expressjs / expressjs/expressjs.com

Review current HTTP Headers, DNS, etc...

Open
#1,973 2 comments 1 reaction 1 assignee Claimed by @bjohansebas View on GitHub
Dominant language
MDX
Stars
5.4k
Forks
2.3k
Avg merge
2d 23m
Merged PRs (30d)
14

Description

So far seems like we can invest some time to improve several things:

- The HTTP headers in the website and discuss if we want to apply headers like: Content Security Policy, Strict Transport Policy, X-Content-Type-Options, X-Frame-Options, X-XSS-Protection...
- CA Authorization in the TLS layer
- Enable HSTS
- Add a `Security.Txt`file pointing to the current project security policy?

I used [Web Check](https://web-check.xyz/check/https%3A%2F%2Fexpressjs.com) to do a fast review, so this is not yet an exhaustive list

Contributor guide

Open the contributing guide

Assessment

This issue has not been assessed yet.

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.