mirror of
https://github.com/lunchcat/sif.git
synced 2026-06-12 19:11:25 -07:00
7efd62c804
adds a -sh/--security-headers scan that flags missing or weak response headers (hsts, csp, x-frame-options, x-content-type-options, referrer-policy, permissions-policy, coop) and headers that leak server internals (server, x-powered-by, ...). hsts is only graded over https where it actually applies. wired into App.Run and the module results.