Skip to content

Remove deprecated X-XSS-Protection header#28

Merged
MarceloRGonc merged 1 commit intomainfrom
mg/OPS-4149
Apr 15, 2026
Merged

Remove deprecated X-XSS-Protection header#28
MarceloRGonc merged 1 commit intomainfrom
mg/OPS-4149

Conversation

@MarceloRGonc
Copy link
Copy Markdown
Contributor

Part of OPS-4149

Copilot AI review requested due to automatic review settings April 15, 2026 14:32
@linear
Copy link
Copy Markdown

linear bot commented Apr 15, 2026

Copy link
Copy Markdown

Copilot AI left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Removes the deprecated X-XSS-Protection HTTP response header from the NGINX gateway configuration, aligning the chart’s security headers with modern browser behavior (OPS-4149).

Changes:

  • Removed add_header X-XSS-Protection "1; mode=block" always; from the NGINX ConfigMap template.

💡 Add Copilot custom instructions for smarter, more guided reviews. Learn how to get started.

@MarceloRGonc MarceloRGonc merged commit ae52658 into main Apr 15, 2026
7 checks passed
@MarceloRGonc MarceloRGonc deleted the mg/OPS-4149 branch April 15, 2026 19:07
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants