Blog
FAQ
Discussions
Search
Projects, issues, users, and merge requests.
Project ID, name, and description.
User nickname, name, and org.
Issue ID, title, and summary.
Merge request titles.
Contrib
.social
Feed
Live feed
Builds
Live builds
Core
Tags
Tags and Initiatives
Security Kit
Open on Drupal.org โ
Open on Drupal GitLab โ
Created on 26 March 2011,
about 14 years ago
Maintained by
๐จ๐ฆ
Canada
badjava
๐ณ๐ฟ
New Zealand
jweowu
๐ฌ๐ง
United Kingdom
mcdruid
p0deje
Clone
Clone with SSH
Clone with HTTPS
Clone with
doGit
๐ฌ๐ง
United Kingdom
32%
๐บ๐ธ
United States
15%
๐ฆ๐บ
Australia
13%
๐ฎ๐ณ
India
8%
๐ต๐ช
Peru
5%
๐ฉ๐ช
Germany
4%
๐จ๐ฆ
Canada
4%
๐ฎ๐น
Italy
4%
๐ดโโ ๏ธ
3%
๐ซ๐ฎ
Finland
3%
๐ณ๐ฟ
New Zealand
3%
๐ณ๐ฑ
Netherlands
3%
๐ท๐บ
Russia
2%
๐ดโโ ๏ธ
๐ช๐ธ ๐บ๐ฆ ๐ง๐ท
2%
Top 10 contributors
Acquia
18%
๐ฎ๐ณ
@ankitv18
๐ฌ๐ง
@mcdruid
๐ฎ๐ณ
@deepakkm
Affinity Digital Tech Ltd
5%
๐ฌ๐ง
@somersoft
Tomato Elephant Studio
5%
๐ฆ๐บ
@VladimirAus
SeeD EM
5%
๐ต๐ช
@alyaj2a
Third and Grove
4%
๐บ๐ธ
@jds1
Catalyst IT
4%
๐ณ๐ฟ
@jweowu
๐ฆ๐บ
@jnlar
Jarltech Europe GmbH
3%
๐ฉ๐ช
@mkalkbrenner
Fame Helsinki
3%
๐ซ๐ฎ
@sokru
DICTU
3%
๐ณ๐ฑ
@groendijk
Chromatic
2%
๐บ๐ธ
@apotek
+13
and 13 other organisations
Oomph, Inc.
๐บ๐ธ
@ben.hamelin
Share Good USA
๐บ๐ธ
@BenStallings
Redfin Solutions, LLC
๐บ๐ธ
@leslieg
Numiko
@joshhytr
United Nations
๐ฉ๐ช
@berliner
Drupal Ukraine Community
๐บ๐ฆ
@eugene.brit
State Library of New South Wales
๐ฆ๐บ
@geoffreyr
Cyber-Duck
๐ฌ๐ง
@Alina Basarabeanu
Attico International
@yauheni
Zoocha
๐ง๐ท
@PabloNicolas
Interdependent Web LLC
๐บ๐ธ
@BenStallings
Investis Digital
๐บ๐ฆ
@eugene.brit
Somersoft
๐ฌ๐ง
@somersoft
and 14 individuals
( 38% )
๐ช๐ธ
@bmunslow
๐ฌ๐ง
@dahousecat
๐บ๐ธ
@DamienMcKenna
๐ฆ๐บ
@dpi
๐จ๐ฆ
@gapple
๐ฎ๐น
@apaderno
๐บ๐ธ
@dabblela
๐ท๐บ
@shra
๐ฌ๐ง
@the_g_bomb
๐ฌ๐ง
@littlepixiez
๐ท๐บ
@a.kovrigin
๐ฎ๐ณ
@hetalsagar
๐จ๐ฆ
@No Sssweat
@project update bot
Follow
Sign in to follow projects
Merge Requests
More
!47
Resolve #3521718 "Add support for form-action directive"
Open
Unnamed author
updated
9 days ago
!16
default-src has wrong description
Open
Show issue
Unnamed author
updated
3 months ago
!46
Avoid using document.write('<!--');
Open
Show issue
๐ฌ๐ง
United Kingdom
the_g_bomb
updated
3 months ago
!30
Avoid using document.write('<!--');
Open
Show issue
๐ช๐ธ
Spain
luismagr
updated
3 months ago
!45
Allow certain paths to be excluded from the Origin check (patch included)
Open
Show issue
joshhytr
updated
6 months ago
!44
"Directive style-src-elem violated."
Open
Show issue
๐บ๐ธ
United States
DamienMcKenna
updated
6 months ago
More Merge Requests
Issues
โจ
Need to exclude admin path from applying the policies
Active
Code
Created
about 1 year ago
v2.0
๐ป๐ณ
Vietnam
tm01xx
about 3 hours ago
โจ
Extend length of src fields
Needs review
Code
Created
about 4 years ago
v2.0
๐ท๐ธ
Serbia
milovan
1 day ago
๐
CSS fails, if default-src "self" configured
Active
Code
Created
4 days ago
v2.0
๐ฉ๐ช
Germany
drupalbubb
3 days ago
๐
Breaks sitemap.xml when JS +CSS + Noscript protection is enabled
Active
Code
Created
almost 4 years ago
v2.0
๐ญ๐บ
Hungary
asrob
8 days ago
โจ
Add support for form-action directive
Needs work
Code
Created
16 days ago
v2.0
๐ฎ๐ฑ
Israel
albert van kiel
9 days ago
โจ
Add support for form-action directive
Closed: duplicate
Code
Created
16 days ago
v2.0
๐ฎ๐ฑ
Israel
albert van kiel
9 days ago
โจ
Support for configuring script-src-elem
Active
Code
Created
about 2 months ago
v2.0
๐บ๐ธ
United States
apotek
about 2 months ago
๐
default-src has wrong description
Needs work
Documentation
Created
over 4 years ago
v2.0
๐ฆ๐บ
Australia
marji
3 months ago
โจ
Change Feature Policy to Permissions Policy (D8/D9)
Needs review
Code
Created
over 4 years ago
v2.0
๐ต๐น
Portugal
rfmarcelino
3 months ago
๐
Avoid using document.write('<!--');
Needs work
Code
Created
over 4 years ago
v1.2
๐ท๐บ
Russia
kostyashupenko
3 months ago
๐ฌ
How to add all google tlds for CSP
Active
User interface
Created
almost 3 years ago
v2.0
๐บ๐ธ
United States
justclint
3 months ago
๐ฌ
CSP: Directive script-src-elem violated with googletagmanager
Needs work
Code
Created
about 4 years ago
v2.0
๐ฎ๐ณ
India
sivaprasadc
3 months ago
๐ฌ
Google URL's are blocked.
Active
Miscellaneous
Created
over 1 year ago
v2.0
๐ฎ๐ณ
India
suresh prabhu parkala
3 months ago
โจ
Permissions Policy Support
RTBC
Miscellaneous
Created
over 4 years ago
v2.0
๐ฆ๐น
Austria
gr4phic3r
4 months ago
โจ
Change Feature Policy to Permissions Policy
Closed: won't fix
Code
Created
over 4 years ago
v1.11
๐ฎ๐ณ
India
Souvik Pal
4 months ago
๐
Seckit doesnยดt work for Images, CSS, JS
Active
Code
Created
4 months ago
v2.0
๐ฆ๐น
Austria
gr4phic3r
4 months ago
๐
Seckit seckitGetJsCssNoscriptCode hijacks js aggregation files.
Active
Code
Created
about 1 year ago
v2.0
๐บ๐ฆ
Ukraine
bahbka
5 months ago
๐ฌ
/report-csp-violation throwing an error
Active
Miscellaneous
Created
5 months ago
v2.0
๐บ๐ธ
United States
duckydan
5 months ago
โจ
Implement a "semi automatic" Nonce settings
Needs review
Miscellaneous
Created
over 3 years ago
v2.0
๐ง๐ท
Brazil
barone
5 months ago
โจ
"Directive style-src-elem violated."
Active
Code
Created
over 4 years ago
v1.0
๐บ๐ธ
United States
DamienMcKenna
5 months ago
โจ
Allow certain paths to be excluded from the Origin check (patch included)
Active
Code
Created
about 4 years ago
v2.0
๐ฌ๐ง
United Kingdom
andy tawse
6 months ago
โจ
Add worker-src
Needs review
Code
Created
almost 3 years ago
v1.0
๐ฌ๐ง
United Kingdom
dahousecat
6 months ago
โจ
Dispatch an event when there is a CSP violation
Active
Code
Created
6 months ago
v2.0
๐บ๐ธ
United States
dabblela
6 months ago
โจ
Add worker-src
Active
Code
Created
about 1 year ago
v2.0
๐ฌ๐ง
United Kingdom
dahousecat
7 months ago
โจ
Add form-action directive
Needs review
Code
Created
almost 4 years ago
v2.0
๐ฌ๐ง
United Kingdom
Dubs
7 months ago
๐
Drupal calls should be avoided in classes, use dependency injection instead
Active
Code
Created
over 1 year ago
v2.0
๐ง๐ท
Brazil
PabloNicolas
7 months ago
๐
Multiple html lines of seckitGetJsCssNoscriptCode function create issue when js aggregate and minify html is on
Active
Code
Created
8 months ago
v2.0
๐ฎ๐ณ
India
hetalsagar
7 months ago
๐
Missing container invalidation update from issue modifying services
Active
Code
Created
9 months ago
v2.0
๐ฆ๐บ
Australia
prussobcm
7 months ago
๐
The base-uri policy is missing
Needs review
Code
Created
over 5 years ago
v2.0
๐ง๐ช
Belgium
cubeinspire
8 months ago
๐
Clickjacking CSS protection hides content when site is embed inside an iframe, even if frame-ancestors is set
Active
Code
Created
over 1 year ago
v2.0
๐ช๐ธ
Spain
jsbalsera
8 months ago
๐ฌ
SA-CONTRIB-2024-039 Clarification?
Fixed
Code
Created
8 months ago
v2.0
๐บ๐ธ
United States
kruser
8 months ago
โจ
Provide hook_seckit_options_alter() D8
Needs review
Code
Created
over 8 years ago
v2.0
๐ท๐บ
Russia
ogggg
8 months ago
๐
Set 2.x as default branch
Fixed
Code
Created
9 months ago
v2.0
๐ฉ๐ช
Germany
mkalkbrenner
8 months ago
๐
Update summary on project page for compatibility with Project Browser
Active
Miscellaneous
Created
8 months ago
v2.0
๐บ๐ธ
United States
leslieg
8 months ago
๐
Update logo for compatibility with Project Browser
Active
Miscellaneous
Created
8 months ago
v2.0
๐บ๐ธ
United States
leslieg
8 months ago
๐
Enabling "Enable JavaScript + CSS + Noscript protection" causes invalid HTML
Needs work
Code
Created
almost 6 years ago
v2.0
๐บ๐ธ
United States
averagejoe3000
8 months ago
๐
php error
Closed: duplicate
Code
Created
8 months ago
v2.0
๐ฉ๐ช
Germany
ngruendel
8 months ago
๐
Modernize services: Add autowiring aliases, use autoconfigure, etc
Needs review
Code
Created
8 months ago
v2.0
๐ฆ๐บ
Australia
dpi
8 months ago
๐
Multiple html lines of seckitGetJsCssNoscriptCode function create issue when js aggregate and minify html is on
Active
Code
Created
8 months ago
v2.0
๐ฎ๐ณ
India
hetalsagar
8 months ago
๐
D11 release for seckit
Fixed
Code
Created
9 months ago
v2.0
๐ฌ๐ง
United Kingdom
mcdruid
8 months ago
๐
Coding Standard Issues
Fixed
Code
Created
8 months ago
v2.0
๐ต๐ช
Peru
alyaj2a
8 months ago
๐
Add testing of report-csp-violation
Fixed
Code
Created
9 months ago
v2.0
๐ฌ๐ง
United Kingdom
mcdruid
8 months ago
โจ
Silent mode for CSP reporting
Active
Code
Created
about 3 years ago
v2.0
๐บ๐ฆ
Ukraine
ksemihin
8 months ago
โจ
Update CSP directives
Needs review
Code
Created
over 7 years ago
v2.0
๐บ๐ธ
United States
Mojiferous
9 months ago
โจ
Store CSP sources as a list of values on multiple lines to increase manageability and prevent merge conflicts
Needs review
Code
Created
over 1 year ago
v2.0
๐ง๐ช
Belgium
Dozz
9 months ago
๐
Automated Drupal 11 compatibility fixes for seckit
Closed: duplicate
Code
Created
10 months ago
v2.0
project update bot
9 months ago
๐
Automated Drupal 11 compatibility fixes for seckit
Fixed
Code
Created
about 1 year ago
v2.0
project update bot
9 months ago
๐
Fix validate pipeline
Fixed
Code
Created
10 months ago
v2.0
๐ฎ๐ณ
India
ankitv18
10 months ago
๐
Add Gitlab CI
Fixed
Code
Created
over 1 year ago
v2.0
๐ฎ๐ณ
India
deepakkm
10 months ago
๐
No values in X-XSS-Protection Header select box
Fixed
User interface
Created
almost 7 years ago
v2.0
rajithkumark
11 months ago
๐
Drupal 9.1 Deprecated Code Report
RTBC
Code
Created
over 4 years ago
v2.0
๐ฌ๐ท
Greece
suzymasri
11 months ago
๐ฌ
Question about HSTS max-age
Active
Miscellaneous
Created
about 1 year ago
v2.0
๐ณ๐ฑ
Netherlands
RobBNL
12 months ago
โจ
Text fields not big enough
Fixed
Code
Created
over 2 years ago
v2.0
๐ช๐ธ
Spain
penyaskito
about 1 year ago
๐
Add phpcs and drupal-check fixes
Needs review
Code
Created
about 3 years ago
v2.0
๐ฎ๐ณ
India
bendale
about 1 year ago
โจ
Store each CSP rule on a seperate line in config
Active
Code
Created
about 1 year ago
v2.0
๐ฌ๐ง
United Kingdom
dahousecat
about 1 year ago
๐
Support flood control for CSP violation reports
Needs work
Code
Created
about 9 years ago
v1.0
๐ณ๐ฟ
New Zealand
jweowu
about 1 year ago
๐
t() calls should be avoided in classes.
Needs review
Code
Created
about 1 year ago
v2.0
๐ฎ๐ณ
India
chaitanyadessai
about 1 year ago
๐
\Drupal calls should be avoided in classes, use dependency injection instead
Needs review
Code
Created
about 1 year ago
v2.0
๐ฎ๐ณ
India
chaitanyadessai
about 1 year ago
๐
Add LICENSE.txt file
Closed: works as designed
Code
Created
about 1 year ago
v2.0
๐ท๐ด
Romania
ciprian.stavovei
about 1 year ago
๐ฌ
Backdrop CMS Port?
Fixed
Miscellaneous
Created
over 3 years ago
v1.0
rbargerhuff
about 1 year ago
๐
Misleading recommendation for CSP directive "frame-src"
RTBC
Documentation
Created
about 2 years ago
v1.0
๐จ๐ฆ
Canada
fengtan
over 1 year ago
๐
Fix D7 Forms API syntax
RTBC
Code
Created
almost 2 years ago
v1.0
๐จ๐ฆ
Canada
mvc
over 1 year ago
โจ
Add support for setting referer policy from route in issue #3027122
Needs work
Code
Created
almost 4 years ago
v2.0
๐ฆ๐บ
Australia
gordon
over 1 year ago
๐ฌ
Lottie files / base64 encoding
Active
Miscellaneous
Created
about 2 years ago
v1.11
๐บ๐ธ
United States
Mile3
over 1 year ago
๐ฌ
Uncaught DOMException: Permission denied to access property "hostname" on cross-origin object
Active
Code
Created
over 1 year ago
v2.0
๐ช๐ธ
Spain
gpollner
over 1 year ago
๐
Add a reference to csp_log in documentation
Active
Documentation
Created
over 1 year ago
v2.0
๐ง๐ช
Belgium
daften
over 1 year ago
๐ฌ
How to set httpOnly flag on cookies?
Needs review
Documentation
Created
over 1 year ago
v2.0
๐ช๐ธ
Spain
uridrupal
over 1 year ago
๐ฌ
Vulnerability Scan reported 150206 - Content-Security-Policy Not Implemented
Closed: won't fix
User interface
Created
over 1 year ago
v2.0
๐ฎ๐ณ
India
ankitasharma13
over 1 year ago
๐
Replace README.txt with README.md
Fixed
Documentation
Created
over 2 years ago
v2.0
๐ฎ๐ณ
India
Manoj Raj.R
over 1 year ago
๐
Fix the warnings/errors reported by PHP_CodeSniffer
Fixed
Code
Created
about 5 years ago
v2.0
๐ณ๐ฟ
New Zealand
xurizaemon
almost 2 years ago
๐
Update source url in composer.json
Fixed
Code
Created
over 4 years ago
v2.0
๐ณ๐ด
Norway
neslee canil pinto
almost 2 years ago
๐
License "GPL-2.0+" is a deprecated SPDX license identifier
Fixed
Code
Created
almost 5 years ago
v2.0
๐ฎ๐ณ
India
harishh
almost 2 years ago
๐
JS/CSS/Noscript code gets added twice to head on 404/403 pages
Fixed
Code
Created
over 5 years ago
v2.0
๐บ๐ธ
United States
averagejoe3000
almost 2 years ago
๐
Minor Typo in SecKitEventSubscriber.php File
Fixed
Code
Created
over 4 years ago
v2.0
๐ฎ๐ณ
India
sivaprasadc
almost 2 years ago
๐
Drupal CSS Standards
Fixed
Code
Created
about 2 years ago
v1.0
๐บ๐ธ
United States
bygeoffthompson
almost 2 years ago
๐
seckit/listener library incorrectly defined
Fixed
Code
Created
almost 2 years ago
v2.0
๐ฌ๐ง
United Kingdom
mcdruid
almost 2 years ago
๐
style-src key missing in seckit.settings.yml
Fixed
Code
Created
almost 2 years ago
v2.0
๐ฆ๐บ
Australia
jnlar
almost 2 years ago
๐
report-uri is deprecated
Active
Code
Created
about 2 years ago
v2.0
๐ณ๐ฑ
Netherlands
LaurentD
almost 2 years ago
โจ
Remove Generator meta tag from output
Closed: works as designed
Code
Created
over 8 years ago
v2.0
๐ฆ๐บ
Australia
chOP
almost 2 years ago
๐
Illegal choice 0 in Configure element.
