Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

OpenSSF Scorecard checklist #21322

Closed
11 of 18 tasks
danielroe opened this issue Jun 2, 2023 · 1 comment
Closed
11 of 18 tasks

OpenSSF Scorecard checklist #21322

danielroe opened this issue Jun 2, 2023 · 1 comment

Comments

@danielroe
Copy link
Member

danielroe commented Jun 2, 2023

As part of improving Nuxt's security profile, I'm working through implementing recommendations from the OSSF Scorecard. While not all of them will be relevant for Nuxt, I still think there are some best practices we can implement.

Tasks

@Hebilicious
Copy link
Member

Great idea ! I would love to have more sensible security defaults out-of-the box.

A few things that comes to mind :

  • Add a security section to the box
  • add an origin check for POST requests and a flag to disable it, similar to sveltekit
  • Add some of the security features provided by nuxt/security in core

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Projects
None yet
Development

No branches or pull requests

2 participants