Skip to content

Releases: adopted-ember-addons/ember-cli-content-security-policy

Release 2.0.3

02 Jan 16:14
Compare
Choose a tag to compare

🐛 Bug Fix

Committers: 1

Release 2.0.2

20 Dec 11:51
Compare
Choose a tag to compare

🐛 Bug Fix

  • #271 Fastboot instance initializer throws if reportOnly config is false (@JoeyBG)

Committers: 1

Release 2.0.1

13 Dec 08:01
Compare
Choose a tag to compare

🐛 Bug Fix

🏠 Internal

  • #272 use a recent fastboot version in tests (@jelhan)

Committers: 2

Release 2.0.0

12 Nov 15:27
Compare
Choose a tag to compare

v2.0.0 is the same as last pre-release (v2.0.0-5). It does not include any additional changes.

Release 2.0.0-5

28 Oct 23:10
Compare
Choose a tag to compare
Release 2.0.0-5 Pre-release
Pre-release

💥 Breaking Change

🐛 Bug Fix

  • #249 use environment from appConfig instead of deriving it ourselves (@jelhan)

📝 Documentation

🏠 Internal

Committers: 3

Release 2.0.0-4

06 May 14:25
Compare
Choose a tag to compare
Release 2.0.0-4 Pre-release
Pre-release

🐛 Bug Fix

  • #201 Support Ember CLI >= 3.26.0 and match injected script element by all supported Ember CLI versions with same RegExp (@snewcomer)

Committers: 1

Release 2.0.0-3

16 Apr 18:55
Compare
Choose a tag to compare
Release 2.0.0-3 Pre-release
Pre-release

🐛 Bug Fix

📝 Documentation

  • #195 Fix typo form-ancestors -> frame-ancestors in readme (@nicomihalich)
  • #188 remove duplicated entry in config interface documentation (@jelhan)

Committers: 4

Release 2.0.0-2

09 Jan 17:43
Compare
Choose a tag to compare
Release 2.0.0-2 Pre-release
Pre-release

highlightjs/highlight.js#2877

v2.0.0-2 (2021-01-09)

🐛 Bug Fix

  • #172 remove report-uri from policy delivered through meta (@jelhan)
  • #152 append frame-src config in test mode (@chbonser)
  • #158 Support live reload and add optional debug log (@jelhan)
  • #156 Remove existing 'none' keyword when applying to source list (@jelhan)

📝 Documentation

🏠 Internal

Committers: 4

Release 2.0.0-1

15 Apr 07:11
Compare
Choose a tag to compare
Release 2.0.0-1 Pre-release
Pre-release

🐛 Bug Fix

  • #143 development server should use config for test if serving /tests/ (@jelhan)

Committers: 1

Release 2.0.0-0

13 Apr 09:24
Compare
Choose a tag to compare
Release 2.0.0-0 Pre-release
Pre-release

This releases cumulates the work of 1 1/2 years. Main changes are:

  • It allows projects to test for CSP compliance.
  • It integrates with Ember FastBoot to set CSP header in FastBoot App Server.
  • It moves it's own configuration to config/content-security-policy.js and avoids injecting unnecessary configuration into run-time.
  • It introduces tests for it's own implementation to avoid regressions and increase stability.

The existing configuration syntax in config/environment.js is still supported but deprecated. You are recommended to migrate your configuration to config/content-security-policy.js as soon as possible. The deprecation guide contains migration instructions.

💥 Breaking Change

  • #135 Do not set X-Content-Security-Policy header (@jelhan)
  • #107 Ensure csp-headers command emits to standard out (to allow for piping into other programs) (@Exelord)
  • #130 Drop Node 8, 9, and 11 support. (@rwjblue)
  • #87 Drop Ember CLI < 2.13 and Node 4 support (@loganrosen)

🚀 Enhancement

  • #91 Add ability to fail application / addon tests when a CSP violation is detected. (@jelhan)
  • #113 Set CSP header in FastBoot (@jelhan)
  • #104 Move config to config/content-security-policy.js (@jelhan)
    Previous Iterations:
    • #94 Refactor configuration to use ember-cli-content-security-policy (instead of contentSecurityPolicy) (@jelhan)
    • #97 Allow configuration to be specified in ember-cli-build.js (@jelhan)
  • #101 Avoid merging policies in build time configuration (@jelhan)
  • #84 Add option to output raw CSP (Closes #81) (@YoranBrondsema)
  • #121 Inject runtime config only if needed (if FastBoot dependency exists) (@jelhan)

🐛 Bug Fix

  • #122 Consistent test results regardless of environment (@jelhan)
  • #134 Prevent unnecessary meta + reportOnly warning (@reidab)
  • #136 Do not override existing CSP headers in fastboot (@jelhan)
  • #129 Set status-code to 204 (no content) (@sandstrom)
  • #128 Don't add nonce to script-src when it already contains 'unsafe-inline' (@joukevandermaas)
  • #109 Fix support for --live-reload-host option (@jelhan)
  • #107 Ensure csp-headers command emits to standard out (to allow for piping into other programs) (@Exelord)
  • #96 Fix inconsistency between meta element and HTTP header regarding live reload support (@jelhan)
  • #95 Remove trailing whitespace from generated CSP string (@jelhan)

📝 Documentation

🏠 Internal

Committers: 8