proposal 13.4.* Verify that source maps are disabled in production environments to prevent source code leakage.
Open
Nobody has claimed this yet.
4) proposal for review
requires change control
V13 (prev V14)
- Dominant language
- HTML
- Stars
- 3.6k
- Forks
- 831
- Avg merge
- 7h 55m
- Merged PRs (30d)
- 4
Description
Following the leak of Apple’s App Store frontend source code caused by source maps being enabled in production, it may be beneficial to add an explicit requirement advising against enabling source maps in production environments.
Contributor guide
First steps
- Read the whole issue, then the project's contributing guide.
- Comment on the issue to say you are picking it up — it saves two people doing the same work.
- Fork the repository and make your change on a branch.
- Open a pull request that references the issue number.
Research direction
Start by reviewing the ASVS section associated with proposal 13.4.* and the linked TC39 source maps reference. Determine where an explicit production source-map requirement belongs and confirm that the finished change clearly advises against exposing source code through source maps in production environments.
Written by the indexing model from the issue text.
Assessment
- Domain
- documentation, security
- Issue type
- Documentation
- Difficulty
- 3/5
- Estimated time
- 1-2 days
- Activity status
- Stale
- Clarity
- Mostly clear
- Newbie friendliness
- 35/100