Skip to content

fix(csp): allow HTTPS images in report-only img-src - #3154

Merged
JacobCoffee merged 2 commits into
mainfrom
fix/csp-img-src
Oct 6, 2026
Merged

JacobCoffee merged 2 commits into
mainfrom
fix/csp-img-src

Conversation

@JacobCoffee

Copy link
Copy Markdown
Member

CSP allowed imgs pile up, each view of downloads is 7-8 images == 7-8 CSP reports and a lot of people visit /downloads

/downloads/ and release pages load media from the S3 endpoint
(s3.dualstack.us-east-2.amazonaws.com), devguide.python.org and
images embedded in release notes (hugovk.dev, GitHub). None matched
img-src, so every page view sent several violation reports; ~5M
reports between Sep 30 and Oct 3 exhausted the PSF Sentry quota.

Refs #3041
Copilot AI balanced review requested due to automatic review settings October 6, 2026 14:14

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot was unable to review this pull request because the user who requested the review has reached their quota limit.

@chatgpt-codex-connector

Copy link
Copy Markdown

You have reached your Codex usage limits for code reviews. You can see your limits in the Codex usage dashboard.

@JacobCoffee
JacobCoffee merged commit d5d0c03 into main Oct 6, 2026
12 checks passed
@JacobCoffee
JacobCoffee deleted the fix/csp-img-src branch October 6, 2026 14:32
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants