Skip to content

'unsafe-inline' in style-src directive capping score to A when it should probably not #100

@joelbourbon

Description

@joelbourbon

Hi,

I recently reworked my CSP rules to try and get an A+ using your tooling.
I adjusted my CSP rules using the Google Tooling --> https://csp-evaluator.withgoogle.com/

According to their evaluation, having 'unsafe-inline' in style-src directive is not an issue.

Would me nice to have both your tools agree on the severity of this ;)

Thanks,

image

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type
    No fields configured for issues without a type.

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions