@deepfence @navaltiger @kubesploit Hi Vijay - if you're having problems and want to talk directly to someone, feel free to DM me, thanks. Alternatively, GitHub issues or slack are good ways to get in touch
The open-source project of the week Threatmapper is a cloud-native security observability platform that scans, maps, and ranks vulnerabilities from development through production across serverless, Kubernetes, container, and multi-cloud environments. https://t.co/CyuzaOCM9J
@bertjwregeer @crlowell@IanColdwater Hi @bertjwregeer - I work for NGINX but am not on the security-alert alias. I've raised this to the right people. Not sure when you sent the email, but if you asked for an ack, you should receive a response soon. Thanks for following up
@rmhrisk As it becomes more widely used, we will look again options to improve the configuration with NGINX, without complicating or compromising the architecture and performance, and I hope other parties will also follow
@rmhrisk Great research in that paper. NGINX /can/ be configured to play its part in Must-Staple using either of the two workarounds documentedin this thread. I think the biggest impediment is that only Firefox supports the Must-Staple extension...