expressjs / expressjs/expressjs.com
Review current HTTP Headers, DNS, etc...
Open
- Dominant language
- MDX
- Stars
- 5.4k
- Forks
- 2.3k
- Avg merge
- 2d 23m
- Merged PRs (30d)
- 14
Description
So far seems like we can invest some time to improve several things:
- The HTTP headers in the website and discuss if we want to apply headers like: Content Security Policy, Strict Transport Policy, X-Content-Type-Options, X-Frame-Options, X-XSS-Protection...
- CA Authorization in the TLS layer
- Enable HSTS
- Add a `Security.Txt`file pointing to the current project security policy?
I used [Web Check](https://web-check.xyz/check/https%3A%2F%2Fexpressjs.com) to do a fast review, so this is not yet an exhaustive list
Contributor guide
Assessment
This issue has not been assessed yet.