Blog
FAQ
Discussions
Search
Projects, issues, users, and merge requests.
Project ID, name, and description.
User nickname, name, and org.
Issue ID, title, and summary.
Merge request titles.
Contrib
.social
Feed
Live feed
Builds
Live builds
Core
Tags
Tags and Initiatives
Security Kit
Open on Drupal.org โ
Open on Drupal GitLab โ
Created on 26 March 2011,
over 14 years ago
Maintained by
๐จ๐ฆ
Canada
badjava
๐ณ๐ฟ
New Zealand
jweowu
๐ฌ๐ง
United Kingdom
mcdruid
p0deje
Clone
Clone with SSH
Clone with HTTPS
Clone with
doGit
๐ฌ๐ง
United Kingdom
30%
๐บ๐ธ
United States
18%
๐ณ๐ฑ
Netherlands
9%
๐ฆ๐บ
Australia
8%
๐ฎ๐ณ
India
5%
๐ฎ๐น
Italy
5%
๐ณ๐ฟ
New Zealand
5%
๐ต๐ช
Peru
5%
๐ฉ๐ช
Germany
4%
๐จ๐ฆ
Canada
4%
๐ซ๐ฎ
Finland
2%
๐ดโโ ๏ธ
2%
๐ท๐บ
Russia
2%
๐ดโโ ๏ธ
๐ช๐ธ ๐บ๐ฆ ๐ง๐ท
2%
Top 10 contributors
Full Fat Things
12%
๐ฌ๐ง
@the_g_bomb
Catalyst IT
6%
๐ณ๐ฟ
@jweowu
๐ฆ๐บ
@jnlar
ezCompany
5%
๐ณ๐ฑ
@idebr
Affinity Digital Tech Ltd
5%
๐ฌ๐ง
@somersoft
SeeD EM
5%
๐ต๐ช
@alyaj2a
Third and Grove
4%
๐บ๐ธ
@jds1
Oomph, Inc.
3%
๐บ๐ธ
@ben.hamelin
๐บ๐ธ
@pfrilling
Jarltech Europe GmbH
3%
๐ฉ๐ช
@mkalkbrenner
DICTU
3%
๐ณ๐ฑ
@groendijk
Blue Oak Interactive
2%
๐บ๐ธ
@andyg5000
+18
and 18 other organisations
Fame Helsinki
๐ซ๐ฎ
@sokru
Chromatic
๐บ๐ธ
@apotek
Redfin Solutions, LLC
๐บ๐ธ
@leslieg
Chronos Interactive Media
๐บ๐ธ
@dabblela
Bluehorn Digital
๐บ๐ธ
@mglaman
Numiko
@joshhytr
United Nations
๐ฉ๐ช
@berliner
Drupal Ukraine Community
๐บ๐ฆ
@eugene.brit
State Library of New South Wales
๐ฆ๐บ
@geoffreyr
QED42
๐ฎ๐ณ
@rahulrasgon
Cyber-Duck
๐ฌ๐ง
@Alina Basarabeanu
Attico International
@yauheni
Zoocha
๐ง๐ท
@PabloNicolas
Acquia
๐ฎ๐ณ
@ankitv18
๐ฌ๐ง
@mcdruid
๐บ๐ธ
@mglaman
Investis Digital
๐บ๐ฆ
@eugene.brit
iO
๐ณ๐ฑ
@idebr
Brewed Up
๐บ๐ธ
@mglaman
Somersoft
๐ฌ๐ง
@somersoft
and 11 individuals
( 36% )
๐ช๐ธ
@bmunslow
๐ฌ๐ง
@dahousecat
๐บ๐ธ
@damienmckenna
๐ฆ๐บ
@dpi
๐จ๐ฆ
@gapple
๐ฎ๐น
@apaderno
๐ท๐บ
@shra
๐ฌ๐ง
@littlepixiez
๐ท๐บ
@a.kovrigin
๐ฎ๐ณ
@hetalsagar
๐จ๐ฆ
@No Sssweat
Follow
Sign in to follow projects
Merge Requests
More
!51
Issue #3541096: Remove the term whitelist* from the module
Open
๐ฌ๐ง
United Kingdom
the_g_bomb
updated
1 day ago
!50
Issue #3537083: cspell issues reported in pipeline
Open
๐ฌ๐ง
United Kingdom
the_g_bomb
updated
1 day ago
!19
Change Feature Policy to Permissions Policy (D8/D9)
Open
Show issue
๐ฎ๐ณ
India
Lokeshwari
updated
24 days ago
!49
Added COOP header support
Open
๐บ๐ธ
United States
pfrilling
updated
28 days ago
!48
