{"repo":"w3c/webappsec-csp","summary":{"retrieved":"2026-05-16T07:47:22Z","triageViolations":45,"urgentViolations":0,"soonViolations":0,"agendaViolations":4,"needsEditsViolations":0,"needTriage":0,"urgent":0,"soon":0,"agenda":0,"needsEdits":0,"other":156},"triage":[{"number":226,"url":"https://github.com/w3c/webappsec-csp/issues/226","title":"Prefer blocking fall-through conditions","author":"aidantwoods","createdAt":"2017-07-26T23:18:33Z","labels":[],"sloTimeUsed":"P3215DT8H28M49S","whichSlo":"triage","stats":{"numTimelineItems":0,"numComments":0,"numLabels":0},"outOfSlo":true},{"number":235,"url":"https://github.com/w3c/webappsec-csp/issues/235","title":"Should frame-src control frames with \"local scheme\"?","author":"ameshkov","createdAt":"2017-08-31T11:34:50Z","labels":["needs concrete proposal"],"sloTimeUsed":"P3179DT20H12M32S","whichSlo":"triage","stats":{"numTimelineItems":1,"numComments":0,"numLabels":1},"outOfSlo":true},{"number":292,"url":"https://github.com/w3c/webappsec-csp/issues/292","title":"Potential wrong sha256 example in 'Hash usage for script elements'","author":"AnujRNair","createdAt":"2018-02-09T21:27:09Z","labels":["editorial"],"sloTimeUsed":"P3017DT10H20M13S","whichSlo":"triage","stats":{"numTimelineItems":1,"numComments":0,"numLabels":1},"outOfSlo":true},{"number":297,"url":"https://github.com/w3c/webappsec-csp/issues/297","title":"Expose host in a 'host' source reference","author":"emilfihlman","createdAt":"2018-02-23T13:45:57Z","labels":["needs concrete proposal","addition/proposal"],"sloTimeUsed":"P3003DT18H1M25S","whichSlo":"triage","stats":{"numTimelineItems":2,"numComments":0,"numLabels":2},"outOfSlo":true},{"number":314,"url":"https://github.com/w3c/webappsec-csp/issues/314","title":"Clarification of term \"parser-inserted\"","author":"nikitastupin","createdAt":"2018-06-06T16:23:27Z","labels":[],"sloTimeUsed":"P2900DT15H23M55S","whichSlo":"triage","stats":{"numTimelineItems":0,"numComments":0,"numLabels":0},"outOfSlo":true},{"number":384,"url":"https://github.com/w3c/webappsec-csp/issues/384","title":"policy's self-origin for CSP policies inserted by <meta>","author":"hiroshige-g","createdAt":"2019-02-11T23:24:30Z","labels":["editorial","clarification"],"sloTimeUsed":"P2650DT8H22M52S","whichSlo":"triage","stats":{"numTimelineItems":2,"numComments":0,"numLabels":2},"outOfSlo":true},{"number":387,"url":"https://github.com/w3c/webappsec-csp/issues/387","title":"http-equiv delivery method: recommend to set after <meta charset=\"utf-8\">?","author":"Malvoz","createdAt":"2019-03-09T22:30:23Z","labels":["editorial"],"sloTimeUsed":"P2624DT9H16M59S","whichSlo":"triage","stats":{"numTimelineItems":1,"numComments":0,"numLabels":1},"outOfSlo":true},{"number":388,"url":"https://github.com/w3c/webappsec-csp/issues/388","title":"Is CSPViolationReportBody a funny name?","author":"foolip","createdAt":"2019-03-15T16:54:07Z","labels":["editorial"],"sloTimeUsed":"P2618DT14H53M15S","whichSlo":"triage","stats":{"numTimelineItems":3,"numComments":0,"numLabels":1},"outOfSlo":true},{"number":397,"url":"https://github.com/w3c/webappsec-csp/issues/397","title":"Header parsing and integration with Fetch","author":"annevk","createdAt":"2019-05-28T13:20:57Z","labels":["addition/proposal"],"sloTimeUsed":"P2544DT18H26M25S","whichSlo":"triage","stats":{"numTimelineItems":1,"numComments":0,"numLabels":1},"outOfSlo":true},{"number":401,"url":"https://github.com/w3c/webappsec-csp/issues/401","title":"Define interaction between script-src / trusted-types","author":"mikesamuel","createdAt":"2019-06-13T20:10:48Z","labels":[],"sloTimeUsed":"P2528DT11H36M34S","whichSlo":"triage","stats":{"numTimelineItems":0,"numComments":0,"numLabels":0},"outOfSlo":true},{"number":406,"url":"https://github.com/w3c/webappsec-csp/issues/406","title":"Conflict in CSP reporting specs on nullable fields","author":"huchenlei","createdAt":"2019-08-16T15:06:23Z","labels":[],"sloTimeUsed":"P2464DT16H40M59S","whichSlo":"triage","stats":{"numTimelineItems":0,"numComments":0,"numLabels":0},"outOfSlo":true},{"number":408,"url":"https://github.com/w3c/webappsec-csp/issues/408","title":"Update spec to new IDL syntax for optional dictionaries","author":"Ms2ger","createdAt":"2019-08-22T09:16:31Z","labels":[],"sloTimeUsed":"P2458DT22H30M51S","whichSlo":"triage","stats":{"numTimelineItems":0,"numComments":0,"numLabels":0},"outOfSlo":true},{"number":409,"url":"https://github.com/w3c/webappsec-csp/issues/409","title":"Update to constructor operations","author":"Ms2ger","createdAt":"2019-08-29T09:00:24Z","labels":[],"sloTimeUsed":"P2451DT22H46M58S","whichSlo":"triage","stats":{"numTimelineItems":0,"numComments":0,"numLabels":0},"outOfSlo":true},{"number":416,"url":"https://github.com/w3c/webappsec-csp/issues/416","title":"Add version number to allow 'non-backwards compatible' CSP[version]-mode","author":"NL-William","createdAt":"2019-12-15T08:59:57Z","labels":[],"sloTimeUsed":"P2343DT22H47M25S","whichSlo":"triage","stats":{"numTimelineItems":0,"numComments":0,"numLabels":0},"outOfSlo":true},{"number":421,"url":"https://github.com/w3c/webappsec-csp/issues/421","title":"Inconsistent behavior of frame-ancestors versus implementations","author":"iangcarroll","createdAt":"2020-02-21T00:15:33Z","labels":[],"sloTimeUsed":"P2276DT7H31M49S","whichSlo":"triage","stats":{"numTimelineItems":0,"numComments":0,"numLabels":0},"outOfSlo":true},{"number":428,"url":"https://github.com/w3c/webappsec-csp/issues/428","title":"`unsafe-allow-redirects` and `form-action` interact weirdly","author":"bakkot","createdAt":"2020-03-20T02:01:31Z","labels":[],"sloTimeUsed":"P2248DT5H45M51S","whichSlo":"triage","stats":{"numTimelineItems":0,"numComments":0,"numLabels":0},"outOfSlo":true},{"number":432,"url":"https://github.com/w3c/webappsec-csp/issues/432","title":"Clarify that report-uri cannot violate mixed-content","author":"antosart","createdAt":"2020-04-24T08:45:28Z","labels":[],"sloTimeUsed":"P2212DT23H1M54S","whichSlo":"triage","stats":{"numTimelineItems":0,"numComments":0,"numLabels":0},"outOfSlo":true},{"number":442,"url":"https://github.com/w3c/webappsec-csp/issues/442","title":"Document that line-number and column-number are 1-based in CSP reporting spec","author":"adob","createdAt":"2020-09-16T18:32:50Z","labels":["editorial"],"sloTimeUsed":"P2067DT13H14M32S","whichSlo":"triage","stats":{"numTimelineItems":1,"numComments":0,"numLabels":1},"outOfSlo":true},{"number":514,"url":"https://github.com/w3c/webappsec-csp/issues/514","title":"Content-Security-Policy header isn't registered","author":"mnot","createdAt":"2021-09-29T08:52:51Z","labels":[],"sloTimeUsed":"P1689DT22H54M31S","whichSlo":"triage","stats":{"numTimelineItems":0,"numComments":0,"numLabels":0},"outOfSlo":true},{"number":521,"url":"https://github.com/w3c/webappsec-csp/issues/521","title":"Editorial: header names and values are byte sequences","author":"annevk","createdAt":"2021-10-25T10:59:01Z","labels":["editorial"],"sloTimeUsed":"P1663DT20H48M21S","whichSlo":"triage","stats":{"numTimelineItems":1,"numComments":0,"numLabels":1},"outOfSlo":true},{"number":524,"url":"https://github.com/w3c/webappsec-csp/issues/524","title":"should-block-response doesn't forward arguments","author":"annevk","createdAt":"2021-11-09T13:14:43Z","labels":["editorial"],"sloTimeUsed":"P1648DT18H32M39S","whichSlo":"triage","stats":{"numTimelineItems":1,"numComments":0,"numLabels":1},"outOfSlo":true},{"number":556,"url":"https://github.com/w3c/webappsec-csp/issues/556","title":"Correct the link for CSP3 in the CSP2 Page ","author":"Abdulali97","createdAt":"2022-07-08T18:33:30Z","labels":[],"sloTimeUsed":"P1407DT13H13M52S","whichSlo":"triage","stats":{"numTimelineItems":0,"numComments":0,"numLabels":0},"outOfSlo":true},{"number":581,"url":"https://github.com/w3c/webappsec-csp/issues/581","title":"Remove initialization hook","author":"antosart","createdAt":"2022-12-01T09:58:51Z","labels":[],"sloTimeUsed":"P1261DT21H48M31S","whichSlo":"triage","stats":{"numTimelineItems":0,"numComments":0,"numLabels":0},"outOfSlo":true},{"number":610,"url":"https://github.com/w3c/webappsec-csp/issues/610","title":"CSP: Embedded Enforcement Links for issue 16 and 17 are dead","author":"JannisBush","createdAt":"2023-07-07T13:02:29Z","labels":[],"sloTimeUsed":"P1043DT18H44M53S","whichSlo":"triage","stats":{"numTimelineItems":0,"numComments":0,"numLabels":0},"outOfSlo":true},{"number":624,"url":"https://github.com/w3c/webappsec-csp/issues/624","title":"frame-src using the fetch instead of the navigational check - can end up checking the wrong policies","author":"antosart","createdAt":"2023-11-07T14:07:52Z","labels":[],"sloTimeUsed":"P920DT17H39M30S","whichSlo":"triage","stats":{"numTimelineItems":0,"numComments":0,"numLabels":0},"outOfSlo":true},{"number":632,"url":"https://github.com/w3c/webappsec-csp/issues/632","title":"Some way to allow workers other than URL and strict-dynamic","author":"bakkot","createdAt":"2023-12-19T02:50:28Z","labels":[],"sloTimeUsed":"P879DT4H56M54S","whichSlo":"triage","stats":{"numTimelineItems":0,"numComments":0,"numLabels":0},"outOfSlo":true},{"number":635,"url":"https://github.com/w3c/webappsec-csp/issues/635","title":"Does \"Is Element Nonceable\" apply to non-inline scripts?","author":"evilpie","createdAt":"2024-01-12T10:50:41Z","labels":[],"sloTimeUsed":"P854DT20H56M41S","whichSlo":"triage","stats":{"numTimelineItems":0,"numComments":1,"numLabels":0},"outOfSlo":true},{"number":638,"url":"https://github.com/w3c/webappsec-csp/issues/638","title":"`service-worker-src` directive","author":"bakkot","createdAt":"2024-01-17T03:41:53Z","labels":["needs concrete proposal"],"sloTimeUsed":"P850DT4H5M29S","whichSlo":"triage","stats":{"numTimelineItems":1,"numComments":0,"numLabels":1},"outOfSlo":true},{"number":643,"url":"https://github.com/w3c/webappsec-csp/issues/643","title":"\"Is element nonceable\" not applied to non-<script> elements in Chrome?","author":"evilpie","createdAt":"2024-02-12T09:40:37Z","labels":["needs tests"],"sloTimeUsed":"P823DT22H6M45S","whichSlo":"triage","stats":{"numTimelineItems":1,"numComments":0,"numLabels":1},"outOfSlo":true},{"number":674,"url":"https://github.com/w3c/webappsec-csp/issues/674","title":"Consider using SecurityPolicyViolationEvent.sourceFile a USVString","author":"emilio","createdAt":"2024-07-31T15:05:30Z","labels":["needs concrete proposal"],"sloTimeUsed":"P653DT16H41M52S","whichSlo":"triage","stats":{"numTimelineItems":1,"numComments":1,"numLabels":1},"outOfSlo":true},{"number":679,"url":"https://github.com/w3c/webappsec-csp/issues/679","title":"Feedback request on not capturing the caller in `new Function` and indirect `eval`","author":"nicolo-ribaudo","createdAt":"2024-09-04T09:45:17Z","labels":["needs concrete proposal","addition/proposal"],"sloTimeUsed":"P618DT22H2M5S","whichSlo":"triage","stats":{"numTimelineItems":2,"numComments":0,"numLabels":2},"outOfSlo":true},{"number":680,"url":"https://github.com/w3c/webappsec-csp/issues/680","title":"port-part being null is not handled","author":"evilpie","createdAt":"2024-09-13T12:41:16Z","labels":["editorial"],"sloTimeUsed":"P609DT19H6M6S","whichSlo":"triage","stats":{"numTimelineItems":1,"numComments":0,"numLabels":1},"outOfSlo":true},{"number":696,"url":"https://github.com/w3c/webappsec-csp/issues/696","title":"https://w3c.github.io/webappsec-csp/#report-violation invokes \"Queue a task\" without passing a task source","createdAt":"2024-12-02T14:44:16Z","labels":[],"sloTimeUsed":"P529DT17H3M6S","whichSlo":"triage","stats":{"numTimelineItems":0,"numComments":0,"numLabels":0},"outOfSlo":true},{"number":697,"url":"https://github.com/w3c/webappsec-csp/issues/697","title":"EnsureCSPDoesNotBlockStringCompilation: Explain why we need to check TrustedScript's data (and add tests)","author":"fred-wang","createdAt":"2024-12-04T10:37:54Z","labels":[],"sloTimeUsed":"P527DT21H9M28S","whichSlo":"triage","stats":{"numTimelineItems":0,"numComments":0,"numLabels":0},"outOfSlo":true},{"number":698,"url":"https://github.com/w3c/webappsec-csp/issues/698","title":"EnsureCSPDoesNotBlockStringCompilation: calling \"Get Trusted Type compliant string\"","author":"fred-wang","createdAt":"2024-12-04T10:53:59Z","labels":["editorial"],"sloTimeUsed":"P527DT20H53M23S","whichSlo":"triage","stats":{"numTimelineItems":1,"numComments":0,"numLabels":1},"outOfSlo":true},{"number":708,"url":"https://github.com/w3c/webappsec-csp/issues/708","title":"Strict-Dynamic CSP doesn't prevent execution of parser inserted scripts via document.createRange().createContextualFragment","author":"andreituicu","createdAt":"2025-02-26T13:05:18Z","labels":[],"sloTimeUsed":"P443DT18H42M4S","whichSlo":"triage","stats":{"numTimelineItems":0,"numComments":0,"numLabels":0},"outOfSlo":true},{"number":781,"url":"https://github.com/w3c/webappsec-csp/issues/781","title":"`report-multiple-violations-{01,02}` don't conform with the spec","author":"TimvdLippe","createdAt":"2025-07-11T15:58:10Z","labels":[],"sloTimeUsed":"P308DT15H49M12S","whichSlo":"triage","stats":{"numTimelineItems":0,"numComments":0,"numLabels":0},"outOfSlo":true},{"number":782,"url":"https://github.com/w3c/webappsec-csp/issues/782","title":"Incorrect assertion in form-action Pre-Navigation Check","author":"Lubrsi","createdAt":"2025-07-28T15:10:12Z","labels":[],"sloTimeUsed":"P291DT16H37M10S","whichSlo":"triage","stats":{"numTimelineItems":0,"numComments":0,"numLabels":0},"outOfSlo":true},{"number":788,"url":"https://github.com/w3c/webappsec-csp/issues/788","title":"Incorrect assertion in Obtain the deprecated serialization of violation","author":"Lubrsi","createdAt":"2025-10-30T13:39:44Z","labels":[],"sloTimeUsed":"P197DT18H7M38S","whichSlo":"triage","stats":{"numTimelineItems":0,"numComments":0,"numLabels":0},"outOfSlo":true},{"number":789,"url":"https://github.com/w3c/webappsec-csp/issues/789","title":"Broken links in Content Security Policy Level 3","author":"dontcallmedom-bot","createdAt":"2025-11-03T09:47:05Z","labels":[],"sloTimeUsed":"P193DT22H17S","whichSlo":"triage","stats":{"numTimelineItems":0,"numComments":0,"numLabels":0},"outOfSlo":true},{"number":797,"url":"https://github.com/w3c/webappsec-csp/issues/797","title":"Providing a directive for XSLT","author":"Tachi107","createdAt":"2026-01-21T16:39:09Z","labels":[],"sloTimeUsed":"P114DT15H8M13S","whichSlo":"triage","stats":{"numTimelineItems":0,"numComments":0,"numLabels":0},"outOfSlo":true},{"number":798,"url":"https://github.com/w3c/webappsec-csp/issues/798","title":"Integration point for WebDriver BiDi CSP bypass","author":"juliandescottes","createdAt":"2026-02-05T11:39:47Z","labels":["addition/proposal"],"sloTimeUsed":"P99DT20H7M35S","whichSlo":"triage","stats":{"numTimelineItems":1,"numComments":0,"numLabels":1},"outOfSlo":true},{"number":801,"url":"https://github.com/w3c/webappsec-csp/issues/801","title":"Proposal: CSP control over interactive HTTP authentication for subresources","author":"nirmalk401","createdAt":"2026-02-16T13:35:55Z","labels":[],"sloTimeUsed":"P88DT18H11M27S","whichSlo":"triage","stats":{"numTimelineItems":0,"numComments":0,"numLabels":0},"outOfSlo":true},{"number":811,"url":"https://github.com/w3c/webappsec-csp/issues/811","title":"Embedded enforcement links are broken","author":"domfarolino","createdAt":"2026-04-09T18:59:37Z","labels":[],"sloTimeUsed":"P36DT12H47M45S","whichSlo":"triage","stats":{"numTimelineItems":0,"numComments":0,"numLabels":0},"outOfSlo":true},{"number":815,"url":"https://github.com/w3c/webappsec-csp/issues/815","title":"Clarification RFC 7234 caches for present nonce-sources","author":"codingjoe","createdAt":"2026-05-07T12:06:09Z","labels":[],"sloTimeUsed":"P8DT19H41M13S","whichSlo":"triage","stats":{"numTimelineItems":0,"numComments":1,"numLabels":0},"outOfSlo":true}],"urgent":[],"soon":[],"agenda":[{"number":363,"url":"https://github.com/w3c/webappsec-csp/pull/363","title":"Specify behavior in case of malformed policies","author":"andypaicu","createdAt":"2018-11-09T14:43:18Z","pull_request":{"draft":false},"labels":["agenda+","clarification","interop"],"sloTimeUsed":"PT0S","whichSlo":"none","onAgendaFor":"P492DT14H16M21S","stats":{"numTimelineItems":47,"numComments":47,"numLabels":3},"outOfSlo":true},{"number":625,"url":"https://github.com/w3c/webappsec-csp/issues/625","title":"Allow 'strict-dynamic' scripts to inject styles","author":"vejja","createdAt":"2023-11-10T09:39:12Z","labels":["agenda+","addition/proposal"],"sloTimeUsed":"PT0S","whichSlo":"none","onAgendaFor":"P457DT14H7M46S","stats":{"numTimelineItems":2,"numComments":7,"numLabels":2},"outOfSlo":true},{"number":677,"url":"https://github.com/w3c/webappsec-csp/issues/677","title":"Should font-src reporting kick in on font-face reference or font request?","author":"robinwhittleton","createdAt":"2024-08-22T09:31:21Z","labels":["agenda+"],"sloTimeUsed":"PT0S","whichSlo":"none","onAgendaFor":"P429DT17H46M16S","stats":{"numTimelineItems":1,"numComments":8,"numLabels":1},"outOfSlo":true},{"number":664,"url":"https://github.com/w3c/webappsec-csp/issues/664","title":"Add new CSP sandbox directive to allow SameSite=None cookies on top-level