NewYour coding agent can read the release notes before it upgrades.Set up the MCP server →
NuGet · #1872 most downloaded on NuGet
Middleware for ASP.NET Core to automatically add security headers to requests.
Last release 9 months ago
20 Dec 2025
Release timing varies
gaps range from 2 weeks to 9 months
Most releases are documented
notes for 24 of 36 stable releases
Nothing withdrawn
no release was ever pulled
10 years old
37 releases · first in 2016
Fix WithHashTagHelper() using incorrect tag helper hashes for style-src, style-src-attr, and style-scr-elem CSP directives
Fixes:
WithHashTagHelper() using incorrect tag helper hashes for style-src, style-src-attr, and style-scr-elem CSP directives (#279)Breaking Changes:
WithHashTagHelper() on CustomDirectiveBuilder or DefaultSourceDirectiveBuilder - technically breaking, but really a bug (#279)Features:
OverInsecureHttp() and OverInsecureWs() scheme sources to CSP builders #273Features:
child-src to Content-Security-Policy #259AddSecurityHeadersPolicies() for registering named polices #250Fixes:
Features:
AddRange() to SourceCollection #240, #242 (Thanks @rankobp)X-Frame-Options ALLOW-FROM with correct method name AddFrameOptionsAllowFrom() #244This marks the first major release of the NetEscapades.AspNetCore.SecurityHeaders. For simplicity, all the changes since 0.24.0 are included below.
Breaking Changes:
X-XSS-Protection from default headers and mark obsolete #168cross-origin-opener-policy: same-origin to default headers #184Feature-Policy as obsolete #187Expect-CT as obsolete #197HttpContext.GetNonce() #198DefaultSecureDirectives() for permissions policy #203 (Thanks damienbod!)AddDefaultSecurityHeaders() and AddDefaultApiSecurityHeaders() #204 (Thanks damienbod!)Features:
HeaderPolicyCollection just before it is applied, customizing per request #174, #185Content-Security-Policy idempotent to avoid duplicates #169AddDefaultApiSecurityHeaders() for adding default headers to APIs #183, #184AddPermissionsPolicyWithRecommendedDirectives() and PermissionsPolicyBuilder.AddDefaultSecureDirectives() for adding secure Permissions-Policy directives in bulk #183, #184IServiceProvider when configuring a SecurityHeaderPolicyBuilder #200Build updates:
Allow building from forks #232
Fix release generation #231, #235, #236
Fix recording test results #221
Define version in the build project instead #223
Generate SBOM #222
Generate SBOM attestation #224
Generate artifact provenance attestation #225
Automatically create releases #229
See https://github.com/andrewlock/NetEscapades.AspNetCore.SecurityHeaders/blob/master/CHANGELOG.md#v131 for more details.
One column per quarter.
Fixes:
WithHashTagHelper() using incorrect tag helper hashes for style-src, style-src-attr, and style-scr-elem CSP directives (#279)Breaking Changes:
WithHashTagHelper() on CustomDirectiveBuilder or DefaultSourceDirectiveBuilder - technically breaking, but really a bug (#279)Features:
OverInsecureHttp() and OverInsecureWs() scheme sources to CSP builders #273Features:
child-src to Content-Security-Policy #259AddSecurityHeadersPolicies() for registering named polices #250Fixes:
Features:
AddRange() to SourceCollection #240, #242 (Thanks @rankobp)X-Frame-Options ALLOW-FROM with correct method name AddFrameOptionsAllowFrom() #244This marks the first major release of the NetEscapades.AspNetCore.SecurityHeaders. For simplicity, all the changes since 0.24.0 are included below.
Breaking Changes:
X-XSS-Protection from default headers and mark obsolete #168cross-origin-opener-policy: same-origin to default headers #184Feature-Policy as obsolete #187Expect-CT as obsolete #197HttpContext.GetNonce() #198DefaultSecureDirectives() for permissions policy #203 (Thanks damienbod!)AddDefaultSecurityHeaders() and AddDefaultApiSecurityHeaders() #204 (Thanks damienbod!)Features:
HeaderPolicyCollection just before it is applied, customizing per request #174, #185Content-Security-Policy idempotent to avoid duplicates #169AddDefaultApiSecurityHeaders() for adding default headers to APIs #183, #184AddPermissionsPolicyWithRecommendedDirectives() and PermissionsPolicyBuilder.AddDefaultSecureDirectives() for adding secure Permissions-Policy directives in bulk #183, #184IServiceProvider when configuring a SecurityHeaderPolicyBuilder #200Build updates:
All NuGet packages are available on https://www.nuget.org. You can view the build provenance attestation
for the NuGet packages here.
The Software Bill of Materials (SBOM) is available for each package in CycloneDX format. View the provenance
attestations for the SBOMs here:
Note
You cannot assert the provenance of the .nupkg packages downloaded from nuget.org directly. First, you
must remove the .signature.p7s file, as described here.
Add API for registering an async policy selector #259 (Thanks @jchannon)
Features:
OverInsecureHttp() and OverInsecureWs() scheme sources to CSP builders #273Features:
child-src to Content-Security-Policy #259AddSecurityHeadersPolicies() for registering named polices #250Fixes:
Features:
AddRange() to SourceCollection #240, #242 (Thanks @rankobp)X-Frame-Options ALLOW-FROM with correct method name AddFrameOptionsAllowFrom() #244This marks the first major release of the NetEscapades.AspNetCore.SecurityHeaders. For simplicity, all the changes since 0.24.0 are included below.
Breaking Changes:
X-XSS-Protection from default headers and mark obsolete #168cross-origin-opener-policy: same-origin to default headers #184Feature-Policy as obsolete #187Expect-CT as obsolete #197HttpContext.GetNonce() #198DefaultSecureDirectives() for permissions policy #203 (Thanks damienbod!)AddDefaultSecurityHeaders() and AddDefaultApiSecurityHeaders() #204 (Thanks damienbod!)Features:
HeaderPolicyCollection just before it is applied, customizing per request #174, #185Content-Security-Policy idempotent to avoid duplicates #169AddDefaultApiSecurityHeaders() for adding default headers to APIs #183, #184AddPermissionsPolicyWithRecommendedDirectives() and PermissionsPolicyBuilder.AddDefaultSecureDirectives() for adding secure Permissions-Policy directives in bulk #183, #184IServiceProvider when configuring a SecurityHeaderPolicyBuilder #200Build updates:
Allow building from forks #232
Fix release generation #231, #235, #236
Fix recording test results #221
Define version in the build project instead #223
Generate SBOM #222
Generate SBOM attestation #224
Generate artifact provenance attestation #225
Automatically create releases #229
See https://github.com/andrewlock/NetEscapades.AspNetCore.SecurityHeaders/blob/master/CHANGELOG.md#v130 for more details.
Features:
OverInsecureHttp() and OverInsecureWs() scheme sources to CSP builders #273Features:
child-src to Content-Security-Policy #259AddSecurityHeadersPolicies() for registering named polices #250Fixes:
Features:
AddRange() to SourceCollection #240, #242 (Thanks @rankobp)X-Frame-Options ALLOW-FROM with correct method name AddFrameOptionsAllowFrom() #244This marks the first major release of the NetEscapades.AspNetCore.SecurityHeaders. For simplicity, all the changes since 0.24.0 are included below.
