 years 8 months
Update CSP directives Needs review Normal Feature request 2.x-dev Code 10 10 months 4 days 8 years 10 months
JavaScript + CSS + Noscript protection can cause Javascript errors Active Normal Bug report 2.x-dev Code 2 10 months 2 weeks 10 months 2 weeks
CSP: Directive script-src-elem violated with googletagmanager Reviewed & tested by the community Normal Support request 2.x-dev Code 22 10 months 3 weeks 5 years 4 months
cspell issues reported in pipeline Active Normal Task 2.x-dev Code 4 1 year 2 weeks 1 year 1 month
Implement the script-src-attr policy Needs review Normal Feature request 2.x-dev Code 7 1 year 2 months 4 years 5 months
User interface improvements Active Minor Feature request 2.0.3 User interface 4 1 year 3 months 1 year 3 months
Extend length of src fields Needs review Major Feature request 2.0.0 Code 9 1 year 3 months 5 years 4 months
default-src has wrong description Needs review Major Bug report 2.x-dev Documentation 17 1 year 6 months 5 years 7 months
How to add all google tlds for CSP Active Normal Support request 2.0.0 User interface 10 1 year 6 months 4 years 2 months
Google URL's are blocked. Active Major Support request 2.0.1 Miscellaneous 5 1 year 6 months 2 years 7 months
Seckit seckitGetJsCssNoscriptCode hijacks js aggregation files. Needs work Normal Bug report 2.x-dev Code 9 1 year 8 months 2 years 4 months
"Directive style-src-elem violated." Needs review Normal Feature request 7.x-1.x-dev Code 23 1 year 8 months 5 years 11 months
Allow certain paths to be excluded from the Origin check (patch included) Needs review Normal Feature request 2.0.0 Code 4 1 year 9 months 5 years 6 months
Add worker-src Reviewed & tested by the community Normal Feature request 7.x-1.x-dev Code 12 1 year 9 months 4 years 1 month
Dispatch an event when there is a CSP violation Needs review Normal Feature request 2.x-dev Code 3 1 year 9 months 1 year 9 months
Missing container invalidation update from issue modifying services Active Normal Bug report 2.x-dev Code 8 1 year 10 months 1 year 11 months
Clickjacking CSS protection hides content when site is embed inside an iframe, even if frame-ancestors is set Needs review Normal Bug report 2.0.1 Code 9 1 year 11 months 2 years 7 months
Provide hook_seckit_options_alter() D8 Needs review Major Feature request 2.0.3 Code 26 1 year 11 months 9 years 7 months
Update summary on project page for compatibility with Project Browser Active Normal Task 2.0.3 Miscellaneous 1 1 year 11 months 1 year 11 months
Update logo for compatibility with Project Browser Active Normal Task 2.0.3 Miscellaneous 1 1 year 11 months 1 year 11 months
Modernize services: Add autowiring aliases, use autoconfigure, etc Needs review Normal Task 2.x-dev Code 6 1 year 11 months 1 year 11 months
Multiple html lines of seckitGetJsCssNoscriptCode function create issue when js aggregate and minify html is on Active Normal Bug report 2.0.1 Code 2 1 year 11 months hetalsagar 1 year 11 months
Silent mode for CSP reporting Active Normal Feature request 2.x-dev Code 4 1 year 11 months 4 years 3 months
Store CSP sources as a list of values on multiple lines to increase manageability and prevent merge conflicts Needs review Normal Feature request 2.x-dev Code 13 2 years 1 week 2 years 10 months
Drupal 9.1 Deprecated Code Report Reviewed & tested by the community Normal Task 2.x-dev Code 17 2 years 2 months sourabhjain 5 years 7 months
Question about HSTS max-age Active Normal Support request 2.0.1 Miscellaneous 2 2 years 2 months 2 years 5 months

Pages

Subscribe with RSS Subscribe to Issues for Security Kit