frames","author":"DCtheTall","createdAt":"2024-05-24T13:09:05Z","labels":["agenda+"],"sloTimeUsed":"PT0S","whichSlo":"none","onAgendaFor":"P429DT17H42M49S","stats":{"numTimelineItems":1,"numComments":7,"numLabels":1},"outOfSlo":true}],"needsEdits":[],"other":[{"number":6,"url":"https://github.com/w3c/webappsec-csp/issues/6","title":"[CSP] specify handling of malformed content-security-policy HTTP header","author":"mikewest","createdAt":"2015-10-07T06:49:42Z","labels":["clarification","interop"],"milestone":{"url":"https://github.com/w3c/webappsec-csp/milestone/1","title":"CSP3 CR"},"sloTimeUsed":"PT0S","whichSlo":"none","stats":{"numTimelineItems":2,"numLabels":2}},{"number":8,"url":"https://github.com/w3c/webappsec-csp/issues/8","title":"CSP: form-action and redirects","author":"mikewest","createdAt":"2015-10-07T06:50:10Z","labels":["CSP"],"milestone":{"url":"https://github.com/w3c/webappsec-csp/milestone/2","title":"Future"},"sloTimeUsed":"PT0S","whichSlo":"none","stats":{"numTimelineItems":1,"numLabels":1}},{"number":17,"url":"https://github.com/w3c/webappsec-csp/issues/17","title":"CSP: Consider allowing `frame-ancestors` to work for subresource loads.","author":"mikewest","createdAt":"2015-10-07T06:51:51Z","labels":["CSP"],"milestone":{"url":"https://github.com/w3c/webappsec-csp/milestone/2","title":"Future"},"sloTimeUsed":"PT0S","whichSlo":"none","stats":{"numTimelineItems":1,"numLabels":1}},{"number":20,"url":"https://github.com/w3c/webappsec-csp/issues/20","title":"CSP: form-nonce directive","author":"mikewest","createdAt":"2015-10-07T06:52:21Z","labels":["CSP"],"milestone":{"url":"https://github.com/w3c/webappsec-csp/milestone/2","title":"Future"},"sloTimeUsed":"PT0S","whichSlo":"none","stats":{"numTimelineItems":1,"numLabels":1}},{"number":26,"url":"https://github.com/w3c/webappsec-csp/issues/26","title":"block-all-mixed-content for report-only","author":"ejcx","createdAt":"2015-10-28T15:16:25Z","labels":["addition/proposal"],"milestone":{"url":"https://github.com/w3c/webappsec-csp/milestone/2","title":"Future"},"sloTimeUsed":"PT0S","whichSlo":"none","stats":{"numTimelineItems":1,"numLabels":1}},{"number":28,"url":"https://github.com/w3c/webappsec-csp/issues/28","title":"Identify requirements for other documents defining new directives","author":"hillbrad","createdAt":"2015-10-29T07:27:28Z","labels":["CSP","CORE"],"sloTimeUsed":"PT0S","whichSlo":"none","stats":{"numTimelineItems":4,"numComments":1,"numLabels":2}},{"number":29,"url":"https://github.com/w3c/webappsec-csp/issues/29","title":"CSP 401 Issue","author":"kepengli","createdAt":"2015-10-29T07:59:47Z","labels":["CORE"],"milestone":{"url":"https://github.com/w3c/webappsec-csp/milestone/2","title":"Future"},"sloTimeUsed":"PT0S","whichSlo":"none","stats":{"numTimelineItems":3,"numLabels":1}},{"number":45,"url":"https://github.com/w3c/webappsec-csp/issues/45","title":"Further granularity of unsafe-inline styles","author":"jonathanKingston","createdAt":"2015-12-03T03:06:22Z","labels":["CORE"],"milestone":{"url":"https://github.com/w3c/webappsec-csp/milestone/2","title":"Future"},"sloTimeUsed":"PT0S","whichSlo":"none","stats":{"numTimelineItems":1,"numLabels":1}},{"number":67,"url":"https://github.com/w3c/webappsec-csp/issues/67","title":"Block `setAttribute('onload', 'code code code')` on `'unsafe-eval'`","author":"mikewest","createdAt":"2016-04-07T11:36:28Z","labels":["addition/proposal"],"milestone":{"url":"https://github.com/w3c/webappsec-csp/milestone/2","title":"Future"},"sloTimeUsed":"PT0S","whichSlo":"none","stats":{"numTimelineItems":1,"numLabels":1}},{"number":87,"url":"https://github.com/w3c/webappsec-csp/issues/87","title":"Allow dynamically enabling/disabling unsafe-eval","author":"devd","createdAt":"2016-05-17T17:30:23Z","labels":["addition/proposal"],"milestone":{"url":"https://github.com/w3c/webappsec-csp/milestone/2","title":"Future"},"sloTimeUsed":"PT0S","whichSlo":"none","stats":{"numTimelineItems":1,"numLabels":1}},{"number":88,"url":"https://github.com/w3c/webappsec-csp/issues/88","title":"Allow dynamically enabling/disabling nonce as a source","author":"devd","createdAt":"2016-05-17T17:52:56Z","labels":[],"milestone":{"url":"https://github.com/w3c/webappsec-csp/milestone/2","title":"Future"},"sloTimeUsed":"PT0S","whichSlo":"none","stats":{"numTimelineItems":0,"numLabels":0}},{"number":91,"url":"https://github.com/w3c/webappsec-csp/issues/91","title":"Consider providing a way to tighten source-expressions that contain `self`","author":"shekyan","createdAt":"2016-06-17T20:06:41Z","labels":["needs concrete proposal"],"milestone":{"url":"https://github.com/w3c/webappsec-csp/milestone/2","title":"Future"},"sloTimeUsed":"PT0S","whichSlo":"none","stats":{"numTimelineItems":1,"numLabels":1}},{"number":96,"url":"https://github.com/w3c/webappsec-csp/issues/96","title":"Instruct user agents to report invalid policies","author":"neilstuartcraig","createdAt":"2016-06-29T09:58:58Z","labels":[],"milestone":{"url":"https://github.com/w3c/webappsec-csp/milestone/2","title":"Future"},"sloTimeUsed":"PT0S","whichSlo":"none","stats":{"numTimelineItems":0,"numLabels":0}},{"number":111,"url":"https://github.com/w3c/webappsec-csp/issues/111","title":"Add a flag to strip potentially sensitive data from reports","author":"ScottHelme","createdAt":"2016-08-26T11:48:15Z","labels":[],"milestone":{"url":"https://github.com/w3c/webappsec-csp/milestone/2","title":"Future"},"sloTimeUsed":"PT0S","whichSlo":"none","stats":{"numTimelineItems":0,"numLabels":0}},{"number":112,"url":"https://github.com/w3c/webappsec-csp/issues/112","title":"Add a new directive governing the use of http-equiv in <meta> tags","author":"aidantwoods","createdAt":"2016-08-29T14:15:40Z","labels":[],"milestone":{"url":"https://github.com/w3c/webappsec-csp/milestone/2","title":"Future"},"sloTimeUsed":"PT0S","whichSlo":"none","stats":{"numTimelineItems":0,"numLabels":0}},{"number":116,"url":"https://github.com/w3c/webappsec-csp/issues/116","title":"Allow nonce-source to be used in more directives.","author":"ScottHelme","createdAt":"2016-09-11T13:36:32Z","labels":[],"milestone":{"url":"https://github.com/w3c/webappsec-csp/milestone/2","title":"Future"},"sloTimeUsed":"PT0S","whichSlo":"none","stats":{"numTimelineItems":0,"numLabels":0}},{"number":117,"url":"https://github.com/w3c/webappsec-csp/issues/117","title":"do we want a directive to control postMessage explicit channels outbound?","author":"hillbrad","createdAt":"2016-09-22T13:02:04Z","labels":[],"milestone":{"url":"https://github.com/w3c/webappsec-csp/milestone/2","title":"Future"},"sloTimeUsed":"PT0S","whichSlo":"none","stats":{"numTimelineItems":0,"numLabels":0}},{"number":121,"url":"https://github.com/w3c/webappsec-csp/issues/121","title":"Nonces for Embedding-CSP","author":"dhausknecht","createdAt":"2016-09-30T07:25:50Z","labels":["EMBEDDED"],"milestone":{"url":"https://github.com/w3c/webappsec-csp/milestone/1","title":"CSP3 CR"},"sloTimeUsed":"PT0S","whichSlo":"none","stats":{"numTimelineItems":1,"numLabels":1}},{"number":129,"url":"https://github.com/w3c/webappsec-csp/issues/129","title":"Multiple headers of Allow-CSP-From","author":"aubakirova","createdAt":"2016-10-14T08:20:20Z","labels":["EMBEDDED"],"milestone":{"url":"https://github.com/w3c/webappsec-csp/milestone/1","title":"CSP3 CR"},"sloTimeUsed":"PT0S","whichSlo":"none","stats":{"numTimelineItems":1,"numLabels":1}},{"number":174,"url":"https://github.com/w3c/webappsec-csp/issues/174","title":"Policy to allow only custom properties in inline CSS","author":"J0WI","createdAt":"2017-01-14T13:58:38Z","labels":[],"milestone":{"url":"https://github.com/w3c/webappsec-csp/milestone/2","title":"Future"},"sloTimeUsed":"PT0S","whichSlo":"none","stats":{"numTimelineItems":0,"numLabels":0}},{"number":191,"url":"https://github.com/w3c/webappsec-csp/issues/191","title":"Add keyword to prevent parser-based JS APIs from adding new scripts ","author":"arturjanc","createdAt":"2017-03-09T23:44:40Z","labels":["needs concrete proposal","addition/proposal"],"milestone":{"url":"https://github.com/w3c/webappsec-csp/milestone/2","title":"Future"},"sloTimeUsed":"PT0S","whichSlo":"none","stats":{"numTimelineItems":2,"numLabels":2}},{"number":197,"url":"https://github.com/w3c/webappsec-csp/issues/197","title":"Include `script-sample' for \"eval\" violations","author":"arturjanc","createdAt":"2017-03-19T09:41:46Z","labels":["needs concrete proposal"],"milestone":{"url":"https://github.com/w3c/webappsec-csp/milestone/2","title":"Future"},"sloTimeUsed":"PT0S","whichSlo":"none","stats":{"numTimelineItems":1,"numLabels":1}},{"number":198,"url":"https://github.com/w3c/webappsec-csp/issues/198","title":"CSP3: Consider adding a 'resource-src' directive","author":"jwatt","createdAt":"2017-03-19T22:22:26Z","labels":["needs