Blog
FAQ
Discussions
Search
Projects, issues, users, and merge requests.
Project ID, name, and description.
User nickname, name, and org.
Issue ID, title, and summary.
Merge request titles.
Contrib
.social
Feed
Live feed
Builds
Live builds
Core
Tags
Tags and Initiatives
Security Kit
Open on Drupal.org โ
Open on Drupal GitLab โ
Created on 26 March 2011,
over 14 years ago
Maintained by
๐จ๐ฆ
Canada
badjava
๐ณ๐ฟ
New Zealand
jweowu
๐ฌ๐ง
United Kingdom
mcdruid
p0deje
Clone
Clone with SSH
Clone with HTTPS
Clone with
doGit
๐ฌ๐ง
United Kingdom
33%
๐บ๐ธ
United States
24%
๐ณ๐ฑ
Netherlands
12%
๐ฎ๐น
Italy
9%
๐ณ๐ฟ
New Zealand
7%
๐จ๐ฆ
Canada
6%
๐ดโโ ๏ธ
3%
๐ช๐ธ
Spain
1%
๐ฎ๐ณ
India
1%
๐ท๐บ
Russia
1%
๐ฆ๐บ
Australia
1%
Top 10 contributors
Full Fat Things
21%
๐ฌ๐ง
@the_g_bomb
ezCompany
10%
๐ณ๐ฑ
@idebr
Catalyst IT
9%
๐ณ๐ฟ
@jweowu
๐ฆ๐บ
@jnlar
Affinity Digital Tech Ltd
9%
๐ฌ๐ง
@somersoft
Oomph, Inc.
6%
๐บ๐ธ
@ben.hamelin
๐บ๐ธ
@pfrilling
Blue Oak Interactive
4%
๐บ๐ธ
@andyg5000
Chromatic
3%
๐บ๐ธ
@apotek
Chronos Interactive Media
3%
๐บ๐ธ
@dabblela
Bluehorn Digital
3%
๐บ๐ธ
@mglaman
Numiko
3%
@joshhytr
+6
and 6 other organisations
QED42
๐ฎ๐ณ
@rahulrasgon
DICTU
๐ณ๐ฑ
@groendijk
iO
๐ณ๐ฑ
@idebr
Acquia
๐ฌ๐ง
@mcdruid
๐บ๐ธ
@mglaman
Brewed Up
๐บ๐ธ
@mglaman
Somersoft
๐ฌ๐ง
@somersoft
and 6 individuals
( 25% )
๐ช๐ธ
@bmunslow
๐บ๐ธ
@damienmckenna
๐จ๐ฆ
@gapple
๐ฎ๐น
@apaderno
๐ท๐บ
@a.kovrigin
๐จ๐ฆ
@No Sssweat
Follow
Sign in to follow projects
Merge Requests
More
!54
report-uri is deprecated
Open
Show issue
๐ง๐ช
Belgium
Jonasanne
updated
10 days ago
!53
Missing CSP directives
Open
Show issue
๐ฏ๐ต
Japan
eleonel
updated
about 1 month ago
!52
Support flood control for CSP violation reports
Open
Show issue
๐ฆ๐บ
Australia
geoffreyr
updated
about 2 months ago
!51
Issue #3541096: Remove the term whitelist* from the module
Open
๐ฌ๐ง
United Kingdom
the_g_bomb
updated
2 months ago
!50
Issue #3537083: cspell issues reported in pipeline
Open
๐ฌ๐ง
United Kingdom
the_g_bomb
updated
2 months ago
!19
Change Feature Policy to Permissions Policy (D8/D9)
Open
Show issue
๐ฎ๐ณ
India
Lokeshwari
updated
3 months ago
More Merge Requests
Issues
๐
report-uri is deprecated
Active
Code
Created
over 2 years ago
v2.0
๐ณ๐ฑ
Netherlands
laurentd
2 months ago
๐
Remove the term whitelist* from the module
Active
Code
Created
2 months ago
v2.0
๐ฌ๐ง
United Kingdom
the_g_bomb
2 months ago
๐
cspell issues reported in pipeline
Active
Code
Created
3 months ago
v2.0
๐ณ๐ฑ
Netherlands
idebr
2 months ago
โจ
Change Feature Policy to Permissions Policy (D8/D9)
Needs review
Code
Created
almost 5 years ago
v2.0
๐ต๐น
Portugal
rfmarcelino
3 months ago
โจ
Add support for the Cross-Origin-Opener-Policy (COOP) header
Active
Code
Created
3 months ago
v2.0
๐บ๐ธ
United States
pfrilling
3 months ago
โจ
Implement the script-src-attr policy
Needs review
Code
Created
over 3 years ago
v2.0
๐ง๐ท
Brazil
barone
4 months ago
โจ
Support for configuring script-src-elem
Active
Code
Created
7 months ago
v2.0
๐บ๐ธ
United States
apotek
5 months ago
โจ
Need to exclude admin path from applying the policies
Active
Code
Created
over 1 year ago
v2.0
๐ป๐ณ
Vietnam
tm01xx
5 months ago
๐
Breaks sitemap.xml when JS +CSS + Noscript protection is enabled
Active
Code
Created
over 4 years ago
v2.0
๐ญ๐บ
Hungary
asrob
5 months ago
๐
CSS fails, if default-src "self" configured
Active
Code
Created
6 months ago
v2.0
๐ฉ๐ช
Germany
drupalbubb
5 months ago
๐ฌ
Offering to maintain Security Kit
Active
Miscellaneous
Created
almost 3 years ago
v2.0
๐ฎ๐ณ
India
rajeshreeputra
5 months ago
โจ
Extend length of src fields
Needs review
Code
Created
over 4 years ago
v2.0
๐ท๐ธ
Serbia
milovan
5 months ago
โจ
Add support for form-action directive
Needs work
Code
Created
6 months ago
v2.0
๐ฎ๐ฑ
Israel
albert van kiel
6 months ago
โจ
Add support for form-action directive
Closed: duplicate
Code
Created
6 months ago
v2.0
๐ฎ๐ฑ
Israel
albert van kiel
6 months ago
๐
default-src has wrong description
Needs work
Documentation
Created
almost 5 years ago
v2.0
๐ฆ๐บ
Australia
marji
8 months ago
๐
Avoid using document.write('<!--');
Needs work
Code
Created
almost 5 years ago
v1.2
๐ท๐บ
Russia
kostyashupenko
8 months ago
๐ฌ
How to add all google tlds for CSP
Active
User interface
Created
over 3 years ago
v2.0
๐บ๐ธ
United States
justclint
8 months ago
๐ฌ
CSP: Directive script-src-elem violated with googletagmanager
Needs work
Code
Created
over 4 years ago
v2.0
๐ฎ๐ณ
India
sivaprasadc
8 months ago
๐ฌ
Google URL's are blocked.
Active
Miscellaneous
Created
over 1 year ago
v2.0
๐ฎ๐ณ
India
suresh prabhu parkala
8 months ago
โจ
Permissions Policy Support
RTBC
Miscellaneous
Created
over 4 years ago
v2.0
๐ฆ๐น
Austria
gr4phic3r
9 months ago
โจ
Change Feature Policy to Permissions Policy
Closed: won't fix
Code
Created
about 5 years ago
v1.11
๐ฎ๐ณ
India
Souvik Pal
9 months ago
๐
Seckit doesnยดt work for Images, CSS, JS
Active
Code
Created
9 months ago
v2.0
๐ฆ๐น
Austria
gr4phic3r
9 months ago
๐
Seckit seckitGetJsCssNoscriptCode hijacks js aggregation files.
Active
Code
Created
over 1 year ago
v2.0
๐บ๐ฆ
Ukraine
bahbka
11 months ago
๐ฌ
/report-csp-violation throwing an error
Active
Miscellaneous
Created
11 months ago
v2.0
๐บ๐ธ
United States
duckydan
11 months ago
โจ
Implement a "semi automatic" Nonce settings
Needs review
Miscellaneous
Created
about 4 years ago
v2.0
๐ง๐ท
Brazil
barone
11 months ago
โจ
"Directive style-src-elem violated."
Active
Code
Created
about 5 years ago
v1.0
๐บ๐ธ
United States
damienmckenna
11 months ago
โจ
Allow certain paths to be excluded from the Origin check (patch included)
Active
Code
Created
over 4 years ago
v2.0
๐ฌ๐ง
United Kingdom
andy tawse
11 months ago
โจ
Add worker-src
Needs review
Code
Created
about 3 years ago
v1.0
๐ฌ๐ง
United Kingdom
dahousecat
11 months ago
โจ
Dispatch an event when there is a CSP violation
Active
Code
Created
11 months ago
v2.0
๐บ๐ธ
United States
dabblela
11 months ago
โจ
Add worker-src
Active
Code
Created
over 1 year ago
v2.0
๐ฌ๐ง
United Kingdom
dahousecat
about 1 year ago
โจ
Add form-action directive
Needs review
Code
Created
over 4 years ago
v2.0
๐ฌ๐ง
United Kingdom
Dubs
about 1 year ago
๐
Drupal calls should be avoided in classes, use dependency injection instead
Active
Code
Created
almost 2 years ago
v2.0
๐ง๐ท
Brazil
PabloNicolas
about 1 year ago
๐
Multiple html lines of seckitGetJsCssNoscriptCode function create issue when js aggregate and minify html is on
Active
Code
Created
about 1 year ago
v2.0
๐ฎ๐ณ
India
hetalsagar
about 1 year ago
๐
Missing container invalidation update from issue modifying services
Active
Code
Created
about 1 year ago
v2.0
๐ฆ๐บ
Australia
prussobcm
about 1 year ago
๐
The base-uri policy is missing
Needs review
Code
Created
almost 6 years ago
v2.0
๐ง๐ช
Belgium
cubeinspire
about 1 year ago
๐
Clickjacking CSS protection hides content when site is embed inside an iframe, even if frame-ancestors is set
Active
Code
Created
almost 2 years ago
v2.0
๐ช๐ธ
Spain
jsbalsera
about 1 year ago
๐ฌ
SA-CONTRIB-2024-039 Clarification?
Fixed
Code
Created
about 1 year ago
v2.0
๐บ๐ธ
United States
kruser
about 1 year ago
โจ
Provide hook_seckit_options_alter() D8
Needs review
Code
Created
almost 9 years ago
v2.0
๐ท๐บ
Russia
ogggg
about 1 year ago
๐
Set 2.x as default branch
Fixed
Code
Created
about 1 year ago
v2.0
๐ฉ๐ช
Germany
mkalkbrenner
about 1 year ago
๐
Update summary on project page for compatibility with Project Browser
Active
Miscellaneous
Created
about 1 year ago
v2.0
๐บ๐ธ
United States
leslieg
about 1 year ago
๐
Update logo for compatibility with Project Browser
Active
Miscellaneous
Created
about 1 year ago
v2.0
๐บ๐ธ
United States
leslieg
about 1 year ago
๐
Enabling "Enable JavaScript + CSS + Noscript protection" causes invalid HTML
Needs work
Code
Created
over 6 years ago
v2.0
๐บ๐ธ
United States
averagejoe3000
about 1 year ago
๐
php error
Closed: duplicate
Code
Created
about 1 year ago
v2.0
๐ฉ๐ช
Germany
ngruendel
about 1 year ago
๐
Modernize services: Add autowiring aliases, use autoconfigure, etc
Needs review
Code
Created
about 1 year ago
v2.0
๐ฆ๐บ
Australia
dpi
about 1 year ago
๐
Multiple html lines of seckitGetJsCssNoscriptCode function create issue when js aggregate and minify html is on
Active
Code
Created
about 1 year ago
v2.0
๐ฎ๐ณ
India
hetalsagar
about 1 year ago
๐
D11 release for seckit
Fixed
Code
Created
about 1 year ago
v2.0
๐ฌ๐ง
United Kingdom
mcdruid
about 1 year ago
๐
Coding Standard Issues
Fixed
Code
Created
about 1 year ago
v2.0
๐ต๐ช
Peru
alyaj2a
about 1 year ago
๐
Add testing of report-csp-violation
Fixed
Code
Created
about 1 year ago
v2.0
๐ฌ๐ง
United Kingdom
mcdruid
about 1 year ago