Breaking Changes:
X-XSS-Protection from default headers and mark obsolete #168cross-origin-opener-policy: same-origin to default headers #184Feature-Policy as obsolete #187Expect-CT as obsolete #197HttpContext.GetNonce() #198DefaultSecureDirectives() for permissions policy #203 (Thanks damienbod!)AddDefaultSecurityHeaders() and AddDefaultApiSecurityHeaders() #204 (Thanks damienbod!)Features:
HeaderPolicyCollection just before it is applied, customizing per request #174, #185Content-Security-Policy idempotent to avoid duplicates #169AddDefaultApiSecurityHeaders() for adding default headers to APIs #183, #184AddPermissionsPolicyWithRecommendedDirectives() and PermissionsPolicyBuilder.AddDefaultSecureDirectives() for adding secure Permissions-Policy directives in bulk #183, #184IServiceProvider when configuring a SecurityHeaderPolicyBuilder #200Build updates:
All NuGet packages are available on https://www.nuget.org. You can view the build provenance attestation
for the NuGet packages here.
The Software Bill of Materials (SBOM) is available for each package in CycloneDX format. View the provenance
attestations for the SBOMs here:
Note
You cannot assert the provenance of the .nupkg packages downloaded from nuget.org directly. First, you
must remove the .signature.p7s file, as described here.
Add support for child-src to Content-Security-Policy #259
Features:
child-src to Content-Security-Policy #259AddSecurityHeadersPolicies() for registering named polices #250Fixes:
Features:
AddRange() to SourceCollection #240, #242 (Thanks @rankobp)X-Frame-Options ALLOW-FROM with correct method name AddFrameOptionsAllowFrom() #244This marks the first major release of the NetEscapades.AspNetCore.SecurityHeaders. For simplicity, all the changes since 0.24.0 are included below.
Breaking Changes:
X-XSS-Protection from default headers and mark obsolete #168cross-origin-opener-policy: same-origin to default headers #184Feature-Policy as obsolete #187Expect-CT as obsolete #197HttpContext.GetNonce() #198DefaultSecureDirectives() for permissions policy #203 (Thanks damienbod!)AddDefaultSecurityHeaders() and AddDefaultApiSecurityHeaders() #204 (Thanks damienbod!)Features:
HeaderPolicyCollection just before it is applied, customizing per request #174, #185Content-Security-Policy idempotent to avoid duplicates #169AddDefaultApiSecurityHeaders() for adding default headers to APIs #183, #184AddPermissionsPolicyWithRecommendedDirectives() and PermissionsPolicyBuilder.AddDefaultSecureDirectives() for adding secure Permissions-Policy directives in bulk #183, #184IServiceProvider when configuring a SecurityHeaderPolicyBuilder #200Build updates:
Changes from 1.0.0-preview.4 to 1.0.0:
Features:
child-src to Content-Security-Policy #259AddSecurityHeadersPolicies() for registering named polices #250Fixes:
Features:
AddRange() to SourceCollection #240, #242 (Thanks @rankobp)X-Frame-Options ALLOW-FROM with correct method name AddFrameOptionsAllowFrom() #244This marks the first major release of the NetEscapades.AspNetCore.SecurityHeaders. For simplicity, all the changes since 0.24.0 are included below.
Breaking Changes:
X-XSS-Protection from default headers and mark obsolete #168cross-origin-opener-policy: same-origin to default headers #184Feature-Policy as obsolete #187Expect-CT as obsolete #197HttpContext.GetNonce() #198DefaultSecureDirectives() for permissions policy #203 (Thanks damienbod!)AddDefaultSecurityHeaders() and AddDefaultApiSecurityHeaders() #204 (Thanks damienbod!)Features:
HeaderPolicyCollection just before it is applied, customizing per request #174, #185Content-Security-Policy idempotent to avoid duplicates #169AddDefaultApiSecurityHeaders() for adding default headers to APIs #183, #184AddPermissionsPolicyWithRecommendedDirectives() and PermissionsPolicyBuilder.AddDefaultSecureDirectives() for adding secure Permissions-Policy directives in bulk #183, #184IServiceProvider when configuring a SecurityHeaderPolicyBuilder #200Build updates:
Changes from 1.0.0-preview.4 to 1.0.0:
All NuGet packages are available on https://www.nuget.org. You can view the build provenance attestation
for the NuGet packages here.
The Software Bill of Materials (SBOM) is available for each package in CycloneDX format. View the provenance
attestations for the SBOMs here:
Note
You cannot assert the provenance of the .nupkg packages downloaded from nuget.org directly. First, you
must remove the .signature.p7s file, as described here.
Add AddRange() to SourceCollection #240, #242 (Thanks @rankobp)
Features:
AddRange() to SourceCollection #240, #242 (Thanks @rankobp)X-Frame-Options ALLOW-FROM with correct method name AddFrameOptionsAllowFrom() #244This marks the first major release of the NetEscapades.AspNetCore.SecurityHeaders. For simplicity, all the changes since 0.24.0 are included below.
Breaking Changes:
X-XSS-Protection from default headers and mark obsolete #168cross-origin-opener-policy: same-origin to default headers #184Feature-Policy as obsolete #187Expect-CT as obsolete #197HttpContext.GetNonce() #198DefaultSecureDirectives() for permissions policy #203 (Thanks damienbod!)AddDefaultSecurityHeaders() and AddDefaultApiSecurityHeaders() #204 (Thanks damienbod!)Features:
HeaderPolicyCollection just before it is applied, customizing per request #174, #185Content-Security-Policy idempotent to avoid duplicates #169AddDefaultApiSecurityHeaders() for adding default headers to APIs #183, #184AddPermissionsPolicyWithRecommendedDirectives() and PermissionsPolicyBuilder.AddDefaultSecureDirectives() for adding secure Permissions-Policy directives in bulk #183, #184IServiceProvider when configuring a SecurityHeaderPolicyBuilder #200Build updates:
Changes from 1.0.0-preview.4 to 1.0.0:
Features:
AddRange() to SourceCollection #240, #242 (Thanks @rankobp)X-Frame-Options ALLOW-FROM with correct method name AddFrameOptionsAllowFrom() #244This marks the first major release of the NetEscapades.AspNetCore.SecurityHeaders. For simplicity, all the changes since 0.24.0 are included below.
Breaking Changes:
X-XSS-Protection from default headers and mark obsolete #168cross-origin-opener-policy: same-origin to default headers #184Feature-Policy as obsolete #187Expect-CT as obsolete #197HttpContext.GetNonce() #198DefaultSecureDirectives() for permissions policy #203 (Thanks damienbod!)AddDefaultSecurityHeaders() and AddDefaultApiSecurityHeaders() #204 (Thanks damienbod!)Features:
HeaderPolicyCollection just before it is applied, customizing per request #174, #185Content-Security-Policy idempotent to avoid duplicates #169AddDefaultApiSecurityHeaders() for adding default headers to APIs #183, #184AddPermissionsPolicyWithRecommendedDirectives() and PermissionsPolicyBuilder.AddDefaultSecureDirectives() for adding secure Permissions-Policy directives in bulk #183, #184IServiceProvider when configuring a SecurityHeaderPolicyBuilder #200Build updates:
Changes from 1.0.0-preview.4 to 1.0.0:
All NuGet packages are available on https://www.nuget.org. You can view the build provenance attestation
for the NuGet packages here.
The Software Bill of Materials (SBOM) is available for each package in CycloneDX format. View the provenance
attestations for the SBOMs here:
Note
You cannot assert the provenance of the .nupkg packages downloaded from nuget.org directly. First, you
must remove the .signature.p7s file, as described here.
This marks the first major release of the _NetEscapades.AspNetCore.SecurityHeaders_. For simplicity, all the changes since 0.24.0 are included below.
This marks the first major release of the NetEscapades.AspNetCore.SecurityHeaders. For simplicity, all the changes since 0.24.0 are included below.
