nodejs / security-wg

Node.js Ecosystem Security Working Group

Geek Repo:Geek Repo

Github PK Tool:Github PK Tool

Requirement (Gold level): Secured delivery against man-in-the-middle (MITM) attacks

UlisesGascon opened this issue · comments

We agreed on #1175 to open an issue to follow up a discussion about this requirement for Node.js (cc: @mhdawson @ljharb @RafaelGSS)

The project website, repository (if accessible via the web), and download site (if separate) MUST include key hardening headers with nonpermissive values. (URL required)

Context

Potential actions

TBD

I assume if the website has CORS and HSTS set up, this will be satisfied.

This issue is stale because it has been open many days with no activity. It will be closed soon unless the stale label is removed or a comment is made.