Implement the script-src-attr policy
Open
Show issue
๐บ๐ธ
United States
andyg5000
updated
2 months ago
!47
Resolve #3521718 "Add support for form-action directive"
Open
Unnamed author
updated
3 months ago
More Merge Requests
Issues
๐
Remove the term whitelist* from the module
Active
Code
Created
1 day ago
v2.0
๐ฌ๐ง
United Kingdom
the_g_bomb
about 20 hours ago
๐
cspell issues reported in pipeline
Active
Code
Created
24 days ago
v2.0
๐ณ๐ฑ
Netherlands
idebr
1 day ago
โจ
Change Feature Policy to Permissions Policy (D8/D9)
Needs review
Code
Created
over 4 years ago
v2.0
๐ต๐น
Portugal
rfmarcelino
24 days ago
โจ
Add support for the Cross-Origin-Opener-Policy (COOP) header
Active
Code
Created
28 days ago
v2.0
๐บ๐ธ
United States
pfrilling
28 days ago
โจ
Implement the script-src-attr policy
Needs review
Code
Created
over 3 years ago
v2.0
๐ง๐ท
Brazil
barone
2 months ago
โจ
Support for configuring script-src-elem
Active
Code
Created
5 months ago
v2.0
๐บ๐ธ
United States
apotek
2 months ago
โจ
Need to exclude admin path from applying the policies
Active
Code
Created
over 1 year ago
v2.0
๐ป๐ณ
Vietnam
tm01xx
3 months ago
๐
Breaks sitemap.xml when JS +CSS + Noscript protection is enabled
Active
Code
Created
about 4 years ago
v2.0
๐ญ๐บ
Hungary
asrob
3 months ago
๐
CSS fails, if default-src "self" configured
Active
Code
Created
3 months ago
v2.0
๐ฉ๐ช
Germany
drupalbubb
3 months ago
๐ฌ
Offering to maintain Security Kit
Active
Miscellaneous
Created
over 2 years ago
v2.0
๐ฎ๐ณ
India
rajeshreeputra
3 months ago
โจ
Extend length of src fields
Needs review
Code
Created
over 4 years ago
v2.0
๐ท๐ธ
Serbia
milovan
3 months ago
โจ
Add support for form-action directive
Needs work
Code
Created
4 months ago
v2.0
๐ฎ๐ฑ
Israel
albert van kiel
3 months ago
โจ
Add support for form-action directive
Closed: duplicate
Code
Created
4 months ago
v2.0
๐ฎ๐ฑ
Israel
albert van kiel
3 months ago
๐
default-src has wrong description
Needs work
Documentation
Created
over 4 years ago
v2.0
๐ฆ๐บ
Australia
marji
6 months ago
๐
Avoid using document.write('<!--');
Needs work
Code
Created
over 4 years ago
v1.2
๐ท๐บ
Russia
kostyashupenko
6 months ago
๐ฌ
How to add all google tlds for CSP
Active
User interface
Created
about 3 years ago
v2.0
๐บ๐ธ
United States
justclint
6 months ago
๐ฌ
CSP: Directive script-src-elem violated with googletagmanager
Needs work
Code
Created
over 4 years ago
v2.0
๐ฎ๐ณ
India
sivaprasadc
6 months ago
๐ฌ
Google URL's are blocked.
Active
Miscellaneous
Created
over 1 year ago
v2.0
๐ฎ๐ณ
India
suresh prabhu parkala
6 months ago
โจ
Permissions Policy Support
RTBC
Miscellaneous
Created
over 4 years ago
v2.0
๐ฆ๐น
Austria
gr4phic3r
7 months ago
โจ
Change Feature Policy to Permissions Policy
Closed: won't fix
Code
Created
almost 5 years ago
v1.11
๐ฎ๐ณ
India
Souvik Pal
7 months ago
๐
Seckit doesnยดt work for Images, CSS, JS
Active
Code
Created
7 months ago
v2.0
๐ฆ๐น
Austria
gr4phic3r
7 months ago
๐
Seckit seckitGetJsCssNoscriptCode hijacks js aggregation files.
Active
Code
Created
over 1 year ago
v2.0
๐บ๐ฆ
Ukraine
bahbka
8 months ago
๐ฌ
/report-csp-violation throwing an error
Active
Miscellaneous
Created
8 months ago
v2.0
๐บ๐ธ
United States
duckydan
8 months ago
โจ
Implement a "semi automatic" Nonce settings
Needs review
Miscellaneous
Created
almost 4 years ago
v2.0
๐ง๐ท
Brazil
barone
8 months ago
โจ
"Directive style-src-elem violated."
Active
Code
Created
almost 5 years ago
v1.0
๐บ๐ธ
United States
damienmckenna
9 months ago
โจ
Allow certain paths to be excluded from the Origin check (patch included)
Active
Code
Created
over 4 years ago
v2.0
๐ฌ๐ง
United Kingdom
andy tawse
9 months ago
โจ
Add worker-src
Needs review
Code
Created
about 3 years ago
v1.0
๐ฌ๐ง
United Kingdom
dahousecat
9 months ago
โจ
Dispatch an event when there is a CSP violation
Active
Code
Created
9 months ago
v2.0
๐บ๐ธ
United States
dabblela
9 months ago
โจ
Add worker-src
Active
Code
Created
over 1 year ago
v2.0
๐ฌ๐ง
United Kingdom
dahousecat
10 months ago
โจ
Add form-action directive
Needs review
Code
Created
about 4 years ago
v2.0
๐ฌ๐ง
United Kingdom
Dubs
10 months ago
๐
Drupal calls should be avoided in classes, use dependency injection instead
Active
Code
Created
almost 2 years ago
v2.0
๐ง๐ท
Brazil
PabloNicolas
10 months ago
๐
Multiple html lines of seckitGetJsCssNoscriptCode function create issue when js aggregate and minify html is on
Active
Code
Created
11 months ago
v2.0
๐ฎ๐ณ
India
hetalsagar
10 months ago
๐
Missing container invalidation update from issue modifying services
Active
Code
Created
12 months ago
v2.0
๐ฆ๐บ
Australia
prussobcm
10 months ago
๐
The base-uri policy is missing
Needs review
Code
Created
over 5 years ago
v2.0
๐ง๐ช
Belgium
cubeinspire
11 months ago
๐
Clickjacking CSS protection hides content when site is embed inside an iframe, even if frame-ancestors is set
Active
Code
Created
over 1 year ago
v2.0
๐ช๐ธ
Spain
jsbalsera
11 months ago
๐ฌ
SA-CONTRIB-2024-039 Clarification?
Fixed
Code
Created
11 months ago
v2.0
๐บ๐ธ
United States
kruser
11 months ago
โจ
Provide hook_seckit_options_alter() D8
Needs review
Code
Created
over 8 years ago
v2.0
๐ท๐บ
Russia
ogggg
11 months ago
๐
Set 2.x as default branch
Fixed
Code
Created
12 months ago
v2.0
๐ฉ๐ช
Germany
mkalkbrenner
11 months ago
๐
Update summary on project page for compatibility with Project Browser
Active
Miscellaneous
Created
11 months ago
v2.0
๐บ๐ธ
United States
leslieg
11 months ago
๐
Update logo for compatibility with Project Browser
Active
Miscellaneous
Created
11 months ago
v2.0
๐บ๐ธ
United States
leslieg
11 months ago
๐
Enabling "Enable JavaScript + CSS + Noscript protection" causes invalid HTML
Needs work
Code
Created
about 6 years ago
v2.0
๐บ๐ธ
United States
averagejoe3000
11 months ago
๐
php error
Closed: duplicate
Code
Created
11 months ago
v2.0
๐ฉ๐ช
Germany
ngruendel
11 months ago
๐
Modernize services: Add autowiring aliases, use autoconfigure, etc
Needs review
Code
Created
11 months ago
v2.0
๐ฆ๐บ
Australia
dpi
11 months ago
๐
Multiple html lines of seckitGetJsCssNoscriptCode function create issue when js aggregate and minify html is on
Active
Code
Created
11 months ago
v2.0
๐ฎ๐ณ
India
hetalsagar
11 months ago
๐
D11 release for seckit
Fixed
Code
Created
12 months ago
v2.0
๐ฌ๐ง
United Kingdom
mcdruid
11 months ago
๐
Coding Standard Issues
Fixed
Code
Created
11 months ago
v2.0
๐ต๐ช
Peru
alyaj2a
11 months ago
๐
Add testing of report-csp-violation
Fixed
Code
Created
12 months ago
v2.0
๐ฌ๐ง
United Kingdom
mcdruid
11 months ago
โจ
Silent mode for CSP reporting
Active
Code
Created
over 3 years ago
v2.0
๐บ๐ฆ
Ukraine
ksemihin
12 months ago
โจ
Update CSP directives
Needs review
Code
Created
almost 8 years ago
v2.0
๐บ๐ธ
United States
Mojiferous
12 months ago
โจ
Store CSP sources as a list of values on multiple lines to increase manageability and prevent merge conflicts
Needs review
Code
Created
almost 2 years ago
v2.0
๐ง๐ช
Belgium
Dozz
12 months ago
๐
Automated Drupal 11 compatibility fixes for seckit
Closed: duplicate
Code
Created
about 1 year ago
v2.0
project update bot
12 months ago
๐
Automated Drupal 11 compatibility fixes for seckit
Fixed
Code
Created
over 1 year ago
v2.0
project update bot
about 1 year ago
๐
Fix validate pipeline
Fixed
Code
Created
about 1 year ago
v2.0
๐ฎ๐ณ
India
ankitv18
about 1 year ago
๐
Add Gitlab CI
Fixed
Code
Created
over 1 year ago
v2.0
๐ฎ๐ณ
India
deepakkm
about 1 year ago
๐
No values in X-XSS-Protection Header select box
Fixed
User interface
Created
about 7 years ago
v2.0
rajithkumark
about 1 year ago
๐
Drupal 9.1 Deprecated Code Report
RTBC
Code
Created
over 4 years ago
v2.0
๐ฌ๐ท
Greece
suzymasri
about 1 year ago
๐ฌ
Question about HSTS max-age
Active
Miscellaneous
Created
over 1 year ago
v2.0
๐ณ๐ฑ
Netherlands
RobBNL
about 1 year ago
โจ
Text fields not big enough
Fixed
Code
Created
over 2 years ago
v2.0
๐ช๐ธ
Spain
penyaskito
over 1 year ago
๐
Add phpcs and drupal-check fixes
Needs review
Code
Created
over 3 years ago
v2.0
๐ฎ๐ณ
India
bendale
over 1 year ago
โจ
Store each CSP rule on a seperate line in config
Active
Code
Created
over 1 year ago
v2.0
๐ฌ๐ง
United Kingdom
dahousecat
over 1 year ago
๐
Support flood control for CSP violation reports
Needs work
Code
Created
over 9 years ago
v1.0
๐ณ๐ฟ
New Zealand
jweowu
over 1 year ago
๐
t() calls should be avoided in classes.
