security-wg icon indicating copy to clipboard operation
security-wg copied to clipboard

Requirement (Gold level): Secured delivery against man-in-the-middle (MITM) attacks

Open UlisesGascon opened this issue 2 years ago • 8 comments

We agreed on #1175 to open an issue to follow up a discussion about this requirement for Node.js (cc: @mhdawson @ljharb @RafaelGSS)

The project website, repository (if accessible via the web), and download site (if separate) MUST include key hardening headers with nonpermissive values. (URL required)

Context

Potential actions

TBD

UlisesGascon avatar Jan 04 '24 18:01 UlisesGascon

I assume if the website has CORS and HSTS set up, this will be satisfied.

ljharb avatar Jan 06 '24 15:01 ljharb

This issue is stale because it has been open many days with no activity. It will be closed soon unless the stale label is removed or a comment is made.

github-actions[bot] avatar Apr 06 '24 00:04 github-actions[bot]