concrete proposal"],"milestone":{"url":"https://github.com/w3c/webappsec-csp/milestone/2","title":"Future"},"sloTimeUsed":"PT0S","whichSlo":"none","stats":{"numTimelineItems":1,"numLabels":1}},{"number":199,"url":"https://github.com/w3c/webappsec-csp/issues/199","title":"CSP3: Consider adding a 'clone-src' directive","author":"jwatt","createdAt":"2017-03-19T22:29:51Z","labels":["needs concrete proposal","addition/proposal"],"milestone":{"url":"https://github.com/w3c/webappsec-csp/milestone/2","title":"Future"},"sloTimeUsed":"PT0S","whichSlo":"none","stats":{"numTimelineItems":2,"numLabels":2}},{"number":201,"url":"https://github.com/w3c/webappsec-csp/issues/201","title":"clarify whether csp blocks reflection of non-string arguments to eval","author":"jeisinger","createdAt":"2017-04-07T07:15:41Z","labels":[],"sloTimeUsed":"PT0S","whichSlo":"none","stats":{"numTimelineItems":0,"numComments":3,"numLabels":0}},{"number":212,"url":"https://github.com/w3c/webappsec-csp/issues/212","title":"Inline style bits are very unclear","author":"bzbarsky","createdAt":"2017-04-28T15:59:48Z","labels":[],"milestone":{"url":"https://github.com/w3c/webappsec-csp/milestone/1","title":"CSP3 CR"},"sloTimeUsed":"PT0S","whichSlo":"none","stats":{"numTimelineItems":0,"numLabels":0}},{"number":229,"url":"https://github.com/w3c/webappsec-csp/issues/229","title":"allow calls to new Function(); - but not to the actual constructed function. under csp unsafe-eval.","author":"graingert","createdAt":"2017-08-14T11:15:03Z","labels":["needs concrete proposal"],"milestone":{"url":"https://github.com/w3c/webappsec-csp/milestone/2","title":"Future"},"sloTimeUsed":"PT0S","whichSlo":"none","stats":{"numTimelineItems":1,"numLabels":1}},{"number":233,"url":"https://github.com/w3c/webappsec-csp/issues/233","title":"CSP3: Can be possible adding a `max-age` or `expiration` to remember the CSP?","author":"inkeliz","createdAt":"2017-08-28T04:04:24Z","labels":["needs concrete proposal","addition/proposal"],"milestone":{"url":"https://github.com/w3c/webappsec-csp/milestone/2","title":"Future"},"sloTimeUsed":"PT0S","whichSlo":"none","stats":{"numTimelineItems":2,"numLabels":2}},{"number":242,"url":"https://github.com/w3c/webappsec-csp/issues/242","title":"Should securitypolicyviolation have element set in more cases","author":"annevk","createdAt":"2017-09-26T10:12:47Z","labels":["needs concrete proposal"],"milestone":{"url":"https://github.com/w3c/webappsec-csp/milestone/2","title":"Future"},"sloTimeUsed":"PT0S","whichSlo":"none","stats":{"numTimelineItems":1,"numLabels":1}},{"number":243,"url":"https://github.com/w3c/webappsec-csp/issues/243","title":"Any protection against dynamic module import?","author":"shhnjk","createdAt":"2017-09-27T22:57:39Z","labels":["needs concrete proposal"],"milestone":{"url":"https://github.com/w3c/webappsec-csp/milestone/2","title":"Future"},"sloTimeUsed":"PT0S","whichSlo":"none","stats":{"numTimelineItems":1,"numLabels":1}},{"number":253,"url":"https://github.com/w3c/webappsec-csp/issues/253","title":"Obsolete https://w3c.github.io/webappsec-csp/api/?","author":"foolip","createdAt":"2017-10-15T20:29:33Z","labels":[],"sloTimeUsed":"PT0S","whichSlo":"none","stats":{"numTimelineItems":0,"numComments":5,"numLabels":0}},{"number":255,"url":"https://github.com/w3c/webappsec-csp/issues/255","title":"Prevent CSP reports being sent if I handle the SecurityPolicyViolation event.","author":"ScottHelme","createdAt":"2017-10-20T13:45:35Z","labels":["addition/proposal"],"milestone":{"url":"https://github.com/w3c/webappsec-csp/milestone/2","title":"Future"},"sloTimeUsed":"PT0S","whichSlo":"none","stats":{"numTimelineItems":1,"numLabels":1}},{"number":256,"url":"https://github.com/w3c/webappsec-csp/issues/256","title":"Add way to define all country code top-level domain.","author":"AndrewStoyan","createdAt":"2017-10-20T15:36:40Z","labels":[],"milestone":{"url":"https://github.com/w3c/webappsec-csp/milestone/2","title":"Future"},"sloTimeUsed":"PT0S","whichSlo":"none","stats":{"numTimelineItems":0,"numLabels":0}},{"number":261,"url":"https://github.com/w3c/webappsec-csp/issues/261","title":"Relax CSP source path matching when response is replaced by service worker e.g. redirects","author":"aliams","createdAt":"2017-11-01T21:47:07Z","labels":[],"sloTimeUsed":"PT0S","whichSlo":"none","stats":{"numTimelineItems":2,"numComments":4,"numLabels":0}},{"number":262,"url":"https://github.com/w3c/webappsec-csp/issues/262","title":"Please clearly mark older versions as obsolete","author":"annevk","createdAt":"2017-11-02T09:01:14Z","labels":[],"sloTimeUsed":"PT0S","whichSlo":"none","stats":{"numTimelineItems":0,"numComments":2,"numLabels":0}},{"number":269,"url":"https://github.com/w3c/webappsec-csp/issues/269","title":"Enable call stack for blocked_uri in Content Security Policy Reporting","author":"vibhasethi","createdAt":"2017-11-17T22:35:14Z","labels":[],"milestone":{"url":"https://github.com/w3c/webappsec-csp/milestone/2","title":"Future"},"sloTimeUsed":"PT0S","whichSlo":"none","stats":{"numTimelineItems":0,"numLabels":0}},{"number":274,"url":"https://github.com/w3c/webappsec-csp/issues/274","title":"CSP Directives Should Be Structured","author":"David263","createdAt":"2017-12-01T22:34:27Z","labels":[],"milestone":{"url":"https://github.com/w3c/webappsec-csp/milestone/2","title":"Future"},"sloTimeUsed":"PT0S","whichSlo":"none","stats":{"numTimelineItems":0,"numLabels":0}},{"number":277,"url":"https://github.com/w3c/webappsec-csp/issues/277","title":"Allow CSP-Report-Only in meta tags.","author":"ScottHelme","createdAt":"2017-12-31T18:07:30Z","labels":[],"milestone":{"url":"https://github.com/w3c/webappsec-csp/milestone/2","title":"Future"},"sloTimeUsed":"PT0S","whichSlo":"none","stats":{"numTimelineItems":0,"numLabels":0}},{"number":279,"url":"https://github.com/w3c/webappsec-csp/issues/279","title":"Sandbox directive for workers","author":"aliams","createdAt":"2018-01-05T00:52:30Z","labels":[],"sloTimeUsed":"PT0S","whichSlo":"none","stats":{"numTimelineItems":0,"numComments":8,"numLabels":0}},{"number":282,"url":"https://github.com/w3c/webappsec-csp/issues/282","title":"Allow control over `dns-prefetch` and `preconnect`","author":"annevk","createdAt":"2018-01-11T11:20:49Z","labels":["needs concrete proposal","addition/proposal"],"milestone":{"url":"https://github.com/w3c/webappsec-csp/milestone/2","title":"Future"},"sloTimeUsed":"PT0S","whichSlo":"none","stats":{"numTimelineItems":2,"numLabels":2}},{"number":284,"url":"https://github.com/w3c/webappsec-csp/issues/284","title":"`prerender` subresources and CSP","author":"yoavweiss","createdAt":"2018-01-11T13:06:22Z","labels":["needs concrete proposal"],"sloTimeUsed":"PT0S","whichSlo":"none","stats":{"numTimelineItems":1,"numComments":12,"numLabels":1}},{"number":291,"url":"https://github.com/w3c/webappsec-csp/issues/291","title":"Consider hiding content attribute of meta tag CSP","author":"vrastogi","createdAt":"2018-01-31T17:46:53Z","labels":["editorial"],"sloTimeUsed":"PT0S","whichSlo":"none","stats":{"numTimelineItems":5,"numComments":6,"numLabels":1}},{"number":298,"url":"https://github.com/w3c/webappsec-csp/issues/298","title":"Add directive similar to `X-Content-Type-Options: nosniff`?","author":"valtlai","createdAt":"2018-02-28T18:53:24Z","labels":[],"sloTimeUsed":"PT0S","whichSlo":"none","stats":{"numTimelineItems":0,"numComments":2,"numLabels":0}},{"number":299,"url":"https://github.com/w3c/webappsec-csp/issues/299","title":"frame-src, worker-src, child-src confusion","author":"AliceWonderMiscreations","createdAt":"2018-03-28T20:52:15Z","labels":[],"sloTimeUsed":"PT0S","whichSlo":"none","stats":{"numTimelineItems":0,"numComments":8,"numLabels":0}},{"number":301,"url":"https://github.com/w3c/webappsec-csp/issues/301","title":"CSP 4 feature request: cookie policy","author":"AliceWonderMiscreations","createdAt":"2018-04-07T12:08:56Z","labels":[],"milestone":{"url":"https://github.com/w3c/webappsec-csp/milestone/2","title":"Future"},"sloTimeUsed":"PT0S","whichSlo":"none","stats":{"numTimelineItems":0,"numLabels":0}},{"number":304,"url":"https://github.com/w3c/webappsec-csp/issues/304","title":"Consider dot-prefix domains for wildcard matching","author":"007","createdAt":"2018-04-24T00:00:37Z","labels":[],"sloTimeUsed":"PT0S","whichSlo":"none","stats":{"numTimelineItems":0,"numComments":1,"numLabels":0}},{"number":308,"url":"https://github.com/w3c/webappsec-csp/issues/308","title":"BackSwap type of attack","author":"AliceWonderMiscreations","createdAt":"2018-05-26T17:52:25Z","labels":[],"sloTimeUsed":"PT0S","whichSlo":"none","stats":{"numTimelineItems":0,"numComments":3,"numLabels":0}},{"number":309,"url":"https://github.com/w3c/webappsec-csp/issues/309","title":"'strict-dynamic' should not be bound to only nonces/hashes","author":"april","createdAt":"2018-06-04T21:44:46Z","labels":[],"sloTimeUsed":"PT0S","whichSlo":"none","stats":{"numTimelineItems":0,"numComments":1,"numLabels":0}},{"number":320,"url":"https://github.com/w3c/webappsec-csp/issues/320","title":"CSP violation report should not use redirect-mode: \"error\"","author":"yutakahirano","createdAt":"2018-07-13T03:44:52Z","labels":[],"sloTimeUsed":"PT0S","whichSlo":"none","stats":{"numTimelineItems":0,"numComments":7,"numLabels":0}},{"number":321,"url":"https://github.com/w3c/webappsec-csp/issues/321","title":"CSP 4 Feature Request: add new 'default' keyword to compose default-src sources into other directives","author":"Jach","createdAt":"2018-07-17T00:18:17Z","labels":[],"sloTimeUsed":"PT0S","whichSlo":"none","stats":{"numTimelineItems":0,"numComments":1,"numLabels":0}},{"number":323,"url":"https://github.com/w3c/webappsec-csp/issues/323","title":"Feature Request: Support for cross-domain downloads","author":"aarongustafson","createdAt":"2018-08-06T21:07:47Z","labels":[],"sloTimeUsed":"PT0S","whichSlo":"none","stats":{"numTimelineItems":2,"numComments":11,"numLabels":0}},{"number":326,"url":"https://github.com/w3c/webappsec-csp/issues/326","title":"Security issue: fragments (after the '#') must not be reported.","author":"alunmj","createdAt":"2018-09-07T16:27:22Z","labels":[],"sloTimeUsed":"PT0S","whichSlo":"none","stats":{"numTimelineItems":0,"numComments":3,"numLabels":0}},{"number":332,"url":"https://github.com/w3c/webappsec-csp/issues/332","title":"Remove mentions of the ws\\wss schemes in CSP","author":"andypaicu","createdAt":"2018-09-17T12:22:38Z","labels":[],"sloTimeUsed":"PT0S","whichSlo":"none","stats":{"numTimelineItems":0,"numComments":5,"numLabels":0}},{"number":348,"url":"https://github.com/w3c/webappsec-csp/issues/348","title":"Allow report-to in CSP and CSPRO meta tags","author":"ScottHelme","createdAt":"2018-10-10T20:12:54Z","labels":[],"sloTimeUsed":"PT0S","whichSlo":"none","stats":{"numTimelineItems":0,"numComments":3,"numLabels":0}},{"number":375,"url":"https://github.com/w3c/webappsec-csp/issues/375","title":"Choose a consistent model for workers under nonce-based policies","author":"arturjanc","createdAt":"2018-12-04T13:27:22Z","labels":["needs concrete proposal","addition/proposal"],"sloTimeUsed":"PT0S","whichSlo":"none","stats":{"numTimelineItems":8,"numComments":10,"numLabels":2}},{"number":376,"url":"https://github.com/w3c/webappsec-csp/issues/376","title":"parser_inserted flag used in 'strict-dynamic' check is not sufficient","author":"andypaicu","createdAt":"2018-12-12T15:49:01Z","labels":["needs-info"],"milestone":{"url":"https://github.com/w3c/webappsec-csp/milestone/1","title":"CSP3 CR"},"sloTimeUsed":"PT0S","whichSlo":"none","stats":{"numTimelineItems":1,"numLabels":1}},{"number":378,"url":"https://github.com/w3c/webappsec-csp/issues/378","title":"Include script hash in CSP report when 'report-sample' is set","author":"april","createdAt":"2018-12-13T21:24:56Z","labels":["addition/proposal"],"sloTimeUsed":"PT0S","whichSlo":"none","stats":{"numTimelineItems":1,"numComments":5,"numLabels":1}},{"number":389,"url":"https://github.com/w3c/webappsec-csp/issues/389","title":"Initializing a document's CSP list requires synchronous cross-process access","author":"bzbarsky","createdAt":"2019-04-23T14:14:58Z","labels":["needs-info"],"sloTimeUsed":"PT0S","whichSlo":"none","stats":{"numTimelineItems":1,"numComments":5,"numLabels":1}},{"number":390,"url":"https://github.com/w3c/webappsec-csp/issues/390","title":"Clarify behavior for cached favicon loads","author":"briansmith","createdAt":"2019-05-03T20:54:00Z","labels":["addition/proposal"],"sloTimeUsed":"PT0S","whichSlo":"none","stats":{"numTimelineItems":1,"numComments":2,"numLabels":1}},{"number":392,"url":"https://github.com/w3c/webappsec-csp/issues/392","title":"Enforce \"at most once\" semantics for scripts","author":"briansmith","createdAt":"2019-05-06T03:07:01Z","labels":["addition/proposal"],"sloTimeUsed":"PT0S","whichSlo":"none","stats":{"numTimelineItems":1,"numComments":8,"numLabels":1}},{"number":398,"url":"https://github.com/w3c/webappsec-csp/issues/398","title":"Does child-src defer to script-src?","author":"bakkot","createdAt":"2019-05-31T00:12:58Z","labels":["editorial"],"sloTimeUsed":"PT0S","whichSlo":"none","stats":{"numTimelineItems":1,"numComments":2,"numLabels":1}},{"number":399,"url":"https://github.com/w3c/webappsec-csp/issues/399","title":"Support 'strict-dynamic' in style-src","author":"arturjanc","createdAt":"2019-06-05T14:57:49Z","labels":[],"sloTimeUsed":"PT0S","whichSlo":"none","stats":{"numTimelineItems":0,"numComments":3,"numLabels":0}},{"number":400,"url":"https://github.com/w3c/webappsec-csp/issues/400","title":"frame-src spec does not match implementations in terms of which CSP is used","author":"bzbarsky","createdAt":"2019-06-06T17:04:02Z","labels":[],"sloTimeUsed":"PT0S","whichSlo":"none","stats":{"numTimelineItems":0,"numComments":8,"numLabels":0}},{"number":405,"url":"https://github.com/w3c/webappsec-csp/issues/405","title":"Resolving 'self' within srcdoc iframe","author":"ckerschb","createdAt":"2019-07-29T11:17:08Z","labels":[],"sloTimeUsed":"PT0S","whichSlo":"none","stats":{"numTimelineItems":0,"numComments":4,"numLabels":0}},{"number":411,"url":"https://github.com/w3c/webappsec-csp/issues/411","title":"Parsing multiple sources when one of them is 'none'?","author":"mozfreddyb","createdAt":"2019-09-26T15:34:38Z","labels":[],"sloTimeUsed":"PT0S","whichSlo":"none","stats":{"numTimelineItems":0,"numComments":1,"numLabels":0}},{"number":412,"url":"https://github.com/w3c/webappsec-csp/issues/412","title":"recapture bug","author":"Ronsekaon","createdAt":"2019-10-19T03:11:27Z","labels":[],"sloTimeUsed":"PT0S","whichSlo":"none","stats":{"numTimelineItems":0,"numComments":3,"numLabels":0}},{"number":414,"url":"https://github.com/w3c/webappsec-csp/issues/414","title":"Spec is inconsistent about which strings are valid CSPs","author":"bakkot","createdAt":"2019-11-22T04:13:16Z","labels":[],"sloTimeUsed":"PT0S","whichSlo":"none","stats":{"numTimelineItems":0,"numComments":1,"numLabels":0}},{"number":419,"url":"https://github.com/w3c/webappsec-csp/issues/419","title":"Where is the Content Security Policy Directive registry?","author":"bakkot","createdAt":"2020-01-16T22:10:26Z","labels":[],"sloTimeUsed":"PT0S","whichSlo":"none","stats":{"numTimelineItems":0,"numComments":1,"numLabels":0}},{"number":420,"url":"https://github.com/w3c/webappsec-csp/issues/420","title":"Why does plugin-types use the empty list instead of 'none'?","author":"bakkot","createdAt":"2020-01-17T01:02:33Z","labels":[],"sloTimeUsed":"PT0S","whichSlo":"none","stats":{"numTimelineItems":0,"numComments":1,"numLabels":0}},{"number":423,"url":"https://github.com/w3c/webappsec-csp/issues/423","title":"Inconsistent treatment of base64url-encoded hash sources in CSP vs SRI","author":"bakkot","createdAt":"2020-03-18T00:28:38Z","labels":["interop"],"sloTimeUsed":"PT0S","whichSlo":"none","stats":{"numTimelineItems":1,"numComments":1,"numLabels":1}},{"number":429,"url":"https://github.com/w3c/webappsec-csp/issues/429","title":"connect-src: wss without schema ","author":"axelssonHakan","createdAt":"2020-03-20T12:49:54Z","labels":[],"sloTimeUsed":"PT0S","whichSlo":"none","stats":{"numTimelineItems":0,"numComments":7,"numLabels":0}},{"number":430,"url":"https://github.com/w3c/webappsec-csp/issues/430","title":"Why does hash-source apply to external scripts, but not external styles?","author":"bakkot","createdAt":"2020-03-25T20:43:10Z","labels":[],"sloTimeUsed":"PT0S","whichSlo":"none","stats":{"numTimelineItems":0,"numComments":1,"numLabels":0}},{"number":431,"url":"https://github.com/w3c/webappsec-csp/issues/431","title":"Why do `base-uri` and `frame-ancestors` have different grammars?","author":"bakkot","createdAt":"2020-04-23T03:32:46Z","labels":[],"sloTimeUsed":"PT0S","whichSlo":"none","stats":{"numTimelineItems":0,"numComments":2,"numLabels":0}},{"number":433,"url":"https://github.com/w3c/webappsec-csp/issues/433","title":"Are nonces allowed/supported in frame-src?","author":"viraptor","createdAt":"2020-04-29T02:52:52Z","labels":[],"sloTimeUsed":"PT0S","whichSlo":"none","stats":{"numTimelineItems":0,"numComments":5,"numLabels":0}},{"number":434,"url":"https://github.com/w3c/webappsec-csp/issues/434","title":"Clarify/test which quote characters may be