hasadna / hasadna/reportit-agent

security improvements [?h]

Open
#102 1 comment 0 reactions 1 assignee Claimed by @akariv View on GitHub
security
Dominant language
TypeScript
Stars
1
Forks
1
PR merge metrics
No merged PRs in 30d

Description

based on https://sitecheck.sucuri.net/results/https/admin.equality.org.il:

* [ ] Missing security header for [ClickJacking Protection](https://docs.sucuri.net/warnings/hardening/security-headers-x-frame-options/). Alternatively, you can [use Content-Security-Policy: frame-ancestors 'none'. ](https://developer.mozilla.org/en-US/docs/Web/HTTP/Headers/Content-Security-Policy/frame-ancestors)
* [ ] Missing security header to prevent [Content Type sniffing.](https://docs.sucuri.net/warnings/hardening/security-headers-x-content-type-nosniff/)
* [ ] Missing [Strict-Transport-Security security header.](https://developer.mozilla.org/en-US/docs/Web/HTTP/Headers/Strict-Transport-Security)
* [ ] Missing [Content-Security-Policy directive.](https://blog.sucuri.net/2018/04/content-security-policy.html) We recommend to add the following CSP directives (you can use default-src if all values are the same): script-src, object-src, base-uri, frame-src

Contributor guide

No contributing guide indexed for this repository

Assessment

This issue has not been assessed yet.

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.