-
Notifications
You must be signed in to change notification settings - Fork 1.1k
Run hsts-prune and fix impacted rulesets #15387
Conversation
Closing temporarily to fix #15213 |
@@ -40,7 +40,6 @@ | |||
--> | |||
<ruleset name="Financial Times (partial)"> | |||
<target host="ft.com" /> | |||
<target host="www.ft.com" /> |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
One question: Why only www.ft.com is removed when ft.com itself is preloaded?
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
It's missing the includeSubDomains
directive.
See https://github.com/EFForg/https-everywhere/blob/master/CONTRIBUTING.md#hsts-preloaded-rules and https://securityheaders.com/?q=https%3A%2F%2Fft.com%2F
@@ -56,7 +56,6 @@ | |||
<target host="packaging.python.org" /> | |||
<target host="packages.python.org" /> | |||
<target host="pl.python.org" /> | |||
<target host="pypi.python.org" /> |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
same question for here and a couple of other places
Thank you! |
No description provided.