Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Update 0x20-V12-Files-Resources.md #2223

Merged
merged 1 commit into from
Nov 5, 2024
Merged

Conversation

ImanSharaf
Copy link
Collaborator

@ImanSharaf ImanSharaf commented Nov 5, 2024

This PR addresses #1471

@tghosth tghosth merged commit e1c5a64 into OWASP:master Nov 5, 2024
6 checks passed
elarlang added a commit that referenced this pull request Nov 5, 2024
removed requirement:
V12.3.6 Verify that the application does not include and execute functionality from untrusted sources, such as unverified content distribution networks, JavaScript libraries, node npm libraries, or server-side DLLs. | | ✓ | ✓ | 829 |

With duplicate of we should point to v4.0.3 requirements:
* V14.2.3 Verify that if application assets, such as JavaScript libraries, CSS or web fonts, are hosted externally on a Content Delivery Network (CDN) or external provider, Subresource Integrity (SRI) is used to validate the integrity of the asset.
* V14.2.4 Verify that third party components come from pre-defined, trusted and continually maintained repositories.
@elarlang elarlang mentioned this pull request Nov 5, 2024
tghosth pushed a commit that referenced this pull request Nov 5, 2024
removed requirement:
V12.3.6 Verify that the application does not include and execute functionality from untrusted sources, such as unverified content distribution networks, JavaScript libraries, node npm libraries, or server-side DLLs. | | ✓ | ✓ | 829 |

With duplicate of we should point to v4.0.3 requirements:
* V14.2.3 Verify that if application assets, such as JavaScript libraries, CSS or web fonts, are hosted externally on a Content Delivery Network (CDN) or external provider, Subresource Integrity (SRI) is used to validate the integrity of the asset.
* V14.2.4 Verify that third party components come from pre-defined, trusted and continually maintained repositories.
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

3 participants