{"_id":"strict-csp","_rev":"10-f874e552cb515e848241bee97c9e3915","name":"strict-csp","dist-tags":{"beta":"1.0.0-beta.1","latest":"1.1.2"},"versions":{"1.0.0-beta.0":{"name":"strict-csp","version":"1.0.0-beta.0","keywords":["csp","security"],"author":{"name":"Lukas Weichselbaum","email":"lwe@google.com"},"license":"Apache-2.0","_id":"strict-csp@1.0.0-beta.0","maintainers":[{"name":"lweichselbaum","email":"l.weichselbaum@gmail.com"}],"contributors":[{"name":"Maud Nalpas","email":"maudn@google.com"}],"homepage":"https://github.com/google/strict-csp#readme","bugs":{"url":"https://github.com/google/strict-csp/issues"},"dist":{"shasum":"7d5875cb212c71f0b45d3f2f51cfddff3ed5bad3","tarball":"https://registry.npmjs.org/strict-csp/-/strict-csp-1.0.0-beta.0.tgz","fileCount":3,"integrity":"sha512-eeLXt5VSaVHLElRf6RfBTL04JWJh4flcokCSk//rib1NNGYijM7vs52dJBjqdbsTvfmiBul8C7Ty6jRHVD5f3g==","signatures":[{"sig":"MEUCIBpdrpmDEqCErFgNitjxKbWmfuEcKwfjiEtUSyOxZ9OmAiEAxNyC0V82EQy+eTlOKrv9hnJiPFNwF6wuydczIsQWMak=","keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA"}],"unpackedSize":7747,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v3.0.13\r\nComment: https://openpgpjs.org\r\n\r\nwsFcBAEBCAAQBQJgZatMCRA9TVsSAnZWagAAuloP/1R6qoAbhL4Nq7hqujYs\nLaEjw6xuNp28vlOxnG8JD4Kn5OiUr+WuNNOotW/l+NnzYhvTaaMhYwMll4pS\nF83kOzbx06AovXAIqW9GQFC6JmlBBUTNjYXIbJALKUOEZZpGWHssPO9pxmr4\nHMAjryxzaFncfGI+VMUULnQ2VXs93TmqipiAXJ7JTwOd33KZxFdSF55ImzVN\ndWJvOIeKessDXE1Wc7ViR+wdMsv2TmTLgXkvTUBTmdnewEwIZferYTBvsuxN\nYwNwZQpD7AP9+pk5BkAnO8Bu6DGh55dOVCp9mjwbbK0Yl+zNdpbs+mVEeV4G\nW52/T5eYV7MqGQ7eabYJEp1UtAbYp6qLGa4j8djAorsxTTf0/NG9WO7xfp0r\n8RdCzkiLvzyGFB/CCYFJ8ypxPuH7svYQ2CPRtkBJNHHgDaRN31hOUkQwk4JO\nIPLUOguc7ctiIAf2s8+dgJN4pcCGJQNOBhxqaU/tk2R8XmwV9rUPAfM3xyOe\n45sn3/hlUGlB1TlVAdOyY8uKnulaeljcbvnZGx6+EOw2YibjazrMsbZozIgW\nqk+3S8w/4K1nDOUXMyDC9sR9gziOWON4W1DtGimpDjxwzZhfau1/vHaGNcwj\nMRAU8hpl6jxu8iZCIoNiJogpHXLCB+Axgc9VEgUuqr/KaFl2NdIPKtUPGK/G\nHJsw\r\n=3FiX\r\n-----END PGP SIGNATURE-----\r\n"},"main":"build/index.js","scripts":{"tsc":"tsc","lint":"eslint . --ext .ts","build":"rimraf build && tsc","auto-csp":"npm run build && node build/index.js"},"_npmUser":{"name":"lweichselbaum","email":"l.weichselbaum@gmail.com"},"prepublish":"tsc","repository":{"url":"git+https://github.com/google/strict-csp.git","type":"git","directory":"strict-csp"},"_npmVersion":"6.14.11","description":"Enables a hash-based strict Content Security Policy for static HTML files and single page applications.","directories":{},"_nodeVersion":"14.16.0","dependencies":{"fs":"^0.0.1-security","path":"^0.12.7","cheerio":"^1.0.0-rc.5","@types/cheerio":"^0.22.23","command-line-args":"^5.1.1","command-line-usage":"^6.1.1","@types/command-line-args":"^5.0.0"},"_hasShrinkwrap":false,"devDependencies":{"eslint":"^7.15.0","rimraf":"^3.0.2","typescript":"^4.1.3","@types/node":"^14.14.14","@typescript-eslint/parser":"^4.10.0","@typescript-eslint/eslint-plugin":"^4.10.0"},"_npmOperationalInternal":{"tmp":"tmp/strict-csp_1.0.0-beta.0_1617275724067_0.5306169845155617","host":"s3://npm-registry-packages"}},"1.0.0-beta.1":{"name":"strict-csp","version":"1.0.0-beta.1","keywords":["csp","content-security-policy","security"],"author":{"name":"Lukas Weichselbaum","email":"lwe@google.com"},"license":"Apache-2.0","_id":"strict-csp@1.0.0-beta.1","maintainers":[{"name":"lweichselbaum","email":"l.weichselbaum@gmail.com"}],"contributors":[{"name":"Maud Nalpas","email":"maudn@google.com"}],"homepage":"https://github.com/google/strict-csp#readme","bugs":{"url":"https://github.com/google/strict-csp/issues"},"dist":{"shasum":"af1f8461f9d6cc4ed7bddedc6a1b2ee298443917","tarball":"https://registry.npmjs.org/strict-csp/-/strict-csp-1.0.0-beta.1.tgz","fileCount":4,"integrity":"sha512-CYLUClzQSkHQ21w5KSAgKMoQgjfpTE5rOFy2n7VNjZf/fQPxWeX1Gr80qwcCflZxdjx2u8I2YyA9wFgJrVR7+Q==","signatures":[{"sig":"MEUCIQCl8s4K8+XxtOdx8eXTEoBhZtNoWths0wshZxmHMJkntQIga/FfqTERtBUQcPNnX9CsDD16yURszO++Sv4eF1a3nc0=","keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA"}],"unpackedSize":16270,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v3.0.13\r\nComment: https://openpgpjs.org\r\n\r\nwsFcBAEBCAAQBQJgZbZMCRA9TVsSAnZWagAAbzIP/RIMULvlQ/nZ4y2dM7iE\nWo+LgATOzzS0nckq08Rcq4qsTG7jM7s7sjxhFI9r7grhPUCiFvS5XXHCR2EY\nHMK+xU1eTgUPOh/wT04xXYX0JPHXr29Esq8PeaOKr6NuDcHxp2y8cCy7VI8I\n39CjL4yLAuJQBBel6yEKFw1l5Lgv2dJo371z/+F/6tZq0eyQXpacLbRv2dub\neW0bXzIxlCX+bz/LMpEG0k1ZhdvjGkTSJh1+KM5DBlzqtqedd4o5ZrY3g/iC\nxAtcrsrJmyETBmfN1ZlZxnycV+zPfh+IlMUB+yid1kqPvySy4Hs6rnPlLl7d\nf9r6n9XNHQnirOxHn4ctJW+3kCqgu9KJ8BAb64udb/lGftB1T7Q5YfTs2sdX\nu4G5UI7DsH2/osyLSP/PEfMoomFUWQC2TTSbN80Dct85pydkNLyTy6swCB2s\nbpDmNcwd0MVAc7fkoTWFGwUkRz+Tf848Bo0diblTpC8uPgHkP58rG24tDmh5\niwokkPgAA1z3YbsddfVFMN9c0JrYld0GOlStXgH6YEajUubkjYqFdwAIddYC\nn/yuA4iZva1D6SXygauFiMWclgmMfsyL8yMzYGP+9zQN47B8MOEtWsk6FEvF\nCOnKi7TjLRzvucd/+QP0Fnz12w15Tuo8cKS2VNjHEKJGLPK2uEOu3tzFWX5b\nTjxI\r\n=GQMv\r\n-----END PGP SIGNATURE-----\r\n"},"main":"build/index.js","scripts":{"tsc":"tsc","lint":"eslint . --ext .ts","build":"rimraf build && tsc","auto-csp":"npm run build && node build/index.js"},"_npmUser":{"name":"lweichselbaum","email":"l.weichselbaum@gmail.com"},"prepublish":"tsc","repository":{"url":"git+https://github.com/google/strict-csp.git","type":"git","directory":"strict-csp"},"_npmVersion":"6.14.11","description":"Enables a hash-based strict Content Security Policy for static HTML files and single page applications.","directories":{},"_nodeVersion":"14.16.0","dependencies":{"fs":"^0.0.1-security","path":"^0.12.7","cheerio":"^1.0.0-rc.5","@types/cheerio":"^0.22.23","command-line-args":"^5.1.1","command-line-usage":"^6.1.1","@types/command-line-args":"^5.0.0"},"_hasShrinkwrap":false,"devDependencies":{"eslint":"^7.15.0","rimraf":"^3.0.2","typescript":"^4.1.3","@types/node":"^14.14.14","@typescript-eslint/parser":"^4.10.0","@typescript-eslint/eslint-plugin":"^4.10.0"},"_npmOperationalInternal":{"tmp":"tmp/strict-csp_1.0.0-beta.1_1617278539636_0.7305740704409713","host":"s3://npm-registry-packages"}},"1.0.1":{"name":"strict-csp","version":"1.0.1","keywords":["csp","content-security-policy","security"],"author":{"name":"Lukas Weichselbaum","email":"lwe@google.com"},"license":"Apache-2.0","_id":"strict-csp@1.0.1","maintainers":[{"name":"lweichselbaum","email":"l.weichselbaum@gmail.com"}],"contributors":[{"name":"Maud Nalpas","email":"maudn@google.com"}],"homepage":"https://github.com/google/strict-csp#readme","bugs":{"url":"https://github.com/google/strict-csp/issues"},"dist":{"shasum":"a21391242e42acd3ab618aaf3f243b5048dcc522","tarball":"https://registry.npmjs.org/strict-csp/-/strict-csp-1.0.1.tgz","fileCount":5,"integrity":"sha512-3/END5mJ8m2dDem66DG4QcgmN1K+5qzK6JAW3g52qTU6fQVwmlWSJzFuYoDBWwC/jbPL+VzD9L+E+UOtuRE2Aw==","signatures":[{"sig":"MEMCH2pXQjm+izMGmxgXfMuZzPYIvvCDASl7pSabaau1GvQCICCJJjfjNr3dg9UwtW0uBiDpE0rkJoupQQHVjDgmXqyd","keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA"}],"unpackedSize":19718},"main":"build/index.js","types":"build/index.d.ts","scripts":{"tsc":"tsc","lint":"eslint . --ext .ts","build":"rimraf build && tsc","auto-csp":"npm run build && node build/index.js"},"_npmUser":{"name":"lweichselbaum","email":"l.weichselbaum@gmail.com"},"prepublish":"tsc","repository":{"url":"git+https://github.com/google/strict-csp.git","type":"git","directory":"strict-csp"},"_npmVersion":"6.14.15","description":"Enables a hash-based strict Content Security Policy for static HTML files and single page applications.","directories":{},"_nodeVersion":"12.22.7","dependencies":{"fs":"^0.0.1-security","path":"^0.12.7","cheerio":"^1.0.0-rc.5","@types/cheerio":"^0.22.23","command-line-args":"^5.1.1","command-line-usage":"^6.1.1","@types/command-line-args":"^5.0.0"},"_hasShrinkwrap":false,"devDependencies":{"eslint":"^7.15.0","rimraf":"^3.0.2","typescript":"^4.1.3","@types/node":"^14.14.14","@typescript-eslint/parser":"^4.10.0","@typescript-eslint/eslint-plugin":"^4.10.0"},"_npmOperationalInternal":{"tmp":"tmp/strict-csp_1.0.1_1634830514309_0.6989926363837589","host":"s3://npm-registry-packages"}},"1.0.2":{"name":"strict-csp","version":"1.0.2","keywords":["csp","content-security-policy","security"],"author":{"name":"Lukas Weichselbaum","email":"lwe@google.com"},"license":"Apache-2.0","_id":"strict-csp@1.0.2","maintainers":[{"name":"lweichselbaum","email":"l.weichselbaum@gmail.com"}],"contributors":[{"name":"Maud Nalpas","email":"maudn@google.com"}],"homepage":"https://github.com/google/strict-csp#readme","bugs":{"url":"https://github.com/google/strict-csp/issues"},"dist":{"shasum":"a7ac1beb9b90b00393c5682fef0a38c73daa5853","tarball":"https://registry.npmjs.org/strict-csp/-/strict-csp-1.0.2.tgz","fileCount":5,"integrity":"sha512-YLnlJIGZQYRPRo39d/wNmF1CVkaikwCsIcLBWvVBWYAxQGFjigolOE2oPeqPMFt19NPM+Vts/z5nT15nRcKNUg==","signatures":[{"sig":"MEYCIQDx2oKVYRVZX59TLbltfCWDq+o+lSu8SNZ/xX6k9OaV1wIhAKYUJZ7FmzqrdG0WNwz/tCQS0/tr+wrA1TKwTGx+A05P","keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA"}],"unpackedSize":19553,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v3.0.13\r\nComment: https://openpgpjs.org\r\n\r\nwsFcBAEBCAAQBQJhufj0CRA9TVsSAnZWagAAMBMP/0n0zKDevPzuLznf1816\nEJZZ4n2F+NAVp3kdouqdt9x39yD1IHIIDh2zUeB+YyE1yBD8C4J8OrVkc2r0\nWSmOvq+J3MRRQoCCIrkZXitzoMU0mHjyoPPpCGfWXZXDIdePVLaRiLqLzfkU\njbxkidXLTPG6+ULOpl8qyo1m6ZxrUo3bexfBEBKYrcOjvuYeV8S0PvZp0axA\nGaY3yx9JcXlpHjrmjSpHQxp/A69uVxXmRdZahkTLooW29qHhQ1uBXgMga1aB\nIou492zSHeA8FN43Cp51Rwh9qD8Bd4fXMsZecxLS3x50CVA94c78UfFJf2Yv\n/xpNpff1UQRwYJYcpveWalvSNqZ/lTPvmGl0RTRItwFIAoVlMDMdbWFXpBEo\nHmq0bWKOSx2qscO/mYbUev9csKOEq+rNJ8lHTOgbj1Er+dLneiCo3UkdvoF+\nmSqaD7iwZhhXvqCsZIJ+iwkQB2boZhRI3Br6KO6/jZqZJzfApwSE2uqkimbF\nxhzEE/fRMOqgYC2+2j1fkWAqw4NtGNU+ZB9SocxytRCZRYLZqlTE+gsbz0ig\nX1ayVl8Gf+o9mOHvN4L1pNfwkk6RRfD+BIviMR5RNtMP6Gh07+v8My0i7zmG\nDPahTiCStRpfdbFPPZmPN9ificnYiRyzst8loMYSMjIjT22pi2XC0YBy1OCh\ngbOw\r\n=nFgz\r\n-----END PGP SIGNATURE-----\r\n"},"main":"build/index.js","types":"build/index.d.ts","scripts":{"tsc":"tsc","lint":"eslint . --ext .ts","build":"rimraf build && tsc","auto-csp":"npm run build && node build/index.js"},"_npmUser":{"name":"lweichselbaum","email":"l.weichselbaum@gmail.com"},"prepublish":"tsc","repository":{"url":"git+https://github.com/google/strict-csp.git","type":"git","directory":"strict-csp"},"_npmVersion":"6.14.15","description":"Enables a hash-based strict Content Security Policy for static HTML files and single page applications.","directories":{},"_nodeVersion":"12.22.7","dependencies":{"cheerio":"^1.0.0-rc.5","@types/cheerio":"^0.22.23"},"_hasShrinkwrap":false,"devDependencies":{"eslint":"^7.15.0","rimraf":"^3.0.2","typescript":"^4.1.3","@types/node":"^14.14.14","@typescript-eslint/parser":"^4.10.0","@typescript-eslint/eslint-plugin":"^4.10.0"},"_npmOperationalInternal":{"tmp":"tmp/strict-csp_1.0.2_1639577844038_0.21619781085937628","host":"s3://npm-registry-packages"}},"1.0.3":{"name":"strict-csp","version":"1.0.3","keywords":["csp","content-security-policy","security"],"author":{"name":"Lukas Weichselbaum","email":"lwe@google.com"},"license":"Apache-2.0","_id":"strict-csp@1.0.3","maintainers":[{"name":"lweichselbaum","email":"l.weichselbaum@gmail.com"}],"contributors":[{"name":"Maud Nalpas","email":"maudn@google.com"}],"homepage":"https://github.com/google/strict-csp#readme","bugs":{"url":"https://github.com/google/strict-csp/issues"},"dist":{"shasum":"c920c524938a03c5531b2dea93a84c118e72b576","tarball":"https://registry.npmjs.org/strict-csp/-/strict-csp-1.0.3.tgz","fileCount":6,"integrity":"sha512-nyiwxxoFfNnw6nAva+N4k6F8hLBjdga/PiLMQls7/BXk3LZWQhtCTaMhJYFvST0b2yua07UV+3H6Ruwmo8si3A==","signatures":[{"sig":"MEUCIQDJQAEvlaBJgHe0CtYkryFdnofuWTIcGZZlR0WS32Lu0QIgZvlflixa2V1iNTbAMc06kuoiCPbcsOQ6ioiwpiMlofQ=","keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA"}],"unpackedSize":23496,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v3.0.13\r\nComment: https://openpgpjs.org\r\n\r\nwsFcBAEBCAAQBQJhu0Y8CRA9TVsSAnZWagAAqTAP/ieSCZd9IKvpNiVjoMd8\nc+DzKYgghRy45/u+ChXIJoSljRuFOS3ydHoydh0ZFcZQj1ds29awzaceVNgC\ntTKCq0o3mmRFX1cOSKd2QGCWkGw6JKdse3uyc29sGCvECbqQn0RyHasa5nCy\nNDCxvD9CfQDHsg2eI4FwejdtP8H5ogmkkO4h31zdIwH5yA3zg2Hxfyh+q4bH\nOcvftNvLcu+r+1kohJu5bspF/NUA6fD6j5CihPvoSyFLW+Ef/bzat+zWs0Dl\nz1q3Hd+i7x4cjI5/hKcK99dsD0/xpvzbEny0VBBGNURs5unk/IlDj+z7jbrw\nFzh1uxQkoHoftfJbPVpw+7Tv7tHPKsmIUJPmez8kRKa2bOJrcLx/LBxVi0yh\nr9FZpp3sWpiIq/t7iDbcY2grB2jWq0RbjyXAnasQ3vmEsnLApdwDcH3n4bth\ng4nYTV87TL0Y8pJIf1Ou9RwGCi4ww6KPo1bY/l+qYNYNs9thuGjggeFWnitg\n9gVRYDVh3hg9k4NwhKAjKSVFKu1tpBsSnusW1kwiD/dNMffq7ZQxXk1KPj4/\nyZ+1tTKNfsMlOSjWSHVIaAKlFYu/7cZwDkk/4+/zUaR8Pf/Faw5U22SmWKA0\nghLzUNnUPkxo7OFD0ErlGVyibGu/9gTAiLRY6zJv4EiDLLgAhEXvQ4oOYRiE\nJnxk\r\n=IvnB\r\n-----END PGP SIGNATURE-----\r\n"},"main":"build/index.js","types":"build/index.d.ts","scripts":{"tsc":"tsc","lint":"eslint . --ext .ts","build":"rimraf build && tsc","auto-csp":"npm run build && node build/index.js"},"_npmUser":{"name":"lweichselbaum","email":"l.weichselbaum@gmail.com"},"prepublish":"tsc","repository":{"url":"git+https://github.com/google/strict-csp.git","type":"git","directory":"strict-csp"},"_npmVersion":"6.14.15","description":"Enables a hash-based strict Content Security Policy for static HTML files and single page applications.","directories":{},"_nodeVersion":"12.22.7","dependencies":{"cheerio":"^1.0.0-rc.5","@types/cheerio":"^0.22.23"},"_hasShrinkwrap":false,"devDependencies":{"eslint":"^7.15.0","rimraf":"^3.0.2","typescript":"^4.1.3","@types/node":"^14.14.14","@typescript-eslint/parser":"^4.10.0","@typescript-eslint/eslint-plugin":"^4.10.0"},"_npmOperationalInternal":{"tmp":"tmp/strict-csp_1.0.3_1639663163902_0.2078444020176402","host":"s3://npm-registry-packages"}},"1.0.4":{"name":"strict-csp","version":"1.0.4","keywords":["csp","content-security-policy","security"],"author":{"name":"Lukas Weichselbaum","email":"lwe@google.com"},"license":"Apache-2.0","_id":"strict-csp@1.0.4","maintainers":[{"name":"lweichselbaum","email":"l.weichselbaum@gmail.com"}],"contributors":[{"name":"Maud Nalpas","email":"maudn@google.com"}],"homepage":"https://github.com/google/strict-csp#readme","bugs":{"url":"https://github.com/google/strict-csp/issues"},"dist":{"shasum":"95e56fe47334caa9849b4c7a540af44ad3b72ec5","tarball":"https://registry.npmjs.org/strict-csp/-/strict-csp-1.0.4.tgz","fileCount":6,"integrity":"sha512-CDAq0Zpg3XtJtUxjuOgKK2UgBnW03HDIFyb0rwpxNuQdYC8JquMfnGGhNZcbq22iYzVg6eCgqBScebA6MtwRdg==","signatures":[{"sig":"MEQCIAdCgsBeTUVY5gp+nl16boDwfN+IOOJuYx1WWTnp/9jmAiA5+AxSimzWSPysMWf3+VEqCIbkdMLkAb9jYoIkXP2BvA==","keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA"}],"unpackedSize":24119,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v3.0.13\r\nComment: https://openpgpjs.org\r\n\r\nwsFcBAEBCAAQBQJh3FCTCRA9TVsSAnZWagAAgM4QAJZxwcvsQNvPWYi9MfrX\naNKmk7DN3bTYO7txM2r0BI/Z47n1m6HJnv9mWPCDzHG1F/Um1NB98lLL0eXI\nxWwpnnReW6ImzlmUW1Jtml8IR/CMMZ7rzFjY4tWxAAOfVkEMXZqy5HzxNKhM\nnNWtBCpIF5mJZLK0ikdgjKNpDlejYr9yg0ku9uH/FPZMGfZoftUSZUQ54CjZ\nGaTFSXwY3NSV8KZHwyHtsVv8Oz7CNCaXGr0AaXngpL7s5HOCuMg4L4kV3keG\nPTY5hnXo37m/Kl+KV9Xf7bMAWeqeXIYcIckUF2Zrp2Kh12FEy9CBwx4Dlndc\nNOUYK1QovpEWaexG766sX6UrDmwKxDvUgV2AZVUFeMMwmltDW00mR05Edm87\nRAZ5msNGmiNEkUoKtBJi2ljeAUYnPCp+HYAovOyOlGAlrHm3qbSOXjEBkbLh\nn3hxQQYzl2sXY696bpPHJTqOm2jI9a5AHf9cJCFkwmSQzGjcoFyjSfq+ykIK\n86/7SBbL5eLUvAHit9MPT/oF0nCD9jaznhKXoIocou7UeHP3PKWRnTC9Q32x\ng32OTRtG61CRs+RAwl2k95hZcamPbixSMpCLcV+nZ+WV63Cm7arXtZ5+f1NM\nd2d1ym/DCpj3GuKgCHMiNkN1EUT7U+r9YxnIRJnWKd+mp8gGq+00niEcohky\nMUoI\r\n=e0a7\r\n-----END PGP SIGNATURE-----\r\n"},"main":"build/index.js","types":"build/index.d.ts","scripts":{"tsc":"tsc","lint":"eslint . --ext .ts","build":"rimraf build && tsc","auto-csp":"npm run build && node build/index.js"},"_npmUser":{"name":"lweichselbaum","email":"l.weichselbaum@gmail.com"},"prepublish":"tsc","repository":{"url":"git+https://github.com/google/strict-csp.git","type":"git","directory":"strict-csp"},"_npmVersion":"6.14.15","description":"Enables a hash-based strict Content Security Policy for static HTML files and single page applications.","directories":{},"_nodeVersion":"12.22.8","dependencies":{"cheerio":"^1.0.0-rc.5","@types/cheerio":"^0.22.23"},"_hasShrinkwrap":false,"devDependencies":{"eslint":"^7.15.0","rimraf":"^3.0.2","typescript":"^4.1.3","@types/node":"^14.14.14","@typescript-eslint/parser":"^4.10.0","@typescript-eslint/eslint-plugin":"^4.10.0"},"_npmOperationalInternal":{"tmp":"tmp/strict-csp_1.0.4_1641828499120_0.26109215596294866","host":"s3://npm-registry-packages"}},"1.1.0":{"name":"strict-csp","version":"1.1.0","keywords":["csp","content-security-policy","security"],"author":{"name":"Lukas Weichselbaum","email":"lwe@google.com"},"license":"Apache-2.0","_id":"strict-csp@1.1.0","maintainers":[{"name":"lweichselbaum","email":"l.weichselbaum@gmail.com"}],"contributors":[{"name":"Maud Nalpas","email":"maudn@google.com"}],"homepage":"https://github.com/google/strict-csp#readme","bugs":{"url":"https://github.com/google/strict-csp/issues"},"dist":{"shasum":"3a3df5e121504624e1c3e700f0528d5047b36893","tarball":"https://registry.npmjs.org/strict-csp/-/strict-csp-1.1.0.tgz","fileCount":4,"integrity":"sha512-NS+OfMBkDQS2frqb7/BHLuHQ3OCckQwfvKVYJ0Gx5zkTdfW2s/CLpYifsMnt/UYLX66yiVANlc6zDv8tCkyONg==","signatures":[{"sig":"MEQCIEpit55y/xXHr3uVFBlTwKvkuLSlhOtruKJI6h04izWTAiACf+q+YkBY57Z6nev27pai0sXf3wtiDoxa7b4h4lpI7w==","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":12427},"main":"build/index.js","types":"build/index.d.ts","gitHead":"9e3ae1210f2ed909a1d8b4f954c649a0615aa450","scripts":{"tsc":"tsc","lint":"eslint . --ext .ts","build":"rimraf build && tsc","auto-csp":"npm run build && node build/index.js"},"_npmUser":{"name":"lweichselbaum","email":"l.weichselbaum@gmail.com"},"prepublish":"tsc","repository":{"url":"git+https://github.com/google/strict-csp.git","type":"git","directory":"strict-csp"},"_npmVersion":"10.9.2","description":"Enables a hash-based strict Content Security Policy for static HTML files and single page applications.","directories":{},"_nodeVersion":"22.17.0","dependencies":{"cheerio":"^1.0.0-rc.5","@types/cheerio":"^0.22.23"},"_hasShrinkwrap":false,"devDependencies":{"eslint":"^7.15.0","rimraf":"^3.0.2","typescript":"^4.1.3","@types/node":"^14.14.14","@typescript-eslint/parser":"^4.10.0","@typescript-eslint/eslint-plugin":"^4.10.0"},"_npmOperationalInternal":{"tmp":"tmp/strict-csp_1.1.0_1756732256222_0.8165123791126103","host":"s3://npm-registry-packages-npm-production"}},"1.1.1":{"name":"strict-csp","version":"1.1.1","keywords":["csp","content-security-policy","security"],"author":{"name":"Lukas Weichselbaum","email":"lwe@google.com"},"license":"Apache-2.0","_id":"strict-csp@1.1.1","maintainers":[{"name":"lweichselbaum","email":"l.weichselbaum@gmail.com"}],"contributors":[{"name":"Maud Nalpas","email":"maudn@google.com"}],"homepage":"https://github.com/google/strict-csp#readme","bugs":{"url":"https://github.com/google/strict-csp/issues"},"dist":{"shasum":"03f3769ab439156d9d92b54abda1ecc9daafcb32","tarball":"https://registry.npmjs.org/strict-csp/-/strict-csp-1.1.1.tgz","fileCount":6,"integrity":"sha512-2GGYyYg6qnNR0MWxyI2ykzoPa+5CSo6qSmTYmEb21nP/6NzuuH4aoHkN5L+qMvr/YQ9/DX4FcdO57tPJtWrTcQ==","signatures":[{"sig":"MEQCIBfipbU+OSTBo68h/0q9tUiD5CcOyfls69uIAEYLtdvnAiANz/JzP/HbMP3mSa1MF27RLass2jCtM7jZuaVJ0LRiUQ==","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":24162},"main":"build/index.js","types":"build/index.d.ts","gitHead":"9e3ae1210f2ed909a1d8b4f954c649a0615aa450","scripts":{"tsc":"tsc","lint":"eslint . --ext .ts","build":"rimraf build && tsc","auto-csp":"npm run build && node build/index.js"},"_npmUser":{"name":"lweichselbaum","email":"l.weichselbaum@gmail.com"},"prepublish":"tsc","repository":{"url":"git+https://github.com/google/strict-csp.git","type":"git","directory":"strict-csp"},"_npmVersion":"10.9.2","description":"Enables a hash-based strict Content Security Policy for static HTML files and single page applications.","directories":{},"_nodeVersion":"22.17.0","dependencies":{"cheerio":"^1.0.0-rc.5","@types/cheerio":"^0.22.23"},"_hasShrinkwrap":false,"devDependencies":{"eslint":"^7.15.0","rimraf":"^3.0.2","typescript":"^4.1.3","@types/node":"^14.14.14","@typescript-eslint/parser":"^4.10.0","@typescript-eslint/eslint-plugin":"^4.10.0"},"_npmOperationalInternal":{"tmp":"tmp/strict-csp_1.1.1_1756741640211_0.21609308059189902","host":"s3://npm-registry-packages-npm-production"}},"1.1.2":{"name":"strict-csp","version":"1.1.2","description":"Enables a hash-based strict Content Security Policy for static HTML files and single page applications.","main":"build/index.js","types":"build/index.d.ts","scripts":{"build":"rimraf build && tsc","auto-csp":"npm run build && node build/index.js","lint":"eslint . --ext .ts","tsc":"tsc","test":"npm run build && tsc --noEmit && jest"},"keywords":["csp","content-security-policy","security"],"author":{"name":"Lukas Weichselbaum","email":"lwe@google.com"},"contributors":[{"name":"Maud Nalpas","email":"maudn@google.com"}],"license":"Apache-2.0","prepublish":"tsc","repository":{"type":"git","url":"git+https://github.com/google/strict-csp.git","directory":"strict-csp"},"dependencies":{"@types/cheerio":"^0.22.23","cheerio":"^1.1.2"},"devDependencies":{"@types/jest":"^30.0.0","@types/node":"^20.0.0","@typescript-eslint/eslint-plugin":"^4.10.0","@typescript-eslint/parser":"^4.10.0","eslint":"^7.15.0","jest":"^30.1.3","rimraf":"^3.0.2","ts-jest":"^29.4.1","typescript":"^4.1.3"},"_id":"strict-csp@1.1.2","gitHead":"83f5dfadcd434e3d97030a7ebecff9b0c127511a","bugs":{"url":"https://github.com/google/strict-csp/issues"},"homepage":"https://github.com/google/strict-csp#readme","_nodeVersion":"22.17.0","_npmVersion":"10.9.2","dist":{"integrity":"sha512-UoK1QlQos+uB3hk3Wt/07/X4Mz/yV4bHc39v1c/MHOutlfKDjUuMpjre9cDNT19PBfcP2whOJDqKye6X0SOzpQ==","shasum":"78e7fe440d978c10d45d965c9d3fccfff73a6e62","tarball":"https://registry.npmjs.org/strict-csp/-/strict-csp-1.1.2.tgz","fileCount":10,"unpackedSize":32852,"signatures":[{"keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U","sig":"MEYCIQDwBSpMS4M+qda7bALHrSr9S+bisinIeZKS7IvFaOLWzAIhAOROzEKSEXLYsr+YyNn6xUOJw++JsIlxPU6zytc2U+Pj"}]},"_npmUser":{"name":"lweichselbaum","email":"l.weichselbaum@gmail.com"},"directories":{},"maintainers":[{"name":"lweichselbaum","email":"l.weichselbaum@gmail.com"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages-npm-production","tmp":"tmp/strict-csp_1.1.2_1756911317831_0.529272699988826"},"_hasShrinkwrap":false}},"time":{"created":"2021-04-01T11:15:24.066Z","modified":"2025-09-03T14:55:18.176Z","1.0.0-beta.0":"2021-04-01T11:15:24.240Z","1.0.0-beta.1":"2021-04-01T12:02:19.774Z","1.0.1":"2021-10-21T15:35:14.483Z","1.0.2":"2021-12-15T14:17:24.186Z","1.0.3":"2021-12-16T13:59:24.036Z","1.0.4":"2022-01-10T15:28:19.252Z","1.1.0":"2025-09-01T13:10:56.388Z","1.1.1":"2025-09-01T15:47:20.390Z","1.1.2":"2025-09-03T14:55:18.007Z"},"bugs":{"url":"https://github.com/google/strict-csp/issues"},"author":{"name":"Lukas Weichselbaum","email":"lwe@google.com"},"license":"Apache-2.0","homepage":"https://github.com/google/strict-csp#readme","keywords":["csp","content-security-policy","security"],"repository":{"type":"git","url":"git+https://github.com/google/strict-csp.git","directory":"strict-csp"},"description":"Enables a hash-based strict Content Security Policy for static HTML files and single page applications.","contributors":[{"name":"Maud Nalpas","email":"maudn@google.com"}],"maintainers":[{"name":"lweichselbaum","email":"l.weichselbaum@gmail.com"}],"readme":"# strict-csp\n\n[Available on npm](https://www.npmjs.com/package/strict-csp)\n\n⚠️ This is experimental. Make sure to check [what's not supported](https://github.com/google/strict-csp/issues?q=is%3Aissue+is%3Aopen+label%3Afeature). Keep in mind that the `Report-Only` mode is not supported here since the policy is added via a meta tag (`Content-Security-Policy-Report-Only` is unfortunately not supported in meta tags).\n\n## What this library does: defense-in-depth against XSS 🛡\n\n_💡 Are you using webpack? Head over to [strict-csp-html-webpack-plugin](https://github.com/google/strict-csp/tree/main/strict-csp-html-webpack-plugin) instead. It uses this library under the hood to generate a CSP you can use in your webpack project!_\n\nCross-site scripting (XSS)—the ability to inject malicious scripts into a web application—has been one of the biggest web security vulnerabilities for over a decade.\n\nstrict-csp is a **bundler-agnostic** library that helps protect your single-page application against XSS attacks. It does so by configuring a [strict, hash-based Content-Security-Policy (CSP)](https://web.dev/strict-csp) for your web application.\n\nA strict CSP, added in the form of an HTML `meta` tag, looks as follows:\n\n```html\n<meta\n      http-equiv=\"Content-Security-Policy\"\n      content=\"script-src 'sha256-3uCZp...oQxI=' 'strict-dynamic'; style-src 'self' 'unsafe-inline'\">\n</meta>\n```\n\n## Example usage\n\nLet's say that `htmlString` is your SPA's html as a string.\n\n```javascript\nconst s = new StrictCsp(htmlString);\n// Refactor sourced scripts so that we can set a strict hash-based CSP\ns.refactorSourcedScriptsForHashBasedCsp();\n// Hash inline scripts from this html file, if there are any\nconst scriptHashes = s.hashAllInlineScripts();\n// Generate a strict CSP as a string\nconst strictCsp = StrictCsp.getStrictCsp(scriptHashes, {\n  enableBrowserFallbacks: true,\n});\n// Set this CSP via a meta tag\ns.addMetaTag(strictCsp);\nconst htmlStringWithCsp = s.serializeDom();\n```\n\n**TL;DR: this library automates the steps to [add a hash-based strict CSP to your site](https://web.dev/strict-csp/#adopting-a-strict-csp).**\n\n## Arguments for the options object in `getStrictCsp`\n\nBy default, strict-csp will generate up a valid, strict, hash-based CSP.\n\nYou can use additional options to configure it:\n\n| Option                                        | What it does                                                                                                            |\n| --------------------------------------------- | ----------------------------------------------------------------------------------------------------------------------- |\n| `enableBrowserFallbacks` (defaults to `true`) | When `true`, enables fallbacks for older browsers. This does not weaken the policy.                                     |\n| `enableTrustedTypes` (defaults to `false`)    | When `true`, enables [trusted types](https://web.dev/trusted-types) for additional protections against DOM XSS attacks. |\n| `enableUnsafeEval` (defaults to `false`)      | When `true`, enables [unsafe-eval](https://web.dev/strict-csp/) in case you cannot remove all uses of `eval()`.         |\n\n## How does this library work?\n\nHere's what the library does:\n\n1. It replaces sourced scripts with an inline script that dynamically loads all sourced scripts. It calculates the hash of this script.\n2. It calculates the hash of other inline scripts.\n3. It creates a strict hash-based CSP, that includes the hashes calculated in (1) and (2).\n\nThis CSP efficiently helps protect your site against XSS. This CSP is set in a `meta` tag. It looks like this:\n\n`script-src {HASH-INLINE-SCRIPT} 'strict-dynamic'; object-src 'none'; base-uri 'none';`.\n\n`{HASH-INLINE-SCRIPT}` is the hash on the inline script that dynamically loads all sourced scripts.\n\n**TL;DR: this library automates the steps to [add a hash-based CSP to your site](https://web.dev/strict-csp/#:~:text=Option%20B%3A%20Hash-based%20CSP%20Response%20Header).**\n\n## Resources\n\n- [Mitigate cross-site scripting (XSS) with a strict Content Security Policy (CSP)](https://web.dev/strict-csp/)\n","readmeFilename":"README.md"}