used","author":"foolip","createdAt":"2020-05-13T08:54:57Z","labels":["clarification"],"sloTimeUsed":"PT0S","whichSlo":"none","stats":{"numTimelineItems":1,"numComments":8,"numLabels":1}},{"number":437,"url":"https://github.com/w3c/webappsec-csp/issues/437","title":"Looking for guidance on defining CSP for <portal>","author":"domenic","createdAt":"2020-07-27T21:30:59Z","labels":[],"sloTimeUsed":"PT0S","whichSlo":"none","stats":{"numTimelineItems":0,"numComments":5,"numLabels":0}},{"number":438,"url":"https://github.com/w3c/webappsec-csp/issues/438","title":"Cross-realm eval() calls and 'unsafe-eval'","author":"TomiBelan","createdAt":"2020-08-05T14:59:37Z","labels":[],"sloTimeUsed":"PT0S","whichSlo":"none","stats":{"numTimelineItems":0,"numComments":7,"numLabels":0}},{"number":439,"url":"https://github.com/w3c/webappsec-csp/issues/439","title":"Does http://example.com:80 match https://example.com?","author":"antosart","createdAt":"2020-08-07T13:50:00Z","labels":[],"sloTimeUsed":"PT0S","whichSlo":"none","stats":{"numTimelineItems":0,"numComments":4,"numLabels":0}},{"number":440,"url":"https://github.com/w3c/webappsec-csp/issues/440","title":"host-part matching should allow IPv6 \"[::1]\" as it does for \"127.0.0.1\"","createdAt":"2020-08-07T21:53:04Z","labels":[],"sloTimeUsed":"PT0S","whichSlo":"none","stats":{"numTimelineItems":0,"numComments":1,"numLabels":0}},{"number":449,"url":"https://github.com/w3c/webappsec-csp/issues/449","title":"CSP violations triggered by scripts: no 'source-file' or 'script-sample'?","author":"ureesoriano","createdAt":"2020-11-12T10:55:12Z","labels":[],"sloTimeUsed":"PT0S","whichSlo":"none","stats":{"numTimelineItems":0,"numComments":2,"numLabels":0}},{"number":452,"url":"https://github.com/w3c/webappsec-csp/issues/452","title":"Do column numbers in violation reports start with 0 or 1?","author":"antosart","createdAt":"2020-12-09T13:53:05Z","labels":["editorial"],"sloTimeUsed":"PT0S","whichSlo":"none","stats":{"numTimelineItems":1,"numComments":1,"numLabels":1}},{"number":453,"url":"https://github.com/w3c/webappsec-csp/issues/453","title":"CSP rules from an external URL?","author":"yonixw","createdAt":"2020-12-23T00:23:02Z","labels":["needs concrete proposal"],"sloTimeUsed":"PT0S","whichSlo":"none","stats":{"numTimelineItems":1,"numComments":4,"numLabels":1}},{"number":458,"url":"https://github.com/w3c/webappsec-csp/issues/458","title":"Accessing the `nonce` from JS, effectively makes all nonce based CSPs `strict-dynamic`","author":"shaialon","createdAt":"2021-01-21T21:21:59Z","labels":[],"sloTimeUsed":"PT0S","whichSlo":"none","stats":{"numTimelineItems":0,"numComments":8,"numLabels":0}},{"number":459,"url":"https://github.com/w3c/webappsec-csp/issues/459","title":"Clarify meaning of 'self' for CSPs in meta tags of local-scheme documents","author":"antosart","createdAt":"2021-01-27T07:16:59Z","labels":[],"sloTimeUsed":"PT0S","whichSlo":"none","stats":{"numTimelineItems":0,"numComments":12,"numLabels":0}},{"number":460,"url":"https://github.com/w3c/webappsec-csp/issues/460","title":"CSP report referrer property in reports with frame-ancestors CSP directive violations ","author":"mxschmitt","createdAt":"2021-02-08T21:45:41Z","labels":[],"sloTimeUsed":"PT0S","whichSlo":"none","stats":{"numTimelineItems":0,"numComments":3,"numLabels":0}},{"number":470,"url":"https://github.com/w3c/webappsec-csp/issues/470","title":"Add report samples to security considerations","author":"jonathanKingston","createdAt":"2021-02-25T15:26:24Z","labels":[],"sloTimeUsed":"PT0S","whichSlo":"none","stats":{"numTimelineItems":0,"numComments":3,"numLabels":0}},{"number":474,"url":"https://github.com/w3c/webappsec-csp/issues/474","title":"Should the parent CSP apply to documents created by svg images?","author":"antosart","createdAt":"2021-03-09T09:54:28Z","labels":[],"sloTimeUsed":"PT0S","whichSlo":"none","stats":{"numTimelineItems":0,"numComments":7,"numLabels":0}},{"number":476,"url":"https://github.com/w3c/webappsec-csp/issues/476","title":"Media queries in the `media` attribute should be subject to CSP","author":"arturjanc","createdAt":"2021-03-10T12:06:49Z","labels":[],"sloTimeUsed":"PT0S","whichSlo":"none","stats":{"numTimelineItems":0,"numComments":2,"numLabels":0}},{"number":487,"url":"https://github.com/w3c/webappsec-csp/issues/487","title":"CSP script-src self and blobs","author":"youennf","createdAt":"2021-04-14T16:52:28Z","labels":[],"sloTimeUsed":"PT0S","whichSlo":"none","stats":{"numTimelineItems":0,"numComments":6,"numLabels":0}},{"number":490,"url":"https://github.com/w3c/webappsec-csp/issues/490","title":"Mention deprecation of plugin-types in CSP3?","author":"Elchi3","createdAt":"2021-04-21T14:54:47Z","labels":[],"sloTimeUsed":"PT0S","whichSlo":"none","stats":{"numTimelineItems":0,"numComments":2,"numLabels":0}},{"number":492,"url":"https://github.com/w3c/webappsec-csp/issues/492","title":"Using csp attribute to prevent all networking out of the srcdoc iframe","author":"mitar","createdAt":"2021-04-29T01:18:46Z","labels":[],"sloTimeUsed":"PT0S","whichSlo":"none","stats":{"numTimelineItems":0,"numComments":3,"numLabels":0}},{"number":498,"url":"https://github.com/w3c/webappsec-csp/issues/498","title":"SecurityPolicyViolationEventInit data members naming doesn't seem to match browsers","author":"cdumez","createdAt":"2021-05-25T20:46:43Z","labels":[],"sloTimeUsed":"PT0S","whichSlo":"none","stats":{"numTimelineItems":0,"numComments":10,"numLabels":0}},{"number":501,"url":"https://github.com/w3c/webappsec-csp/issues/501","title":"Any chance to get Content-Security-Policy: frame-sandbox?","author":"giy-debug","createdAt":"2021-06-12T14:10:48Z","labels":[],"sloTimeUsed":"PT0S","whichSlo":"none","stats":{"numTimelineItems":0,"numComments":1,"numLabels":0}},{"number":502,"url":"https://github.com/w3c/webappsec-csp/issues/502","title":"Preendering and prefetch-src","author":"mfalken","createdAt":"2021-06-18T01:44:51Z","labels":[],"sloTimeUsed":"PT0S","whichSlo":"none","stats":{"numTimelineItems":0,"numComments":5,"numLabels":0}},{"number":506,"url":"https://github.com/w3c/webappsec-csp/issues/506","title":"Consider adding import-src","author":"shhnjk","createdAt":"2021-07-16T22:17:42Z","labels":[],"sloTimeUsed":"PT0S","whichSlo":"none","stats":{"numTimelineItems":0,"numComments":6,"numLabels":0}},{"number":509,"url":"https://github.com/w3c/webappsec-csp/issues/509","title":"frame-src can leak cross origin information","author":"antosart","createdAt":"2021-09-23T07:10:08Z","labels":[],"sloTimeUsed":"PT0S","whichSlo":"none","stats":{"numTimelineItems":0,"numComments":5,"numLabels":0}},{"number":510,"url":"https://github.com/w3c/webappsec-csp/issues/510","title":"Scope of navigate-to and form-action","author":"annevk","createdAt":"2021-09-23T09:40:16Z","labels":[],"sloTimeUsed":"PT0S","whichSlo":"none","stats":{"numTimelineItems":0,"numComments":3,"numLabels":0}},{"number":516,"url":"https://github.com/w3c/webappsec-csp/issues/516","title":"External color profiles and CSP","author":"annevk","createdAt":"2021-10-07T08:49:51Z","labels":[],"sloTimeUsed":"PT0S","whichSlo":"none","stats":{"numTimelineItems":0,"numComments":8,"numLabels":0}},{"number":518,"url":"https://github.com/w3c/webappsec-csp/issues/518","title":"Request to Support Dynamic Resource Validation","author":"gulachek","createdAt":"2021-10-15T21:47:54Z","labels":[],"sloTimeUsed":"PT0S","whichSlo":"none","stats":{"numTimelineItems":0,"numComments":11,"numLabels":0}},{"number":532,"url":"https://github.com/w3c/webappsec-csp/issues/532","title":"Fetch rewrites ws/wss URLs, but browsers still report them in CSP","author":"annevk","createdAt":"2021-11-22T10:59:08Z","labels":["needs concrete proposal","addition/proposal"],"sloTimeUsed":"PT0S","whichSlo":"none","stats":{"numTimelineItems":2,"numComments":3,"numLabels":2}},{"number":535,"url":"https://github.com/w3c/webappsec-csp/issues/535","title":"definitions of ancestor-source differ between documents","author":"kgoess","createdAt":"2022-01-04T01:22:22Z","labels":["editorial"],"sloTimeUsed":"PT0S","whichSlo":"none","stats":{"numTimelineItems":1,"numComments":1,"numLabels":1}},{"number":538,"url":"https://github.com/w3c/webappsec-csp/issues/538","title":"What should the default be for the \"webrtc\" directive in workers?","author":"alvestrand","createdAt":"2022-02-15T08:23:24Z","labels":[],"sloTimeUsed":"PT0S","whichSlo":"none","stats":{"numTimelineItems":0,"numComments":1,"numLabels":0}},{"number":544,"url":"https://github.com/w3c/webappsec-csp/issues/544","title":"`report-uri` deprecation timeline","author":"carlosjeurissen","createdAt":"2022-05-12T15:20:35Z","labels":[],"sloTimeUsed":"PT0S","whichSlo":"none","stats":{"numTimelineItems":0,"numComments":1,"numLabels":0}},{"number":548,"url":"https://github.com/w3c/webappsec-csp/issues/548","title":"Problem caused by script-src-elem 'nonce-<nonce>' 'strcit-dynamic'","author":"seongil-wi","createdAt":"2022-06-03T04:41:14Z","labels":[],"sloTimeUsed":"PT0S","whichSlo":"none","stats":{"numTimelineItems":0,"numComments":1,"numLabels":0}},{"number":551,"url":"https://github.com/w3c/webappsec-csp/issues/551","title":"when using report-uri / report-to when in report only mode `blocked-uri` is returned as `inline`","author":"allen-munsch","createdAt":"2022-06-29T18:48:27Z","labels":[],"sloTimeUsed":"PT0S","whichSlo":"none","stats":{"numTimelineItems":0,"numComments":2,"numLabels":0}},{"number":553,"url":"https://github.com/w3c/webappsec-csp/issues/553","title":"Regarding hashes for JS URL","author":"seongil-wi","createdAt":"2022-07-05T05:58:20Z","labels":[],"sloTimeUsed":"PT0S","whichSlo":"none","stats":{"numTimelineItems":0,"numComments":7,"numLabels":0}},{"number":563,"url":"https://github.com/w3c/webappsec-csp/issues/563","title":"The editor's draft includes several features that no one has shipped.","author":"mikewest","createdAt":"2022-09-15T06:01:43Z","labels":[],"sloTimeUsed":"PT0S","whichSlo":"none","stats":{"numTimelineItems":0,"numComments":13,"numLabels":0}},{"number":574,"url":"https://github.com/w3c/webappsec-csp/issues/574","title":"Enable CSP3 `'unsafe-hashes'` for script `src` attributes","author":"arturjanc","createdAt":"2022-10-26T13:33:35Z","labels":[],"sloTimeUsed":"PT0S","whichSlo":"none","stats":{"numTimelineItems":0,"numComments":4,"numLabels":0}},{"number":575,"url":"https://github.com/w3c/webappsec-csp/issues/575","title":"`'report-hash'`: Adding hashes of blocked content to violation reports ","author":"arturjanc","createdAt":"2022-10-26T13:47:36Z","labels":[],"sloTimeUsed":"PT0S","whichSlo":"none","stats":{"numTimelineItems":0,"numComments":6,"numLabels":0}},{"number":587,"url":"https://github.com/w3c/webappsec-csp/issues/587","title":"Logic issue with resource hint check with multiple conflicting policies","author":"noamr","createdAt":"2023-01-27T09:25:34Z","labels":[],"sloTimeUsed":"PT0S","whichSlo":"none","stats":{"numTimelineItems":0,"numComments":3,"numLabels":0}},{"number":592,"url":"https://github.com/w3c/webappsec-csp/issues/592","title":"host-char mismatches with the URL Standard","author":"annevk","createdAt":"2023-03-15T18:10:36Z","labels":[],"sloTimeUsed":"PT0S","whichSlo":"none","stats":{"numTimelineItems":0,"numComments":7,"numLabels":0}},{"number":608,"url":"https://github.com/w3c/webappsec-csp/issues/608","title":"Remove WPTs for spec-removed `navigate-to` directive","author":"CanadaHonk","createdAt":"2023-06-27T12:34:12Z","labels":["needs tests"],"sloTimeUsed":"PT0S","whichSlo":"none","stats":{"numTimelineItems":1,"numComments":4,"numLabels":1}},{"number":609,"url":"https://github.com/w3c/webappsec-csp/issues/609","title":"Behavior of `worker-src 'strict-dynamic'`","author":"evilpie","createdAt":"2023-07-05T11:45:10Z","labels":[],"sloTimeUsed":"PT0S","whichSlo":"none","stats":{"numTimelineItems":0,"numComments":8,"numLabels":0}},{"number":618,"url":"https://github.com/w3c/webappsec-csp/issues/618","title":"Algorithms should be <dfn> in prose instead of linked to headers","author":"johnathan79717","createdAt":"2023-08-30T16:48:56Z","labels":[],"sloTimeUsed":"PT0S","whichSlo":"none","stats":{"numTimelineItems":0,"numComments":6,"numLabels":0}},{"number":623,"url":"https://github.com/w3c/webappsec-csp/issues/623","title":"Allow `script-src 'unsafe-hashes'` for `eval()` and `new Function`","author":"nicolo-ribaudo","createdAt":"2023-11-03T21:14:32Z","labels":["addition/proposal"],"sloTimeUsed":"PT0S","whichSlo":"none","stats":{"numTimelineItems":3,"numComments":8,"numLabels":1}},{"number":625,"url":"https://github.com/w3c/webappsec-csp/issues/625","title":"Allow 'strict-dynamic' scripts to inject styles","author":"vejja","createdAt":"2023-11-10T09:39:12Z","labels":["agenda+","addition/proposal"],"sloTimeUsed":"PT0S","whichSlo":"none","onAgendaFor":"P457DT14H7M46S","stats":{"numTimelineItems":2,"numComments":7,"numLabels":2},"outOfSlo":true},{"number":628,"url":"https://github.com/w3c/webappsec-csp/issues/628","title":"CSP:EE does not support Trusted Types CSP directives","author":"tosmolka","createdAt":"2023-12-05T17:19:02Z","labels":[],"sloTimeUsed":"PT0S","whichSlo":"none","stats":{"numTimelineItems":0,"numComments":5,"numLabels":0}},{"number":634,"url":"https://github.com/w3c/webappsec-csp/issues/634","title":"Chrome/Safari trim nonces","author":"evilpie","createdAt":"2024-01-05T10:35:40Z","labels":["needs tests","clarification"],"sloTimeUsed":"PT0S","whichSlo":"none","stats":{"numTimelineItems":2,"numComments":11,"numLabels":2}},{"number":648,"url":"https://github.com/w3c/webappsec-csp/issues/648","title":"Google Analytics URLs","author":"cristiandelgadod","createdAt":"2024-02-29T21:53:57Z","labels":["needs concrete proposal"],"sloTimeUsed":"PT0S","whichSlo":"none","stats":{"numTimelineItems":1,"numComments":1,"numLabels":1}},{"number":649,"url":"https://github.com/w3c/webappsec-csp/issues/649","title":"Document columnNumber format","author":"stefnotch","createdAt":"2024-03-13T22:27:15Z","labels":["editorial"],"sloTimeUsed":"PT0S","whichSlo":"none","stats":{"numTimelineItems":1,"numComments":1,"numLabels":1}},{"number":658,"url":"https://github.com/w3c/webappsec-csp/issues/658","title":"Possibility to block all javascript: URLs","author":"Sjord","createdAt":"2024-04-30T08:30:10Z","labels":["needs concrete proposal"],"sloTimeUsed":"PT0S","whichSlo":"none","stats":{"numTimelineItems":1,"numComments":4,"numLabels":1}},{"number":662,"url":"https://github.com/w3c/webappsec-csp/issues/662","title":"frame-src is not effective in restricting the possible origins of subframes","author":"antosart","createdAt":"2024-05-21T18:18:41Z","labels":["needs concrete proposal"],"sloTimeUsed":"PT0S","whichSlo":"none","stats":{"numTimelineItems":1,"numComments":3,"numLabels":1}},{"number":664,"url":"https://github.com/w3c/webappsec-csp/issues/664","title":"Add new CSP sandbox directive to allow SameSite=None cookies on top-level frames","author":"DCtheTall","createdAt":"2024-05-24T13:09:05Z","labels":["agenda+"],"sloTimeUsed":"PT0S","whichSlo":"none","onAgendaFor":"P429DT17H42M49S","stats":{"numTimelineItems":1,"numComments":7,"numLabels":1},"outOfSlo":true},{"number":672,"url":"https://github.com/w3c/webappsec-csp/issues/672","title":"CSP Report Does Not Reflect Redirected Blocked Domains","author":"ConardLi","createdAt":"2024-07-15T08:16:44Z","labels":["wontfix"],"sloTimeUsed":"PT0S","whichSlo":"none","stats":{"numTimelineItems":1,"numComments":8,"numLabels":1}},{"number":673,"url":"https://github.com/w3c/webappsec-csp/issues/673","title":"CSP spec not user-friendly","author":"galund","createdAt":"2024-07-23T09:54:45Z","labels":["needs concrete proposal"],"sloTimeUsed":"PT0S","whichSlo":"none","stats":{"numTimelineItems":1,"numComments":1,"numLabels":1}},{"number":676,"url":"https://github.com/w3c/webappsec-csp/issues/676","title":"loading local stylesheets without self source","author":"nizos","createdAt":"2024-08-13T17:27:16Z","labels":["needs concrete proposal"],"sloTimeUsed":"PT0S","whichSlo":"none","stats":{"numTimelineItems":1,"numComments":2,"numLabels":1}},{"number":677,"url":"https://github.com/w3c/webappsec-csp/issues/677","title":"Should font-src reporting kick in on font-face reference or font request?","author":"robinwhittleton","createdAt":"2024-08-22T09:31:21Z","labels":["agenda+"],"sloTimeUsed":"PT0S","whichSlo":"none","onAgendaFor":"P429DT17H46M16S","stats":{"numTimelineItems":1,"numComments":8,"numLabels":1},"outOfSlo":true},{"number":687,"url":"https://github.com/w3c/webappsec-csp/issues/687","title":"Should \"Should navigation request of type be blocked by Content Security Policy?