{"_id":"@arachnodex/job-csp-report","_rev":"2-03469a7a15d04d5b1d81b1f0b871e17f","name":"@arachnodex/job-csp-report","dist-tags":{"latest":"1.0.1"},"versions":{"1.0.0":{"name":"@arachnodex/job-csp-report","version":"1.0.0","keywords":["arachnodex","crawler","csp","content security policy","security headers"],"author":{"name":"Rick Kukiela","email":"rick@belniakmedia.com"},"license":"Apache-2.0","_id":"@arachnodex/job-csp-report@1.0.0","maintainers":[{"name":"rickkukiela","email":"rick@belniakmedia.com"}],"homepage":"https://github.com/Arachnodex/arachnodex#readme","bugs":{"url":"https://github.com/Arachnodex/arachnodex/issues"},"dist":{"shasum":"8170ac40418f89a7da1b25a4a455fdcf41df3149","tarball":"https://registry.npmjs.org/@arachnodex/job-csp-report/-/job-csp-report-1.0.0.tgz","fileCount":9,"integrity":"sha512-lhveHT7nP0ADh1GvCWC8LDHz0f21FIcwdBEFRIRwRcZCPO/o2NVYgIXjXD/MpZ2qnpXd9lH4mBaDGIzF0FjcEw==","signatures":[{"sig":"MEUCIQCbHuyxf8fUJtS4DrSYPR0TzHFR62soxK1A7ctR2MwJ9wIgJp24bOLKDHdxIMC/dxSaMMho7n6mwa/2mC5ZrMeVGU4=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":131759},"main":"bin/index.js","type":"module","types":"types/index.d.ts","engines":{"node":">=22.13.0 <25"},"exports":{".":{"types":"./types/index.d.ts","default":"./bin/index.js","development":"./src/index.ts"},"./config/csp-report.example.json":"./config/csp-report.example.json"},"gitHead":"0e7ce7f80e6454376dee1297aaa6f510dd9b827f","scripts":{"test":"node --conditions=development --import tsx test/*.test.ts","build":"npm run clean:bin && npm run clean:types && esbuild src/index.ts --bundle --platform=node --format=esm --target=node22 --minify --packages=external --outfile=bin/index.js && npm run build:types","clean:bin":"node -e \"const fs=require('node:fs'); fs.rmSync('bin',{recursive:true,force:true}); fs.mkdirSync('bin',{recursive:true});\"","build:types":"tsc -p tsconfig.types.json","clean:types":"node -e \"const fs=require('node:fs'); fs.rmSync('types',{recursive:true,force:true});\""},"_npmUser":{"name":"rickkukiela","email":"rick@belniakmedia.com"},"repository":{"url":"git+https://github.com/Arachnodex/arachnodex.git","type":"git","directory":"packages/job-csp-report"},"_npmVersion":"11.13.0","description":"Arachnodex job for generating Content Security Policy header reports.","directories":{},"_nodeVersion":"24.16.0","dependencies":{"axios":"^1.12.2"},"publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"esbuild":"^0.25.0","typescript":"^5.6.3","@types/node":"^22","@arachnodex/core":"^1.0.7"},"peerDependencies":{"@arachnodex/core":"^1.0.7"},"_npmOperationalInternal":{"tmp":"tmp/job-csp-report_1.0.0_1784824848330_0.5583281339683999","host":"s3://npm-registry-packages-npm-production"}},"1.0.1":{"_id":"@arachnodex/job-csp-report@1.0.1","bugs":{"url":"https://github.com/Arachnodex/arachnodex/issues"},"dist":{"shasum":"33964c3ae958f71e10807db941b500355cf108d6","tarball":"https://registry.npmjs.org/@arachnodex/job-csp-report/-/job-csp-report-1.0.1.tgz","fileCount":9,"integrity":"sha512-0w8BeL9/UaLxW9SJAzfzNpZzgwERTys3iJMa++V9JAttb3iEDSJziQtpfsDP9q6Dl8LbKSXiXqCrAOJLsIflgw==","signatures":[{"sig":"MEYCIQCvJ13EdWzzBwmv4pPGHdy2uliRyGHJJKuc7RB6lCjldgIhAKSmYW+fNAfj1O69fzFYVjS3IzEHn/CbeyqP8qYRFJKJ","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"},{"keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U","sig":"MEUCIQDUQP6+HmmRrNbSgTUw/RBsHeDsgZH+sueSsW+NMqYIFQIgXpAA+5WGT/CsIdO+l//cjeRlYYRJjeYsk6EHwMFmGyk="}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/@arachnodex%2fjob-csp-report@1.0.1","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":131759},"main":"bin/index.js","name":"@arachnodex/job-csp-report","type":"module","types":"types/index.d.ts","author":{"name":"Rick Kukiela","email":"rick@belniakmedia.com"},"engines":{"node":">=22.13.0 <25"},"exports":{".":{"types":"./types/index.d.ts","default":"./bin/index.js","development":"./src/index.ts"},"./config/csp-report.example.json":"./config/csp-report.example.json"},"gitHead":"56d075dd0cd42082f51c6aa5a85d4ebbe373178c","license":"Apache-2.0","scripts":{"test":"node --conditions=development --import tsx test/*.test.ts","build":"npm run clean:bin && npm run clean:types && esbuild src/index.ts --bundle --platform=node --format=esm --target=node22 --minify --packages=external --outfile=bin/index.js && npm run build:types","clean:bin":"node -e \"const fs=require('node:fs'); fs.rmSync('bin',{recursive:true,force:true}); fs.mkdirSync('bin',{recursive:true});\"","build:types":"tsc -p tsconfig.types.json","clean:types":"node -e \"const fs=require('node:fs'); fs.rmSync('types',{recursive:true,force:true});\""},"version":"1.0.1","_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:c033861f-a5ea-4ace-96e6-56ce7c3582f9"}},"homepage":"https://github.com/Arachnodex/arachnodex#readme","keywords":["arachnodex","crawler","csp","content security policy","security headers"],"repository":{"url":"git+https://github.com/Arachnodex/arachnodex.git","type":"git","directory":"packages/job-csp-report"},"_npmVersion":"11.19.1","description":"Arachnodex job for generating Content Security Policy header reports.","directories":{},"maintainers":[{"name":"rickkukiela","email":"rick@belniakmedia.com"}],"_nodeVersion":"24.16.0","dependencies":{"axios":"^1.20.0"},"publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"esbuild":"^0.25.0","typescript":"^5.6.3","@types/node":"^22","@arachnodex/core":"^1.0.7"},"peerDependencies":{"@arachnodex/core":"^1.0.7"},"_npmOperationalInternal":{"host":"s3://npm-registry-packages-npm-production","tmp":"tmp/job-csp-report_1.0.1_1788284508023_0.620444614114656"}}},"time":{"created":"2026-07-23T16:40:48.185Z","modified":"2026-09-01T17:41:48.513Z","1.0.0":"2026-07-23T16:40:48.483Z","1.0.1":"2026-09-01T17:41:48.130Z"},"bugs":{"url":"https://github.com/Arachnodex/arachnodex/issues"},"author":{"name":"Rick Kukiela","email":"rick@belniakmedia.com"},"license":"Apache-2.0","homepage":"https://github.com/Arachnodex/arachnodex#readme","keywords":["arachnodex","crawler","csp","content security policy","security headers"],"repository":{"url":"git+https://github.com/Arachnodex/arachnodex.git","type":"git","directory":"packages/job-csp-report"},"description":"Arachnodex job for generating Content Security Policy header reports.","maintainers":[{"name":"rickkukiela","email":"rick@belniakmedia.com"}],"readme":"# @arachnodex/job-csp-report\n\n> **Beta:** This job is in beta and has not been fully tested. Review all generated directives carefully before deploying them.\n\nGenerate Content Security Policy header directives from observed Arachnodex crawl data.\n\n```bash\nnpm install @arachnodex/job-csp-report\n```\n\nRun it with the Arachnodex crawler:\n\n```bash\narachnodex -j csp-report\n```\n\nBy default the job scans crawled HTML plus same-site CSS and JavaScript bodies, outputs both `Content-Security-Policy-Report-Only` and `Content-Security-Policy`, and formats directives for Apache `mod_headers`.\n\n## Switches\n\n| Switch | Description |\n| --- | --- |\n| `-V`, `--version` | Output the job version and terminate. |\n| `-o <format>`, `--output=<format>` | Output format: `apache`, `nginx`, `lighttpd`, or `raw`. |\n| `--no-nested` | Disable nested same-site CSS/JS scanning. |\n| `--unsafe-inline` | Add `'unsafe-inline'` for observed inline script/style usage. |\n| `-p`, `--prompt` | After the normal report, output copy/paste agent prompts for each warning group. |\n| `-h`, `--help` | Show job help. |\n\n## Notes\n\nThe generated CSP is based on crawl observations. It is a strong starting policy, not proof that every runtime dependency was observed. A crawl with no scanned HTML pages is reported as an alert rather than a clean result.\n\nRelative resource URLs honor the document's `<base href>`. External base URLs are preserved for compatibility and reported as risky. Forms without an explicit action contribute `'self'` to `form-action`. Non-executable script data blocks such as JSON-LD and social metadata URLs are not treated as CSP-loaded resources.\n\nInline script/style/event handler usage is reported as a hardening item. Without `--unsafe-inline`, inline usage is not automatically allowed.\n\n## Config\n\nDefault config:\n\n```json\n{\n  \"emailReportEnabled\": true,\n  \"outputFormat\": \"apache\",\n  \"nested\": true,\n  \"unsafeInline\": false,\n  \"includeReportOnly\": true,\n  \"includeEnforce\": true,\n  \"reportUri\": \"\",\n  \"reportTo\": \"\",\n  \"ignorePatterns\": [],\n  \"additionalSources\": {},\n  \"ignoreSources\": {},\n  \"staticDirectives\": {\n    \"default-src\": [\"'self'\"],\n    \"base-uri\": [\"'self'\"],\n    \"frame-ancestors\": [\"'self'\"]\n  }\n}\n```\n\n| Setting | Type | Default | Description |\n| --- | --- | --- | --- |\n| `emailReportEnabled` | boolean | `true` | Allows this job to contribute its report to configured Arachnodex report email output. |\n| `outputFormat` | string | `\"apache\"` | Header format: `apache`, `nginx`, `lighttpd`, or `raw`. |\n| `nested` | boolean | `true` | Fetch and scan same-site CSS/JS files observed in crawled pages, with up to four nested requests in flight. |\n| `unsafeInline` | boolean | `false` | Add `'unsafe-inline'` to `script-src`/`style-src` when matching inline usage is observed. Inline usage is still reported. |\n| `includeReportOnly` | boolean | `true` | Emit `Content-Security-Policy-Report-Only`. |\n| `includeEnforce` | boolean | `true` | Emit `Content-Security-Policy`. |\n| `reportUri` | string | `\"\"` | Optional `report-uri` CSP directive value. Omitted when empty. |\n| `reportTo` | string | `\"\"` | Optional `report-to` CSP directive value. Omitted when empty. |\n| `ignorePatterns` | string[] | `[]` | Page/document URL regular expressions to exclude from this CSP report. Matching pages are not counted, their HTML resources are ignored, and their same-site nested CSS/JS assets are not queued from that page. Patterns are tested against full URL, path plus query, path, and decoded path forms. |\n| `additionalSources` | object | `{}` | Extra CSP sources keyed by directive, for sources that were not observed but must be allowed. |\n| `ignoreSources` | object | `{}` | Exact CSP sources to omit, keyed by directive or `*`. This also applies to static and automatically added sources, so review removals carefully. |\n| `staticDirectives` | object | default safe directives | Fixed directives included in every generated policy. |\n\nExample section-specific CSP exclusion:\n\n```json\n{\n  \"ignorePatterns\": [\n    \"/enews/\",\n    \"past-newsletters\",\n    \"/digital-catalog/\",\n    \"1stmonday\"\n  ]\n}\n```\n\nUse crawler-level `urlCantContain` / `urlMustContain` when a URL should be excluded from the whole crawl and every job. Use this job's `ignorePatterns` when the URL should still be available to other jobs, but should not influence the generated CSP for the current policy scope.\n","readmeFilename":"README.md"}