Skip to content

Commit

Permalink
Update 0x50-V50-Web-Frontend-Security.md
Browse files Browse the repository at this point in the history
improving section text
  • Loading branch information
jmanico committed Feb 13, 2025
1 parent 9d52191 commit 2a30edf
Showing 1 changed file with 2 additions and 2 deletions.
4 changes: 2 additions & 2 deletions 5.0/en/0x50-V50-Web-Frontend-Security.md
Original file line number Diff line number Diff line change
Expand Up @@ -82,15 +82,15 @@ Rendering content or functionality in an incorrect context can lead to a wide va

## V50.7 External Resource Integrity

Hosting content on third-party sites can lead to malicious content modification and supply chain attacks.
Subresource integrity allows for safe hosting of content on third-party sites.

| # | Description | Level | CWE |
| :---: | :--- | :---: | :---: |
| **50.7.1** | [MODIFIED, MOVED FROM 14.2.3] Verify that if client-side assets, such as JavaScript libraries, CSS or web fonts, are hosted externally on a Content Delivery Network (CDN) or external provider, Subresource Integrity (SRI) is used to validate the integrity of the asset. | 1 | 829 |

## V50.8 Other Browser Security Considerations

Client-side security requires enforcing security behavior based on restricting automatic redirections, mandating HSTS preloading, and using other modern browser security features.
Client-side security controls for redirects, HTTPS enforcement, and safe use of modern browser security features.

| # | Description | Level | CWE |
| :---: | :--- | :---: | :---: |
Expand Down

0 comments on commit 2a30edf

Please # to comment.