Skip to content

Tighten CSP rules - #86

Merged
kjlubick merged 1 commit into
NVIDIA:developfrom
kjlubick:csp-check
Sep 23, 2026
Merged

kjlubick merged 1 commit into
NVIDIA:developfrom
kjlubick:csp-check

Conversation

@kjlubick

@kjlubick kjlubick commented Sep 15, 2026 •

Copy link
Copy Markdown
Collaborator

Description

As a defense-in-depth practice, we want to limit CSP to the minimum viable set. This PR removes seemingly extraneous scopes and should not affect any UX.

Release intent

Changelog title

n/a

Changelog body

n/a

Bumps

  • services: none
  • nvpair-cluster-manager: none
  • nvpair-engine-manager: none
  • nvpair-errors: none
  • nvpair-job-scheduler: none
  • nvpair-manual-nodes: none
  • nvpair-node-info: none
  • nvpair-node-scanner: none
  • nvpair-node-settings: none
  • nvpair-proxy: none
  • nvpair-tui: none
  • nvpair-ui-broker: none
  • nvpair-workload-manager: none

Scope

This only protects the UI, not any server side code.

Validation

New test added and run locally.

Risk

This only affects the UI, so I don't believe any services need to have a version bump

Checklist

  • I have read the Contributing Guidelines.
  • Every commit is signed off (git commit -s), certifying the Developer Certificate of Origin.
  • New or existing tests cover the change.
  • Relevant documentation is updated.
  • I checked the diff, changed filenames, and commit messages for credentials, private data, internal URLs, internal issue identifiers, and generated artifacts.
  • I recorded the validation commands and results above.
  • I declared version bumps in the release-intent block above. services/versions.json is written by automation — do not edit it by hand.

I don't see any pdf.js code, so I presume we don't need this.

Signed-off-by: Kaylee Lubick <klubick@nvidia.com>
@kjlubick
kjlubick merged commit 99dc95d into NVIDIA:develop Sep 23, 2026
1 check passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants