Skip to content

Review current HTTP Headers, DNS, etc... #1973

Description

@UlisesGascon

So far seems like we can invest some time to improve several things:

  • The HTTP headers in the website and discuss if we want to apply headers like: Content Security Policy, Strict Transport Policy, X-Content-Type-Options, X-Frame-Options, X-XSS-Protection...
  • CA Authorization in the TLS layer
  • Enable HSTS
  • Add a Security.Txtfile pointing to the current project security policy?

I used Web Check to do a fast review, so this is not yet an exhaustive list

Metadata

Metadata

Assignees

Labels

No labels
No labels

Type

No type
No fields configured for issues without a type.

Projects

No projects

Milestone

No milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions