Text
HTTP Strict Transport Security (HSTS)
HTTP Public Key Pinning (HPKP)
X-Content-Type-Options
X-Frame-Options
X-XSS-Protection
Referrer Policy
Subresource Integrity (SRI)
Escaping must be context sensitive!
Content-Security-Policy:
default-src 'none';
base-uri 'self';
block-all-mixed-content;
child-src render.githubusercontent.com;
connect-src 'self' uploads.github.com status.github.com;
font-src assets-cdn.github.com;
form-action 'self' github.com gist.github.com;
frame-ancestors 'none';
img-src 'self' data: assets-cdn.github.com *.githubusercontent.com;
media-src 'none';
script-src assets-cdn.github.com;
style-src 'unsafe-inline' assets-cdn.github.com
Content-Security-Policy:
object-src 'none';
script-src 'nonce-$random' 'strict-dynamic'
'unsafe-inline' 'unsafe-eval' https: http:;
report-uri https://yourreportingendpoint;
Strict-Transport-Security: max-age=31536000; includeSubdomains; preload
Public-Key-Pins:
pin-sha256='X3pGTSOuJeEVw989IJ/cEtXUEmy52zs1TZQrU06KUKg=';
pin-sha256='MHJYVThihUrJcxW6wcqyOISTXIsInsdj3xK8QrZbHec=';
pin-sha256='isi41AizREkLvvft0IRW4u3XMFR2Yg7bvrF7padyCJg=';
includeSubdomains;
max-age=2592000
X-Content-Type-Options: nosniff
X-Frame-Options: SAMEORIGIN
X-Xss-Protection: 1; mode=block
Referrer-Policy: Referrer-Policy: origin-when-cross-origin