Security improvements #605
Labels
dx
Developer Experience
epic
A master issue thread which contains other smaller issues
hacktoberfest
Issues for Hacktoberfest
security
Web security
Milestone
Overview
This is a master issue to track all security-related improvements to WBW.
Currently the WBW website is still missing some essential security headers, as detected by securityheaders.com
Current Tasks
security.txt
file to make it easier for security researchers to submit security vulnerability reports #482X-Frame-Options: DENY
header #608X-Content-Type-Options: nosniff
header #609Permissions-Policy
header to disallow features that we don't use #610Content-Security-Policy
header to prevent cross-site scripting (XSS) attacks #611The text was updated successfully, but these errors were encountered: