{"_id":"@nichtsam/helmet","_rev":"5-a95ea3ce3dc2d83bb099ade16ae4c1cc","name":"@nichtsam/helmet","dist-tags":{"latest":"0.3.3"},"versions":{"0.1.0":{"name":"@nichtsam/helmet","version":"0.1.0","keywords":["web","security","helmet"],"author":{"url":"https://nichtsam.com","name":"Samuel Jensen"},"license":"MIT","_id":"@nichtsam/helmet@0.1.0","maintainers":[{"name":"nichtsam","email":"abernichtsam@gmail.com"}],"homepage":"https://github.com/nichtsam/helmet","bugs":{"url":"https://github.com/nichtsam/helmet/issues"},"dist":{"shasum":"4d6bb020460b83fba7cf3baadb129b7eaae689df","tarball":"https://registry.npmjs.org/@nichtsam/helmet/-/helmet-0.1.0.tgz","fileCount":50,"integrity":"sha512-8bQ6QUui1Pls19u31SvWG8SpA9tq9xT7FyFJek84K8rPZn3xYui5PLC9f13GG9fNTcI+rgu4NpToaT46caGsyA==","signatures":[{"sig":"MEQCICx0xrhQqCpQppA9udUOAPf0i6xYkqML0R89mi83MQ8mAiAYNzV4oLkzJNBL9QFigJwltIdCFrhMFPuC7mcurB2lew==","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/@nichtsam%2fhelmet@0.1.0","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":38990},"type":"module","engines":{"node":"22"},"exports":{".":"./build/index.js","./*":"./build/rules/*.js","./package.json":"./package.json"},"gitHead":"4ff9f55040942e93e06da301a661b1b1d4774269","scripts":{"build":"tsc","quality":"biome check .","typecheck":"tsc --noEmit","quality:fix":"biome check . --write --unsafe"},"_npmUser":{"name":"nichtsam","email":"abernichtsam@gmail.com"},"repository":{"url":"git+https://github.com/nichtsam/helmet.git","type":"git"},"_npmVersion":"10.9.2","description":"Helps to secure apps by setting HTTP response headers. Inspired by [`helmet`](https://github.com/helmetjs/helmet) and [`http-helmet`](https://github.com/mcansh/http-helmet)","directories":{},"sideEffects":false,"_nodeVersion":"22.13.1","_hasShrinkwrap":false,"devDependencies":{"typescript":"5.7.3","@types/node":"^22.13.1","@biomejs/biome":"1.9.4","@total-typescript/tsconfig":"1.0.4"},"_npmOperationalInternal":{"tmp":"tmp/helmet_0.1.0_1739303966936_0.010618226279182075","host":"s3://npm-registry-packages-npm-production"}},"0.2.0":{"name":"@nichtsam/helmet","version":"0.2.0","keywords":["web","security","helmet"],"author":{"url":"https://nichtsam.com","name":"Samuel Jensen"},"license":"MIT","_id":"@nichtsam/helmet@0.2.0","maintainers":[{"name":"nichtsam","email":"abernichtsam@gmail.com"}],"homepage":"https://github.com/nichtsam/helmet","bugs":{"url":"https://github.com/nichtsam/helmet/issues"},"dist":{"shasum":"bccd1bf6bd391a762cce078734ffa6be7a47a6f1","tarball":"https://registry.npmjs.org/@nichtsam/helmet/-/helmet-0.2.0.tgz","fileCount":59,"integrity":"sha512-mJ4ytw/vZgCjvVl6jArz1ZuomOckw7TkhOKsfjtDDdM1CBOm86G0QuZMoSFDJTC0518pHYlqGvysR97w0IxuOA==","signatures":[{"sig":"MEQCIHaT9eLsrVlx7sUte8LS8ASAVMLBodDc2zXqQPbH/k5jAiB8bSBbVuNjbJR/Kb2KkHxLyc2bl1CGCl/YFsezaqxMoA==","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/@nichtsam%2fhelmet@0.2.0","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":45381},"type":"module","engines":{"node":"22"},"exports":{".":"./build/index.js","./rules/*":"./build/rules/*.js","./node-http":"./build/node-http.js","./package.json":"./package.json"},"gitHead":"bcc314749de0faf71f192ef70380267b1c7aa986","scripts":{"build":"tsc","quality":"biome check .","typecheck":"tsc --noEmit","quality:fix":"biome check . --write --unsafe"},"_npmUser":{"name":"nichtsam","email":"abernichtsam@gmail.com"},"repository":{"url":"git+https://github.com/nichtsam/helmet.git","type":"git"},"_npmVersion":"10.9.2","description":"Helps secure applications by setting HTTP response headers. Inspired by [`helmet`](https://github.com/helmetjs/helmet) and [`http-helmet`](https://github.com/mcansh/http-helmet).","directories":{},"sideEffects":false,"_nodeVersion":"22.13.1","_hasShrinkwrap":false,"devDependencies":{"typescript":"5.7.3","@types/node":"^22.13.1","@biomejs/biome":"1.9.4","@total-typescript/tsconfig":"1.0.4"},"_npmOperationalInternal":{"tmp":"tmp/helmet_0.2.0_1739397593696_0.9507872649664324","host":"s3://npm-registry-packages-npm-production"}},"0.3.0":{"name":"@nichtsam/helmet","version":"0.3.0","keywords":["web","security","helmet"],"author":{"url":"https://nichtsam.com","name":"Samuel Jensen"},"license":"MIT","_id":"@nichtsam/helmet@0.3.0","maintainers":[{"name":"nichtsam","email":"abernichtsam@gmail.com"}],"homepage":"https://github.com/nichtsam/helmet","bugs":{"url":"https://github.com/nichtsam/helmet/issues"},"dist":{"shasum":"98cf3c751efa78aaa42434709b0932f27b640251","tarball":"https://registry.npmjs.org/@nichtsam/helmet/-/helmet-0.3.0.tgz","fileCount":59,"integrity":"sha512-eXpehik+AGZu9FG5fRI3IAznt+NjJ/zKDGQCXQL9QLvfk1dncVpI2VBpvEv6G1rZ49WVHkxPKzuX40F5T6V4SA==","signatures":[{"sig":"MEUCIQDwDioRpXotjBju7cbnmkLrWIZu1aC+DPb9JOnaK+umUgIgAYzQsvnqIdbZFcWNvbi5rdLgAVgQd7rKiioQP2fLd3s=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/@nichtsam%2fhelmet@0.3.0","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":45550},"type":"module","engines":{"node":"22"},"exports":{".":"./build/index.js","./content":"./build/content.js","./general":"./build/general.js","./rules/*":"./build/rules/*.js","./node-http":"./build/node-http.js","./package.json":"./package.json","./resourceSharing":"./build/resourceSharing.js"},"gitHead":"59d503ade26b6d4594274b63bb429d8999eb047c","scripts":{"build":"tsc","quality":"biome check .","typecheck":"tsc --noEmit","quality:fix":"biome check . --write --unsafe"},"_npmUser":{"name":"nichtsam","email":"abernichtsam@gmail.com"},"repository":{"url":"git+https://github.com/nichtsam/helmet.git","type":"git"},"_npmVersion":"10.9.2","description":"Helps secure applications by setting HTTP response headers. Inspired by [`helmet`](https://github.com/helmetjs/helmet) and [`http-helmet`](https://github.com/mcansh/http-helmet).","directories":{},"sideEffects":false,"_nodeVersion":"22.13.1","_hasShrinkwrap":false,"devDependencies":{"typescript":"5.7.3","@types/node":"^22.13.1","@biomejs/biome":"1.9.4","@total-typescript/tsconfig":"1.0.4"},"_npmOperationalInternal":{"tmp":"tmp/helmet_0.3.0_1739568055538_0.45433194881654493","host":"s3://npm-registry-packages-npm-production"}},"0.3.1":{"name":"@nichtsam/helmet","version":"0.3.1","keywords":["web","security","helmet"],"author":{"url":"https://nichtsam.com","name":"Samuel Jensen"},"license":"MIT","_id":"@nichtsam/helmet@0.3.1","maintainers":[{"name":"nichtsam","email":"abernichtsam@gmail.com"}],"homepage":"https://github.com/nichtsam/helmet","bugs":{"url":"https://github.com/nichtsam/helmet/issues"},"dist":{"shasum":"0af9443336189ed87c0f25e18de74a77ae8e541b","tarball":"https://registry.npmjs.org/@nichtsam/helmet/-/helmet-0.3.1.tgz","fileCount":60,"integrity":"sha512-+QZo63klL3+K/nGTyrvlsuzwnUFc3sxkIYTydwxNkjzQcKz4HHFx+YPN80QqB/wBriW9OmwYl/ZGKPbCRJXfVQ==","signatures":[{"sig":"MEUCIQDghIg6YbqbjGKPs44XsrXCE1/PQ8zIHvZHzrg6MQBp0wIgUskCvwunG9lRiHHW65TrFB807MUXc7XNzhYnvaPNF7g=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/@nichtsam%2fhelmet@0.3.1","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":47736},"type":"module","engines":{"node":">=22"},"exports":{".":"./build/index.js","./content":"./build/content.js","./general":"./build/general.js","./rules/*":"./build/rules/*.js","./node-http":"./build/node-http.js","./package.json":"./package.json","./resourceSharing":"./build/resourceSharing.js"},"gitHead":"4aeaa1310bbab6434c089f9882a3a8e462458135","scripts":{"build":"tsc","quality":"biome check .","typecheck":"tsc --noEmit","quality:fix":"biome check . --write --unsafe"},"_npmUser":{"name":"nichtsam","actor":{"name":"nichtsam","type":"user","email":"abernichtsam@gmail.com"},"email":"abernichtsam@gmail.com"},"repository":{"url":"git+https://github.com/nichtsam/helmet.git","type":"git"},"_npmVersion":"10.9.2","description":"Helps secure applications by setting HTTP response headers. Inspired by [`helmet`](https://github.com/helmetjs/helmet) and [`http-helmet`](https://github.com/mcansh/http-helmet).","directories":{},"sideEffects":false,"_nodeVersion":"22.16.0","_hasShrinkwrap":false,"devDependencies":{"typescript":"5.7.3","@types/node":"^22.13.1","@biomejs/biome":"1.9.4","@total-typescript/tsconfig":"1.0.4"},"_npmOperationalInternal":{"tmp":"tmp/helmet_0.3.1_1750965793653_0.5696707895447464","host":"s3://npm-registry-packages-npm-production"}},"0.3.3":{"sideEffects":false,"type":"module","name":"@nichtsam/helmet","version":"0.3.3","license":"MIT","keywords":["web","security","helmet"],"author":{"name":"Samuel Jensen","url":"https://nichtsam.com"},"homepage":"https://github.com/nichtsam/helmet","repository":{"type":"git","url":"git+https://github.com/nichtsam/helmet.git"},"bugs":{"url":"https://github.com/nichtsam/helmet/issues"},"scripts":{"build":"tsc","typecheck":"tsc --noEmit","quality":"biome check .","quality:fix":"biome check . --write --unsafe"},"exports":{".":"./build/index.js","./node-http":"./build/node-http.js","./general":"./build/general.js","./content":"./build/content.js","./resourceSharing":"./build/resourceSharing.js","./rules/*":"./build/rules/*.js","./package.json":"./package.json"},"devDependencies":{"@biomejs/biome":"1.9.4","@total-typescript/tsconfig":"1.0.4","@types/node":"^22.13.1","typescript":"5.7.3"},"engines":{"node":">=22"},"gitHead":"7462d496f81130c389132177166ef086e84a7584","_id":"@nichtsam/helmet@0.3.3","description":"Helps secure applications by setting HTTP response headers. Inspired by [`helmet`](https://github.com/helmetjs/helmet) and [`http-helmet`](https://github.com/mcansh/http-helmet).","_nodeVersion":"24.14.0","_npmVersion":"11.9.0","dist":{"integrity":"sha512-Xg6Ogi8Ko6ARFPXr769cpE7U8YbyZjwcLtKUloEaSgSgbR3B8SIUnoONguXKC+x2LB+Rumg/wKo196r4SGIadA==","shasum":"cb7cb4677cbea52d7d125cedc6b3d317273633bc","tarball":"https://registry.npmjs.org/@nichtsam/helmet/-/helmet-0.3.3.tgz","fileCount":60,"unpackedSize":47726,"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/@nichtsam%2fhelmet@0.3.3","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"signatures":[{"keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U","sig":"MEUCIAEfUWFpw7XiKtGkGqrv6PEg9MJ3wPFGlhErCRp5LAwOAiEAwzz4tmhbg7Jyf+lzjIY+U3JzkN7XoMNLU+hlOTdVy9A="}]},"_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:a5fcd7b1-7536-41c5-a41c-6a64e51937e5"}},"directories":{},"maintainers":[{"name":"nichtsam","email":"abernichtsam@gmail.com"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages-npm-production","tmp":"tmp/helmet_0.3.3_1773337748531_0.5558383335901733"},"_hasShrinkwrap":false}},"time":{"created":"2025-02-11T19:59:26.863Z","modified":"2026-03-12T17:49:09.026Z","0.1.0":"2025-02-11T19:59:27.097Z","0.2.0":"2025-02-12T21:59:53.906Z","0.3.0":"2025-02-14T21:20:55.698Z","0.3.1":"2025-06-26T19:23:13.977Z","0.3.3":"2026-03-12T17:49:08.697Z"},"bugs":{"url":"https://github.com/nichtsam/helmet/issues"},"author":{"name":"Samuel Jensen","url":"https://nichtsam.com"},"license":"MIT","homepage":"https://github.com/nichtsam/helmet","keywords":["web","security","helmet"],"repository":{"type":"git","url":"git+https://github.com/nichtsam/helmet.git"},"description":"Helps secure applications by setting HTTP response headers. Inspired by [`helmet`](https://github.com/helmetjs/helmet) and [`http-helmet`](https://github.com/mcansh/http-helmet).","maintainers":[{"name":"nichtsam","email":"abernichtsam@gmail.com"}],"readme":"# Helmet Security Headers Library\n\nHelps secure applications by setting HTTP response headers.