web.archive.org/web/20170602232026/http:/githubengineering.com/githubs-csp-journey

Preview meta tags from the web.archive.org website.

Linked Hostnames

1

Search Engine Appearance

Google

https://web.archive.org/web/20170602232026/http:/githubengineering.com/githubs-csp-journey

GitHub’s CSP journey

We shipped subresource integrity a few months back to reduce the risk of a compromised CDN serving malicious JavaScript. That is a big win, but does not address related content injection issues that may exist on GitHub.com itself. We have been tackling this side of the problem over the past few years and thought it would be fun, and hopefully useful, to share what we have been up to.



Bing

GitHub’s CSP journey

https://web.archive.org/web/20170602232026/http:/githubengineering.com/githubs-csp-journey

We shipped subresource integrity a few months back to reduce the risk of a compromised CDN serving malicious JavaScript. That is a big win, but does not address related content injection issues that may exist on GitHub.com itself. We have been tackling this side of the problem over the past few years and thought it would be fun, and hopefully useful, to share what we have been up to.



DuckDuckGo

https://web.archive.org/web/20170602232026/http:/githubengineering.com/githubs-csp-journey

GitHub’s CSP journey

We shipped subresource integrity a few months back to reduce the risk of a compromised CDN serving malicious JavaScript. That is a big win, but does not address related content injection issues that may exist on GitHub.com itself. We have been tackling this side of the problem over the past few years and thought it would be fun, and hopefully useful, to share what we have been up to.

  • General Meta Tags

    8
    • title
      GitHub’s CSP journey - GitHub Engineering
    • content-type
      text/html; charset=utf-8
    • viewport
      width=device-width, initial-scale=1.0, maximum-scale=1
    • octolytics-app-id
      internal-engineering-blog
    • description
      We shipped subresource integrity a few months back to reduce the risk of a compromised CDN serving malicious JavaScript. That is a big win, but does not address related content injection issues that may exist on GitHub.com itself. We have been tackling this side of the problem over the past few years and thought it would be fun, and hopefully useful, to share what we have been up to.
  • Open Graph Meta Tags

    5
    • og:title
      GitHub’s CSP journey
    • og:description
      We shipped subresource integrity a few months back to reduce the risk of a compromised CDN serving malicious JavaScript. That is a big win, but does not address related content injection issues that may exist on GitHub.com itself. We have been tackling this side of the problem over the past few years and thought it would be fun, and hopefully useful, to share what we have been up to.
    • og:url
      https://web.archive.org/web/20170316065128/https://githubengineering.com/githubs-csp-journey/
    • og:site_name
      GitHub Engineering
    • og:type
      article
  • Twitter Meta Tags

    3
    • twitter:card
      summary
    • twitter:site
      @GitHubEng
    • twitter:creator
      @patricktoomey
  • Link Tags

    12
    • alternate
      https://web.archive.org/web/20170316065128/https://githubengineering.com/atom.xml
    • canonical
      https://web.archive.org/web/20170316065128/https://githubengineering.com/githubs-csp-journey/
    • profile
      http://gmpg.org/xfn/11
    • shortcut icon
      /web/20170316065128im_/https://githubengineering.com/images/favicon.ico
    • stylesheet
      https://web-static.archive.org/_static/css/banner-styles.css?v=1B2M2Y8A

Links

32