Closed: duplicate
Code
Created
almost 5 years ago
v2.0
๐ฎ๐ณ
India
vijay.mayilsamy
almost 2 years ago
๐
Add textarea type to script-src field
Closed: duplicate
Code
Created
almost 3 years ago
v2.0
๐ฎ๐ณ
India
ashetkar
almost 2 years ago
โจ
Allow entering more content in CSP fields
Closed: duplicate
Code
Created
over 2 years ago
v2.0
๐จ๐ฆ
Canada
dylan donkersgoed
almost 2 years ago
โจ
Extend length of feature policy field
Closed: duplicate
Code
Created
over 5 years ago
v2.0
๐ณ๐ฑ
Netherlands
dennis_meuwissen
almost 2 years ago
โจ
Add support for form-action CSP directive
Active
Code
Created
over 7 years ago
v1.0
๐บ๐ธ
United States
milodesc
almost 2 years ago
โจ
Longer fields to support Google TLD's
Closed: duplicate
Code
Created
almost 2 years ago
v1.0
๐จ๐ฆ
Canada
djac
almost 2 years ago
๐
Trailing slash on void elements has no effect and interacts badly with unquoted attribute values
Closed: duplicate
Code
Created
almost 2 years ago
v2.0
fromme
almost 2 years ago
๐
Remove type="text/javascript" from <script> tag
Needs review
Code
Created
almost 2 years ago
v2.0
fromme
almost 2 years ago
๐
Deprecated Feature Used Expect-CT header
Needs review
Code
Created
over 2 years ago
v2.0
l_nava
almost 2 years ago
๐
Expect-CT is deprecated; provide a warning or remove
Closed: duplicate
Code
Created
over 2 years ago
v2.0
๐ฏ๐ต
Japan
ptmkenny
almost 2 years ago
โจ
Text fields not big enough
Fixed
Code
Created
almost 6 years ago
v1.0
๐ฌ๐ง
United Kingdom
dunx
over 2 years ago
๐
Skip report-uri processing if value is empty
Fixed
Code
Created
over 5 years ago
v1.0
๐บ๐ธ
United States
ron_s
over 2 years ago
โจ
Add support for feature-policy header
Fixed
Code
Created
almost 7 years ago
v1.0
๐ฆ๐บ
Australia
adammalone
over 2 years ago
๐ฌ
Offering to maintain Security Kit
Active
Miscellaneous
Created
over 2 years ago
v2.0
๐ฎ๐ณ
India
rajeshreeputra
about 2 years ago
๐ฑ
Deprecate / Remove Content Security Policy configuration in favour of Content Security Policy module
Active
Code
Created
almost 7 years ago
v1.0
๐จ๐ฆ
Canada
gapple
over 2 years ago
๐
Missing Strict-Transport-Security header
Closed: works as designed
Code
Created
about 6 years ago
v1.0
๐จ๐ญ
Switzerland
handkerchief
about 2 years ago
๐
ALLOW-FROM directive in x-frame-options is obsolete
Active
Code
Created
over 2 years ago
v2.0
๐ฌ๐ง
United Kingdom
oldspot
over 2 years ago
๐
Blocked URI missing/empty in log entries
Closed: works as designed
Code
Created
about 11 years ago
v1.9
๐บ๐ธ
United States
bsnav
about 2 years ago
โจ
Add 'Disable Security Kit' option back
Active
User interface
Created
about 2 years ago
v2.0
๐บ๐ธ
United States
Jonathan_W
about 2 years ago
โจ
Add manifest-src
Active
Code
Created
about 4 years ago
v2.0
๐ธ๐ช
Sweden
acke
about 2 years ago
contrib
.social
Blog
FAQ
Discussions
Production build 0.71.5
2024