\nInspired by [`helmet`](https://github.com/helmetjs/helmet) and [`http-helmet`](https://github.com/mcansh/http-helmet).\n\n## Why?\n\n[`helmet`](https://github.com/helmetjs/helmet) applies security headers globally without considering the specific content type of each response. While this approach works for many cases, it can lead to unnecessary or misapplied headers. For example, Content Security Policy (CSP) should be specific to the response’s content type, and `X-Download-Options` only matters for document responses, whereas headers like `X-Content-Type-Options` and `Strict-Transport-Security` are universally applicable.\n\nTo improve clarity and control, I categorized security headers into three groups:\n1. General – Applies to all resources, ensuring broad security coverage.\n2. Content – Applies based on the response’s content type.\n3. Resource Sharing – Related to cross-origin policies.\n\nThis approach ensures that security headers are applied in a structured manner, improving maintainability and reducing unnecessary overhead. Additionally, this package is designed to work seamlessly with both the Web Fetch API’s `Headers` and `http.ServerResponse`, making it more flexible across different environments.\n\n## Overview\n\nThis package provides a flexible and modular way for managing security headers in a structured manner.\n\n- Provides security headers with sensible defaults (inspired by Express Helmet).\n- Content-specific options available as needed.\n- Resource Sharing Security Headers.\n\n## Installation\n\n```sh\nnpm install @nichtsam/helmet\n```\n\n## Usage\n\nThis is the most basic usage, which applies security headers for general purpose, best practices for protecting any type of resource.\n\n```ts\nimport { helmet } from \"@nichtsam/helmet\";\nconst headers = new Headers();\nhelmet(headers);\n```\n\nThere are options to enable more detailed security headers, such as for html webpage contents.\n\n```ts\nhelmet(headers, {\n  content: { contentSecurityPolicy: {} },\n});\n```\n\nIf you want to share the resource across origins, you can enable the resourceSharing option.\n\n```ts\nhelmet(headers, { resourceSharing: true });\n```\n\n> [!IMPORTANT]  \n> This only sets the headers for enhanced security.\n> You are responsible for setting the correct CORS headers.\n> https://developer.mozilla.org/en-US/docs/Web/HTTP/CORS#the_http_request_headers\n\n### For `node-http`\n\nThe package provides a simple wrapper to make it smoother to use on `http.ServerResponse`.\nFor example in an express app:\n\n```ts\nimport { helmet } from \"@nichtsam/helmet/node-http\";\n\nconst app = express();\napp.use((req, res, next) => {\n  helmet(res);\n  next();\n});\n```\n\n### Granular Interface\n\nThe main `helmet` function integrates all the security rules, you can find them all individually under `@nichtsam/helmet/rules`.\nThey're categorized under `general`, `content` and `resourceSharing`, just like the options in the integrated `helmet` function.\nThis allows for a layered application approach to better suit individual routes.\n\nFor example:\n\n```ts\nimport { generalSecurity } from \"@nichtsam/helmet/general\";\nimport { contentSecurity } from \"@nichtsam/helmet/content\";\nimport { resourceSharingSecurity } from \"@nichtsam/helmet/resourceSharing\";\n\nconst headers = new Headers();\n// on root level\ngeneralSecurity(headers);\n// after the content-type is set\ncontentSecurity(headers);\n// if you want to share across origins\nresourceSharingSecurity(headers, { strategy: \"cross-origin\" });\n```\n\n> [!NOTE]  \n> The `generalSecurity` function includes `resourceSharingSecurity(headers, { strategy: \"same-origin\" })` by default.\n> So you only need to call `resourceSharingSecurity` if you want to share resources across origins or customize the strategy.\n","readmeFilename":"README.md"}