Commit graph

7 commits

Author SHA1 Message Date
513a73f17f checker: flag the deprecated Public-Key-Pins (HPKP) header
All checks were successful
continuous-integration/drone/push Build is passing
continuous-integration/drone/tag Build is passing
2026-06-18 11:06:13 +09:00
a0fb42223b checker: flag information-disclosure response headers
Report Server, X-Powered-By, X-AspNet-Version and X-AspNetMvc-Version
headers, whose presence leaks the server/framework stack. Server only
warns on informative values (version/product detail), accepting a
non-informative value per OWASP.
2026-06-18 11:06:13 +09:00
329df14ec6 checker: flag the deprecated Expect-CT header 2026-06-18 11:05:07 +09:00
a652692ba4 checker: align X-XSS-Protection severities with OWASP
Absent is now OK (OWASP recommends leaving it unset or set to 0),
and filtering mode (bare 1 or 1; report=...) is Warn since selective
script rewriting can itself introduce XSS. 1; mode=block stays Info.
2026-06-18 10:52:31 +09:00
4be2bc9343 Update rules section 2026-04-30 08:57:39 +07:00
01bdadd2ab Add modern security header rules 2026-04-28 18:42:26 +07:00
542ebdea34 Initial commit 2026-04-28 18:42:11 +07:00