โจ
Silent mode for CSP reporting
Active
Code
Created
over 3 years ago
v2.0
๐บ๐ฆ
Ukraine
ksemihin
about 1 year ago
โจ
Update CSP directives
Needs review
Code
Created
about 8 years ago
v2.0
๐บ๐ธ
United States
Mojiferous
about 1 year ago
โจ
Store CSP sources as a list of values on multiple lines to increase manageability and prevent merge conflicts
Needs review
Code
Created
about 2 years ago
v2.0
๐ง๐ช
Belgium
Dozz
about 1 year ago
๐
Automated Drupal 11 compatibility fixes for seckit
Closed: duplicate
Code
Created
over 1 year ago
v2.0
project update bot
about 1 year ago
๐
Automated Drupal 11 compatibility fixes for seckit
Fixed
Code
Created
over 1 year ago
v2.0
project update bot
about 1 year ago
๐
Fix validate pipeline
Fixed
Code
Created
over 1 year ago
v2.0
๐ฎ๐ณ
India
ankitv18
about 1 year ago
๐
Add Gitlab CI
Fixed
Code
Created
over 1 year ago
v2.0
๐ฎ๐ณ
India
deepakkm
about 1 year ago
๐
No values in X-XSS-Protection Header select box
Fixed
User interface
Created
over 7 years ago
v2.0
rajithkumark
over 1 year ago
๐
Drupal 9.1 Deprecated Code Report
RTBC
Code
Created
almost 5 years ago
v2.0
๐ฌ๐ท
Greece
suzymasri
over 1 year ago
๐ฌ
Question about HSTS max-age
Active
Miscellaneous
Created
over 1 year ago
v2.0
๐ณ๐ฑ
Netherlands
RobBNL
over 1 year ago
โจ
Text fields not big enough
Fixed
Code
Created
over 2 years ago
v2.0
๐ช๐ธ
Spain
penyaskito
over 1 year ago
๐
Add phpcs and drupal-check fixes
Needs review
Code
Created
over 3 years ago
v2.0
๐ฎ๐ณ
India
bendale
over 1 year ago
โจ
Store each CSP rule on a seperate line in config
Active
Code
Created
over 1 year ago
v2.0
๐ฌ๐ง
United Kingdom
dahousecat
over 1 year ago
๐
Support flood control for CSP violation reports
Needs work
Code
Created
over 9 years ago
v1.0
๐ณ๐ฟ
New Zealand
jweowu
over 1 year ago
๐
t() calls should be avoided in classes.
Needs review
Code
Created
over 1 year ago
v2.0
๐ฎ๐ณ
India
chaitanyadessai
over 1 year ago
๐
\Drupal calls should be avoided in classes, use dependency injection instead
Needs review
Code
Created
over 1 year ago
v2.0
๐ฎ๐ณ
India
chaitanyadessai
over 1 year ago
๐
Add LICENSE.txt file
Closed: works as designed
Code
Created
over 1 year ago
v2.0
๐ท๐ด
Romania
ciprian.stavovei
over 1 year ago
๐ฌ
Backdrop CMS Port?
Fixed
Miscellaneous
Created
over 3 years ago
v1.0
rbargerhuff
over 1 year ago
๐
Misleading recommendation for CSP directive "frame-src"
RTBC
Documentation
Created
over 2 years ago
v1.0
๐จ๐ฆ
Canada
fengtan
over 1 year ago
๐
Fix D7 Forms API syntax
RTBC
Code
Created
over 2 years ago
v1.0
๐จ๐ฆ
Canada
mvc
over 1 year ago
โจ
Add support for setting referer policy from route in issue #3027122
Needs work
Code
Created
about 4 years ago
v2.0
๐ฆ๐บ
Australia
gordon
almost 2 years ago
๐ฌ
Lottie files / base64 encoding
Active
Miscellaneous
Created
over 2 years ago
v1.11
๐บ๐ธ
United States
Mile3
almost 2 years ago
๐ฌ
Uncaught DOMException: Permission denied to access property "hostname" on cross-origin object
Active
Code
Created
almost 2 years ago
v2.0
๐ช๐ธ
Spain
gpollner
almost 2 years ago
๐
Add a reference to csp_log in documentation
Active
Documentation
Created
almost 2 years ago
v2.0
๐ง๐ช
Belgium
daften
almost 2 years ago
๐ฌ
How to set httpOnly flag on cookies?
Needs review
Documentation
Created
almost 2 years ago
v2.0
๐ช๐ธ
Spain
uridrupal
almost 2 years ago
๐ฌ
Vulnerability Scan reported 150206 - Content-Security-Policy Not Implemented
Closed: won't fix
User interface
Created
about 2 years ago
v2.0
๐ฎ๐ณ
India
ankitasharma13
about 2 years ago
๐
Replace README.txt with README.md
Fixed
Documentation
Created
about 3 years ago
v2.0
๐ฎ๐ณ
India
Manoj Raj.R
about 2 years ago
๐
Fix the warnings/errors reported by PHP_CodeSniffer
Fixed
Code
Created
over 5 years ago
v2.0
๐ณ๐ฟ
New Zealand
xurizaemon
about 2 years ago
๐
Update source url in composer.json
Fixed
Code
Created
about 5 years ago
v2.0
๐ณ๐ด
Norway
neslee canil pinto
about 2 years ago
๐
License "GPL-2.0+" is a deprecated SPDX license identifier
Fixed
Code
Created
over 5 years ago
v2.0
๐ฎ๐ณ
India
harishh
about 2 years ago
๐
JS/CSS/Noscript code gets added twice to head on 404/403 pages
Fixed
Code
Created
almost 6 years ago
v2.0
๐บ๐ธ
United States
averagejoe3000
about 2 years ago
๐
Minor Typo in SecKitEventSubscriber.php File
Fixed
Code
Created
almost 5 years ago
v2.0
๐ฎ๐ณ
India
sivaprasadc
about 2 years ago
๐
Drupal CSS Standards
Fixed
Code
Created
over 2 years ago
v1.0
๐บ๐ธ
United States
bygeoffthompson
about 2 years ago
๐
seckit/listener library incorrectly defined
Fixed
Code
Created
about 2 years ago
v2.0
๐ฌ๐ง
United Kingdom
mcdruid
about 2 years ago
๐
style-src key missing in seckit.settings.yml
Fixed
Code
Created
over 2 years ago
v2.0
๐ฆ๐บ
Australia
jnlar
about 2 years ago
โจ
Remove Generator meta tag from output
Closed: works as designed
Code
Created
about 9 years ago
v2.0
๐ฆ๐บ
Australia
chop
about 2 years ago
๐
Illegal choice 0 in Configure element.
Closed: duplicate
Code
Created
about 5 years ago
v2.0
๐ฎ๐ณ
India
vijay.mayilsamy
about 2 years ago
๐
Add textarea type to script-src field
Closed: duplicate
Code
Created
about 3 years ago
v2.0
๐ฎ๐ณ
India
ashetkar
about 2 years ago
โจ
Allow entering more content in CSP fields
Closed: duplicate
Code
Created
about 3 years ago
v2.0
๐จ๐ฆ
Canada
dylan donkersgoed
about 2 years ago
โจ
Extend length of feature policy field
Closed: duplicate
Code
Created
about 6 years ago
v2.0
๐ณ๐ฑ
Netherlands
dennis_meuwissen
about 2 years ago
โจ
Add support for form-action CSP directive
Active
Code
Created
almost 8 years ago
v1.0
๐บ๐ธ
United States
milodesc
about 2 years ago
โจ
Longer fields to support Google TLD's
Closed: duplicate
Code
Created
over 2 years ago
v1.0
๐จ๐ฆ
Canada
djac
over 2 years ago
๐
Trailing slash on void elements has no effect and interacts badly with unquoted attribute values
Closed: duplicate
Code
Created
over 2 years ago
v2.0
fromme
over 2 years ago
๐
Remove type="text/javascript" from <script> tag
Needs review
Code
Created
over 2 years ago
v2.0
fromme
over 2 years ago
๐
Deprecated Feature Used Expect-CT header
Needs review
Code
Created
almost 3 years ago
v2.0
l_nava
over 2 years ago
๐
Expect-CT is deprecated; provide a warning or remove
Closed: duplicate
Code
Created
over 2 years ago
v2.0
๐ฏ๐ต
Japan
ptmkenny
over 2 years ago
โจ
Text fields not big enough
Fixed
Code
Created
over 6 years ago
v1.0
๐ฌ๐ง
United Kingdom
dunx
over 2 years ago
๐
Skip report-uri processing if value is empty
Fixed
Code
Created
almost 6 years ago
v1.0
๐บ๐ธ
United States
ron_s
over 2 years ago
โจ
Add support for feature-policy header
Fixed
Code
Created
about 7 years ago
v1.0
๐ฆ๐บ
Australia
adammalone
over 2 years ago
๐ฑ
Deprecate / Remove Content Security Policy configuration in favour of Content Security Policy module
Active
Code
Created
over 7 years ago
v1.0
๐จ๐ฆ
Canada
gapple
over 2 years ago
๐
Missing Strict-Transport-Security header
Closed: works as designed
Code
Created
over 6 years ago
v1.0
๐จ๐ญ
Switzerland
handkerchief
over 2 years ago
๐
ALLOW-FROM directive in x-frame-options is obsolete
Active
Code
Created
almost 3 years ago
v2.0
๐ฌ๐ง
United Kingdom
oldspot
almost 3 years ago
contrib
.social
Blog
FAQ
Discussions
Production build 0.71.5
2024