Skip to content

Releases: InvictusNavarchus/cf-headers

v0.5.0

Choose a tag to compare

@InvictusNavarchus InvictusNavarchus released this 13 Sep 15:48
v0.5.0
004d114
  • refactor(csp): rename compatible CSP preset to standard (218fcc9)
  • feat(csp): add permissive CSP preset for inline script compatibility (e3f230b)

v0.4.1

Choose a tag to compare

@InvictusNavarchus InvictusNavarchus released this 13 Sep 15:18
v0.4.1
e9c5216
  • docs(presets): clarify preset options, defaults, and CSP baseline (242ec48)
  • docs: fix dynamicContentPreset cache-control directive order (3a5ebac)
  • docs: clarify builder validation and constraint checks (b62e0fe)

v0.4.0

Choose a tag to compare

@InvictusNavarchus InvictusNavarchus released this 17 Jul 05:52
ad24f4d
  • chore(knip): remove unused exports and redundant types (b36fd9f)
  • chore(knip): configure example vite configs as entry points (55b1917)
  • docs: export CspPresetName and document CSP overrides in README (350eade)
  • docs: update README and production example with new preset and customization configurations (b45fbdb)
  • feat(presets): allow custom and disableable referrer policy, x-content-type-options, and permissions policy (ef17358)
  • docs(presets): document scope of corsPreset and recommend raw rules for APIs (9f72bd8)
  • feat(presets): make presets self-healing and reduce static asset header bloat (1710392)
  • feat(csp): introduce compatible and strict CSP presets (ac3b3a5)
  • fix(presets): align default permissions policy with locked-down settings (3d4eaee)

v0.3.1

Choose a tag to compare

@InvictusNavarchus InvictusNavarchus released this 15 Jul 08:43
b37da36
  • chore: sort package.json fields with sort-package-json (1a70522)
  • chore: add author to package.json (ca3c943)
  • docs: add link to LICENSE badge (681fada)
  • docs: add npm page link to npm badge (7092d3a)
  • chore: add git repo to package.json (06086c0)
  • docs: put npm badge first before license (7028ef9)
  • docs: change version badge title to npm (77fa77f)

v0.3.0

Choose a tag to compare

@InvictusNavarchus InvictusNavarchus released this 15 Jul 05:06
0205892
  • fix(docs): update package imports to use @navarchus/cf-headers scope (fb63c38)
  • feat: implement strict check against rule overriding and add override helper (d0b549d)
  • chore: update examples to explicitly showcase platform option (f680a04)
  • refactor: target platform domains strictly in noIndexPreviewDomainPreset (2135dc7)
  • refactor: update noIndexPreviewDomainPreset to return multiple rules (59a7223)
  • refactor: refine noIndexPreviewDomainPreset signature and validation (5921fbb)
  • test: add vitest coverage (78673cb)

v0.2.1

Choose a tag to compare

@InvictusNavarchus InvictusNavarchus released this 14 Jul 15:30
e865a66
  • chore(scripts): replace npm run with bun run (e7e5bbb)
  • chore: add knip (4b1da3e)
  • docs: fix broken code block due to escaped tildes (cc57527)

v0.2.0

Choose a tag to compare

@InvictusNavarchus InvictusNavarchus released this 13 Jul 13:48
f51c7f1
  • chore(release): adjust release and tagName (46c7ba8)
  • chore: add release-assets to .gitignore (0fd3b64)
  • fix(release): wrong release-it confnig filename - missing dot (fb1962d)
  • chore(release): add github config to release-it and add assets (57cb08f)
  • chore(release): change commit message and style format (6711c8e)
  • refactor: extract release-it config to its own file (575356a)
  • docs: simplify README catalog metadata section (d5726b6)
  • docs: simplify README summary (afb8a2d)
  • Merge pull request #1 from InvictusNavarchus/refactor/drop-cli-and-config-loader (1449ca6)
  • docs: update documentation to reflect CLI removal (2cd16d4)
  • refactor(config): remove config loader and runtime typescript compilation (d43382f)
  • refactor: drop CLI binary and commands (e7a2856)
  • fix(docs): replace npx cf-headers with npx @navarchus/cf-headers (526c09e)

v0.1.1

Choose a tag to compare

@InvictusNavarchus InvictusNavarchus released this 13 Jul 07:13
25d8dd4
  • chore: rename package to @navarchus/cf-headers to avoid npm typosquatting false positive (437c741)

v0.1.0

Choose a tag to compare

@InvictusNavarchus InvictusNavarchus released this 13 Jul 06:15
b3b2136
  • Release 0.1.0 (b3b2136)
  • ci: add ci github workflow (9aceee9)
  • chore: disable automatic release-it npm publishing (f4e671f)
  • chore: add release-it for release automation (c2f7bcf)
  • docs: add img shields badges for license and version (9c8aba5)
  • refactor(vite): use satisfies Plugin to preserve precise hook types in tests (41645aa)
  • docs: document optional peer dependencies and zero-dependency JS setup in README (d9835a9)
  • refactor(cli): scope esbuild dependency to CLI path by dynamically importing it (591374e)
  • refactor(vite): replace hand-rolled plugin type with official vite Plugin type (fbf44bd)
  • refactor: simplify HeaderValueFor type in header-values.ts (5caba0e)
  • refactor: reuse serializeHeaderLine in validate.ts (92db955)
  • refactor: collapse duplicate build/validate pipelines (65945b1)
  • refactor: resolve circular imports between types and registry (06d3453)
  • refactor: remove all deprecated signatures and legacy option sniffer logic (d751c9b)
  • refactor: secure options sniffer with compile-time check and add deprecation overloads (5c79dfd)
  • style: resolve biome noArguments lint warning in presets.ts (16884f3)
  • fix: omit COEP by default and fix resolver default parameter trap (4571915)
  • refactor: extract option resolution logic to dedicated helper functions (a04288f)
  • feat: set default COEP header value to 'unsafe-none' (9a31bd6)
  • feat(examples): add production config example and reorganize examples (689aa68)
  • chore(examples): add runnable script to view generated _headers output (cee4c63)
  • feat(presets): include X-Frame-Options in baseline security headers by default (cb8f49d)
  • feat(presets): revise security headers and add dynamic content presets (b28d8d5)
  • refactor: modularize validate.ts by extracting header-specific validation rules (1b23ad4)
  • refactor: separate CSP and Cache-Control validation from serialization helpers (b82c783)
  • refactor: separate Permissions-Policy validation from helper serialization (216e350)
  • feat: validate Permissions-Policy and prevent common CSP-like configuration errors (bad9d63)
  • feat: add Number.isFinite guard for numeric header values (ff2d1f3)
  • test: add configuration loading, CLI, integration, and Vite plugin tests (eeb2a31)
  • docs: add section on CAC documentation gaps and behavioral quirks (36a2b36)
  • docs: document CLI design decisions and CAC parser behavior (6de87ca)
  • refactor: use cac for CLI argument parsing (4209e51)
  • refactor: use node:util parseArgs for CLI argument parsing (d9726f9)
  • fix: address lint issues for string concatenation and explicit any (14af155)
  • refactor: remove redundant undefined value (69f971d)
  • chore: add biome lint and format scripts to package.json (7593e3e)
  • chore: add lefthook for automatic formatting (50346bb)
  • style: biome format (ec7b10e)
  • chore: setup biome for code formatting (5d85b66)
  • feat: require explicit path argument in corsPreset (5bf22d9)
  • feat: implement secure-by-default enhancements (ad3ff82)
  • refactor(examples): use rule() instead of raw object literal (b20096a)
  • refactor: standardize examples (34d2e6f)
  • fix: remove unsupported tsdown config (be7248b)
  • refactor: drop legacy CJS support and transition to ESM-only (1856904)
  • build: fix package entry points and exports paths (aadd253)
  • chore: migrate to tsdown using migration tool (c877156)
  • docs(license): add author (419eb59)
  • chore: major bump all deps (a037294)
  • chore: replace package lock with bun lock (22ffbba)
  • initial commit (ab65dbf)