Closed
Bug 1960652
Opened 1 year ago
Closed 1 year ago
Ship the strict script-src CSP for browser.xhtml
Categories
(Core :: DOM: Security, task)
Core
DOM: Security
Tracking
()
RESOLVED
FIXED
139 Branch
| Tracking | Status | |
|---|---|---|
| firefox139 | --- | fixed |
People
(Reporter: tschuster, Assigned: tschuster)
References
(Blocks 2 open bugs)
Details
(Whiteboard: [domsecurity-active])
Attachments
(1 file)
The Nightly telemetry just shows the usual userChromeJS failures for eval as well. I would like to ship this in 139, so we have the option to land bug 1960648 during 140 and not overlap with this change.
| Assignee | ||
Comment 1•1 year ago
|
||
Updated•1 year ago
|
Severity: -- → N/A
Whiteboard: [domsecurity-active]
Pushed by tschuster@mozilla.com:
https://hg.mozilla.org/integration/autoland/rev/666f48429f09
Ship the strict script-src CSP for browser.xhtml. r=firefox-desktop-core-reviewers ,mossop
Comment 3•1 year ago
|
||
| bugherder | ||
Status: NEW → RESOLVED
Closed: 1 year ago
status-firefox139:
--- → fixed
Resolution: --- → FIXED
Target Milestone: --- → 139 Branch
Updated•1 year ago
|
QA Whiteboard: [qa-triage-done-c140/b139]
You need to log in
before you can comment on or make changes to this bug.
Description
•