Skip to content

Preload HSTS for nushell.sh #928

@lgarron

Description

@lgarron

https://hstspreload.org/ is using HTTPS, but is not using the full protection of HSTS preloading:

If the subdomains are not used for any private infrastructure I would recommend using the following header:

Strict-Transport-Security: max-age=63072000; includeSubDomains; preload

The site seems to be hosted with GitHub Pages. If you'd like to set this header there's no UI for it in GitHub (yet), but I believe @yoannchaudet should be able to enable it.

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions