Releases: edilec/http-security-header-auditor
Release list
HTTP Security Header Auditor v0.1.0
HTTP Security Header Auditor v0.1.0
First versioned source release of Edilec's MIT-licensed, dependency-free Node.js 22+ CLI for checking saved HTTP response-header captures against a declared route policy. It reports missing or forbidden fields, allowed-value mismatches, CSP contradictions and incomplete evidence separately. Checked-in synthetic examples cover pass, fail and incomplete outcomes.
The tool never connects to a site or scans a live response. A pass covers the supplied capture and policy; it does not choose a good policy, prove what every browser enforced, or certify a production deployment. For those rollout decisions, see Edilec's Security Headers and Browser Controls production guide.
From a checkout of this tag, run npm run check and then node bin/http-security-header-auditor.mjs --root examples/clean --as-of 2026-03-01 to inspect the public clean fixture. The repository README documents its input contract, limits, findings and exits.
This is a GitHub source release, not a claim of publication to npm. Edilec maintains the tool. These release notes were prepared with AI assistance and checked against the public source and test run.