mozilla / http-observatory

Mozilla HTTP Observatory
https://observatory.mozilla.org/
Mozilla Public License 2.0
1.84k stars 168 forks source link

feat: deprecate x-xss-protection header #520

Closed LeoMcA closed 7 months ago

LeoMcA commented 7 months ago

update all scoring to 0, other than -5 for an invalid header, to match the current infosec recommendations: https://infosec.mozilla.org/guidelines/web_security.html#x-xss-protection