Needs review
Code
Created
over 1 year ago
v2.0
๐ฎ๐ณ
India
chaitanyadessai
over 1 year ago
๐
\Drupal calls should be avoided in classes, use dependency injection instead
Needs review
Code
Created
over 1 year ago
v2.0
๐ฎ๐ณ
India
chaitanyadessai
over 1 year ago
๐
Add LICENSE.txt file
Closed: works as designed
Code
Created
over 1 year ago
v2.0
๐ท๐ด
Romania
ciprian.stavovei
over 1 year ago
๐ฌ
Backdrop CMS Port?
Fixed
Miscellaneous
Created
over 3 years ago
v1.0
rbargerhuff
over 1 year ago
๐
Misleading recommendation for CSP directive "frame-src"
RTBC
Documentation
Created
over 2 years ago
v1.0
๐จ๐ฆ
Canada
fengtan
over 1 year ago
๐
Fix D7 Forms API syntax
RTBC
Code
Created
about 2 years ago
v1.0
๐จ๐ฆ
Canada
mvc
over 1 year ago
โจ
Add support for setting referer policy from route in issue #3027122
Needs work
Code
Created
about 4 years ago
v2.0
๐ฆ๐บ
Australia
gordon
over 1 year ago
๐ฌ
Lottie files / base64 encoding
Active
Miscellaneous
Created
over 2 years ago
v1.11
๐บ๐ธ
United States
Mile3
over 1 year ago
๐ฌ
Uncaught DOMException: Permission denied to access property "hostname" on cross-origin object
Active
Code
Created
almost 2 years ago
v2.0
๐ช๐ธ
Spain
gpollner
over 1 year ago
๐
Add a reference to csp_log in documentation
Active
Documentation
Created
over 1 year ago
v2.0
๐ง๐ช
Belgium
daften
over 1 year ago
๐ฌ
How to set httpOnly flag on cookies?
Needs review
Documentation
Created
almost 2 years ago
v2.0
๐ช๐ธ
Spain
uridrupal
almost 2 years ago
๐ฌ
Vulnerability Scan reported 150206 - Content-Security-Policy Not Implemented
Closed: won't fix
User interface
Created
almost 2 years ago
v2.0
๐ฎ๐ณ
India
ankitasharma13
almost 2 years ago
๐
Replace README.txt with README.md
Fixed
Documentation
Created
almost 3 years ago
v2.0
๐ฎ๐ณ
India
Manoj Raj.R
almost 2 years ago
๐
Fix the warnings/errors reported by PHP_CodeSniffer
Fixed
Code
Created
over 5 years ago
v2.0
๐ณ๐ฟ
New Zealand
xurizaemon
almost 2 years ago
๐
Update source url in composer.json
Fixed
Code
Created
almost 5 years ago
v2.0
๐ณ๐ด
Norway
neslee canil pinto
about 2 years ago
๐
License "GPL-2.0+" is a deprecated SPDX license identifier
Fixed
Code
Created
about 5 years ago
v2.0
๐ฎ๐ณ
India
harishh
about 2 years ago
๐
JS/CSS/Noscript code gets added twice to head on 404/403 pages
Fixed
Code
Created
over 5 years ago
v2.0
๐บ๐ธ
United States
averagejoe3000
about 2 years ago
๐
Minor Typo in SecKitEventSubscriber.php File
Fixed
Code
Created
over 4 years ago
v2.0
๐ฎ๐ณ
India
sivaprasadc
about 2 years ago
๐
Drupal CSS Standards
Fixed
Code
Created
over 2 years ago
v1.0
๐บ๐ธ
United States
bygeoffthompson
about 2 years ago
๐
seckit/listener library incorrectly defined
Fixed
Code
Created
about 2 years ago
v2.0
๐ฌ๐ง
United Kingdom
mcdruid
about 2 years ago
๐
style-src key missing in seckit.settings.yml
Fixed
Code
Created
about 2 years ago
v2.0
๐ฆ๐บ
Australia
jnlar
about 2 years ago
๐
report-uri is deprecated
Active
Code
Created
over 2 years ago
v2.0
๐ณ๐ฑ
Netherlands
LaurentD
about 2 years ago
โจ
Remove Generator meta tag from output
Closed: works as designed
Code
Created
almost 9 years ago
v2.0
๐ฆ๐บ
Australia
chop
about 2 years ago
๐
Illegal choice 0 in Configure element.
Closed: duplicate
Code
Created
about 5 years ago
v2.0
๐ฎ๐ณ
India
vijay.mayilsamy
about 2 years ago
๐
Add textarea type to script-src field
Closed: duplicate
Code
Created
about 3 years ago
v2.0
๐ฎ๐ณ
India
ashetkar
about 2 years ago
โจ
Allow entering more content in CSP fields
Closed: duplicate
Code
Created
almost 3 years ago
v2.0
๐จ๐ฆ
Canada
dylan donkersgoed
about 2 years ago
โจ
Extend length of feature policy field
Closed: duplicate
Code
Created
almost 6 years ago
v2.0
๐ณ๐ฑ
Netherlands
dennis_meuwissen
about 2 years ago
โจ
Add support for form-action CSP directive
Active
Code
Created
over 7 years ago
v1.0
๐บ๐ธ
United States
milodesc
about 2 years ago
โจ
Longer fields to support Google TLD's
Closed: duplicate
Code
Created
about 2 years ago
v1.0
๐จ๐ฆ
Canada
djac
about 2 years ago
๐
Trailing slash on void elements has no effect and interacts badly with unquoted attribute values
Closed: duplicate
Code
Created
about 2 years ago
v2.0
fromme
about 2 years ago
๐
Remove type="text/javascript" from <script> tag
Needs review
Code
Created
about 2 years ago
v2.0
fromme
about 2 years ago
๐
Deprecated Feature Used Expect-CT header
Needs review
Code
Created
almost 3 years ago
v2.0
l_nava
about 2 years ago
๐
Expect-CT is deprecated; provide a warning or remove
Closed: duplicate
Code
Created
over 2 years ago
v2.0
๐ฏ๐ต
Japan
ptmkenny
about 2 years ago
โจ
Text fields not big enough
Fixed
Code
Created
about 6 years ago
v1.0
๐ฌ๐ง
United Kingdom
dunx
over 2 years ago
๐
Skip report-uri processing if value is empty
Fixed
Code
Created
over 5 years ago
v1.0
๐บ๐ธ
United States
ron_s
over 2 years ago
โจ
Add support for feature-policy header
Fixed
Code
Created
about 7 years ago
v1.0
๐ฆ๐บ
Australia
adammalone
over 2 years ago
๐ฑ
Deprecate / Remove Content Security Policy configuration in favour of Content Security Policy module
Active
Code
Created
about 7 years ago
v1.0
๐จ๐ฆ
Canada
gapple
over 2 years ago
๐
Missing Strict-Transport-Security header
Closed: works as designed
Code
Created
over 6 years ago
v1.0
๐จ๐ญ
Switzerland
handkerchief
over 2 years ago
๐
ALLOW-FROM directive in x-frame-options is obsolete
Active
Code
Created
over 2 years ago
v2.0
๐ฌ๐ง
United Kingdom
oldspot
over 2 years ago
contrib
.social
Blog
FAQ
Discussions
Production build 0.71.5
2024