\" set the violation object's element?","createdAt":"2024-10-24T10:07:05Z","labels":["editorial","clarification"],"sloTimeUsed":"PT0S","whichSlo":"none","stats":{"numTimelineItems":2,"numComments":5,"numLabels":2}},{"number":690,"url":"https://github.com/w3c/webappsec-csp/issues/690","title":"Consider recommending the usage of events instead of CSP reports for CSP WPTs","createdAt":"2024-11-19T15:16:32Z","labels":["meta"],"sloTimeUsed":"PT0S","whichSlo":"none","stats":{"numTimelineItems":3,"numComments":1,"numLabels":1}},{"number":694,"url":"https://github.com/w3c/webappsec-csp/issues/694","title":"Allow RFC3986 scheme relative URIs in host-source","author":"Mahoney","createdAt":"2024-11-27T17:28:46Z","labels":["addition/proposal"],"sloTimeUsed":"PT0S","whichSlo":"none","stats":{"numTimelineItems":1,"numComments":2,"numLabels":1}},{"number":701,"url":"https://github.com/w3c/webappsec-csp/issues/701","title":"How to specify 2 endpoints for Reporting-Endpoints?","author":"SwiftExtender","createdAt":"2025-01-15T16:06:17Z","labels":["meta"],"sloTimeUsed":"PT0S","whichSlo":"none","stats":{"numTimelineItems":1,"numComments":2,"numLabels":1}},{"number":704,"url":"https://github.com/w3c/webappsec-csp/issues/704","title":"Clipping of violation’s sample to the 40 first characters","author":"fred-wang","createdAt":"2025-01-23T11:53:50Z","labels":["needs tests"],"sloTimeUsed":"PT0S","whichSlo":"none","stats":{"numTimelineItems":1,"numComments":6,"numLabels":1}},{"number":706,"url":"https://github.com/w3c/webappsec-csp/issues/706","title":"connect-src test suite allows multiple non-interopable implementations.","author":"lukewarlow","createdAt":"2025-01-30T16:10:43Z","labels":["interop"],"sloTimeUsed":"PT0S","whichSlo":"none","stats":{"numTimelineItems":5,"numComments":7,"numLabels":1}},{"number":707,"url":"https://github.com/w3c/webappsec-csp/issues/707","title":"\"source file\" lacks a real defintion","author":"evilpie","createdAt":"2025-02-14T14:14:02Z","labels":["clarification","interop"],"sloTimeUsed":"PT0S","whichSlo":"none","stats":{"numTimelineItems":2,"numComments":2,"numLabels":2}},{"number":785,"url":"https://github.com/w3c/webappsec-csp/issues/785","title":"report-to directive to support multiple endpoints","author":"armenzg","createdAt":"2025-05-23T16:57:00Z","labels":[],"sloTimeUsed":"PT0S","whichSlo":"none","stats":{"numTimelineItems":0,"numComments":6,"numLabels":0}},{"number":733,"url":"https://github.com/w3c/webappsec-csp/issues/733","title":"Add Back The `prefetch-src` Directive to The CSP Header","author":"zphrs","createdAt":"2025-06-06T19:41:25Z","labels":[],"sloTimeUsed":"PT0S","whichSlo":"none","stats":{"numTimelineItems":0,"numComments":3,"numLabels":0}},{"number":735,"url":"https://github.com/w3c/webappsec-csp/issues/735","title":"Implementation differences with \"Strip URL for use in reports\"","author":"evilpie","createdAt":"2025-06-13T09:28:32Z","labels":[],"sloTimeUsed":"PT0S","whichSlo":"none","stats":{"numTimelineItems":0,"numComments":19,"numLabels":0}},{"number":736,"url":"https://github.com/w3c/webappsec-csp/issues/736","title":"Making CSP more usable for organizations at scale","author":"swijckmans","createdAt":"2025-06-18T16:27:35Z","labels":[],"sloTimeUsed":"PT0S","whichSlo":"none","stats":{"numTimelineItems":0,"numComments":11,"numLabels":0}},{"number":774,"url":"https://github.com/w3c/webappsec-csp/issues/774","title":"setting cssText rather than style","author":"johanneswilm","createdAt":"2025-07-01T07:59:00Z","labels":[],"sloTimeUsed":"PT0S","whichSlo":"none","stats":{"numTimelineItems":0,"numComments":2,"numLabels":0}},{"number":775,"url":"https://github.com/w3c/webappsec-csp/issues/775","title":"CSP report referrer should adhere to referrer policy","author":"imolorhe-stripe","createdAt":"2025-07-07T13:11:33Z","labels":[],"sloTimeUsed":"PT0S","whichSlo":"none","stats":{"numTimelineItems":0,"numComments":1,"numLabels":0}},{"number":792,"url":"https://github.com/w3c/webappsec-csp/issues/792","title":"Attackers can exploit CSP to block requests to legitimate domains","author":"MartijnCuppens","createdAt":"2025-11-25T09:46:41Z","labels":["needs tests","needs implementer interest","addition/proposal"],"sloTimeUsed":"PT0S","whichSlo":"none","stats":{"numTimelineItems":3,"numComments":11,"numLabels":3}},{"number":809,"url":"https://github.com/w3c/webappsec-csp/issues/809","title":"`frame-src` WPT test expects path to be stripped when loading cross-origin URL","author":"TimvdLippe","createdAt":"2026-03-28T12:04:52Z","labels":[],"sloTimeUsed":"PT0S","whichSlo":"none","stats":{"numTimelineItems":0,"numComments":1,"numLabels":0}},{"number":814,"url":"https://github.com/w3c/webappsec-csp/issues/814","title":"Clarify object-src behavior when plugin content has no associated URL","author":"roberto-apple","createdAt":"2026-05-01T21:55:15Z","labels":[],"sloTimeUsed":"PT0S","whichSlo":"none","stats":{"numTimelineItems":0,"numComments":5,"numLabels":0}},{"number":363,"url":"https://github.com/w3c/webappsec-csp/pull/363","title":"Specify behavior in case of malformed policies","author":"andypaicu","createdAt":"2018-11-09T14:43:18Z","pull_request":{"draft":false},"labels":["agenda+","clarification","interop"],"sloTimeUsed":"PT0S","whichSlo":"none","onAgendaFor":"P492DT14H16M21S","stats":{"numTimelineItems":47,"numComments":47,"numLabels":3},"outOfSlo":true},{"number":377,"url":"https://github.com/w3c/webappsec-csp/pull/377","title":"Use the duplicate attribute flag is nonceable check","author":"andypaicu","createdAt":"2018-12-13T16:49:43Z","pull_request":{"draft":false},"labels":["blocked"],"sloTimeUsed":"PT0S","whichSlo":"none","stats":{"numTimelineItems":8,"numComments":8,"numLabels":1}},{"number":621,"url":"https://github.com/w3c/webappsec-csp/pull/621","title":"[editorial] Make algorithm headers clickable","author":"antosart","createdAt":"2023-09-06T09:18:23Z","pull_request":{"draft":false},"labels":["editorial"],"milestone":{"url":"https://github.com/w3c/webappsec-csp/milestone/1","title":"CSP3 CR"},"sloTimeUsed":"PT0S","whichSlo":"none","stats":{"numTimelineItems":16,"numLabels":1}},{"number":710,"url":"https://github.com/w3c/webappsec-csp/pull/710","title":"Add dveditz, ciaramcmullin and qabandi as editors","author":"qabandi","createdAt":"2025-03-14T23:01:21Z","pull_request":{"draft":false},"labels":[],"sloTimeUsed":"PT0S","whichSlo":"none","stats":{"numTimelineItems":9,"numComments":9,"numLabels":0}},{"number":734,"url":"https://github.com/w3c/webappsec-csp/pull/734","title":"Use \"Strip URL\" from the Reporting API","author":"yoavweiss","createdAt":"2025-06-13T07:12:04Z","pull_request":{"draft":false},"labels":[],"sloTimeUsed":"PT0S","whichSlo":"none","stats":{"numTimelineItems":10,"numComments":10,"numLabels":0}},{"number":776,"url":"https://github.com/w3c/webappsec-csp/pull/776","title":"Integrate with speculation rules","author":"domenic","createdAt":"2025-07-10T05:37:18Z","pull_request":{"draft":false},"labels":[],"sloTimeUsed":"PT0S","whichSlo":"none","stats":{"numTimelineItems":15,"numComments":15,"numLabels":0}},{"number":784,"url":"https://github.com/w3c/webappsec-csp/pull/784","title":"Extend CSP script-src hashes","author":"carlosjoan91","createdAt":"2025-08-20T20:38:54Z","pull_request":{"draft":false},"labels":[],"sloTimeUsed":"PT0S","whichSlo":"none","stats":{"numTimelineItems":14,"numComments":14,"numLabels":0}},{"number":793,"url":"https://github.com/w3c/webappsec-csp/pull/793","title":"`immutable` Specification","author":"MartijnCuppens","createdAt":"2025-11-26T14:37:19Z","pull_request":{"draft":false},"labels":["needs tests","needs implementer interest","addition/proposal"],"sloTimeUsed":"PT0S","whichSlo":"none","stats":{"numTimelineItems":9,"numComments":9,"numLabels":3}},{"number":799,"url":"https://github.com/w3c/webappsec-csp/pull/799","title":"Add WebDriver BiDi CSP bypass checks","author":"juliandescottes","createdAt":"2026-02-06T09:18:12Z","pull_request":{"draft":false},"labels":[],"sloTimeUsed":"PT0S","whichSlo":"none","stats":{"numTimelineItems":23,"numComments":23,"numLabels":0}},{"number":803,"url":"https://github.com/w3c/webappsec-csp/pull/803","title":"[import-bytes] add `bytes` destination","author":"styfle","createdAt":"2026-03-05T02:24:45Z","pull_request":{"draft":false},"labels":[],"sloTimeUsed":"PT0S","whichSlo":"none","stats":{"numTimelineItems":9,"numComments":9,"numLabels":0}},{"number":807,"url":"https://github.com/w3c/webappsec-csp/pull/807","title":"Fix Bikeshed API endpoint in Makefile","author":"yoavweiss","createdAt":"2026-03-13T08:13:35Z","pull_request":{"draft":false},"labels":[],"sloTimeUsed":"PT0S","whichSlo":"none","stats":{"numTimelineItems":7,"numComments":7,"numLabels":0}},{"number":808,"url":"https://github.com/w3c/webappsec-csp/pull/808","title":"Integrate with speculation rules ","author":"vickiez","createdAt":"2026-03-13T22:39:58Z","pull_request":{"draft":false},"labels":[],"sloTimeUsed":"PT0S","whichSlo":"none","stats":{"numTimelineItems":13,"numComments":13,"numLabels":0}},{"number":810,"url":"https://github.com/w3c/webappsec-csp/pull/810","title":"Update nonceable attribute checks for link elements","author":"mikewest","createdAt":"2026-04-08T06:48:29Z","pull_request":{"draft":false},"labels":[],"sloTimeUsed":"PT0S","whichSlo":"none","stats":{"numTimelineItems":5,"numComments":5,"numLabels":0}}]}