Breaking Changes:
X-XSS-Protection from default headers and mark obsolete #168cross-origin-opener-policy: same-origin to default headers #184Feature-Policy as obsolete #187Expect-CT as obsolete #197HttpContext.GetNonce() #198DefaultSecureDirectives() for permissions policy #203 (Thanks damienbod!)AddDefaultSecurityHeaders() and AddDefaultApiSecurityHeaders() #204 (Thanks damienbod!)Features:
HeaderPolicyCollection just before it is applied, customizing per request #174, #185Content-Security-Policy idempotent to avoid duplicates #169AddDefaultApiSecurityHeaders() for adding default headers to APIs #183, #184AddPermissionsPolicyWithRecommendedDirectives() and PermissionsPolicyBuilder.AddDefaultSecureDirectives() for adding secure Permissions-Policy directives in bulk #183, #184IServiceProvider when configuring a SecurityHeaderPolicyBuilder #200Build updates:
Changes from 1.0.0-preview.4 to 1.0.0:
This marks the first major release of the NetEscapades.AspNetCore.SecurityHeaders. For simplicity, all the changes since 0.24.0 are included below.
Breaking Changes:
X-XSS-Protection from default headers and mark obsolete #168cross-origin-opener-policy: same-origin to default headers #184Feature-Policy as obsolete #187Expect-CT as obsolete #197HttpContext.GetNonce() #198DefaultSecureDirectives() for permissions policy #203 (Thanks @damienbod!)AddDefaultSecurityHeaders() and AddDefaultApiSecurityHeaders() #204 (Thanks @damienbod)!)Features:
HeaderPolicyCollection just before it is applied, customizing per request #174, #185Content-Security-Policy idempotent to avoid duplicates #169AddDefaultApiSecurityHeaders() for adding default headers to APIs #183, #184AddPermissionsPolicyWithRecommendedDirectives() and PermissionsPolicyBuilder.AddDefaultSecureDirectives() for adding secure Permissions-Policy directives in bulk #183, #184IServiceProvider when configuring a SecurityHeaderPolicyBuilder #200Build updates:
Changes from 1.0.0-preview.4 to 1.0.0:
All NuGet packages are available on https://www.nuget.org. You can view the build provenance attestation
for the NuGet packages here.
The Software Bill of Materials (SBOM) is available for each package in CycloneDX format. View the provenance
attestations for the SBOMs here:
Note
You cannot assert the provenance of the .nupkg packages downloaded from nuget.org directly. First, you
must remove the .signature.p7s file, as described here.
Allow adding multiple uris to CSP builder AddFrameAncestors() #179
Features:
AddFrameAncestors() #179Permissions-Policy header #177 (Thanks @Registeel!)See https://github.com/andrewlock/NetEscapades.AspNetCore.SecurityHeaders/blob/master/CHANGELOG.md#v0240 for more details.
Add support for unsafe-hashes on style attributes, and inline event handlers #162 (Thanks @tiesmaster!)
Features:
unsafe-hashes on style attributes, and inline event handlers #162 (Thanks @tiesmaster!)See https://github.com/andrewlock/NetEscapades.AspNetCore.SecurityHeaders/blob/master/CHANGELOG.md#v0230 for more details.
Add support for Cross-Origin-Embedder-Policy: credentialless #153 (Thanks RaceProUK!)
Features:
Cross-Origin-Embedder-Policy: credentialless #153 (Thanks RaceProUK!)Bugfix:
StyleSourceAttr and StyleSourceElem directives #152 (Thanks ThomasBjallas!)Add support for using both 'none' and 'report-sample' in directives
Features:
'none' and 'report-sample' in directivesSee https://github.com/andrewlock/NetEscapades.AspNetCore.SecurityHeaders/blob/master/CHANGELOG.md#v0210 for more details.
Add support for script-src-attr, script-src-elem, style-src-attr, style-src-elem #139
Features:
script-src-attr, script-src-elem, style-src-attr, style-src-elem #139See https://github.com/andrewlock/NetEscapades.AspNetCore.SecurityHeaders/blob/master/CHANGELOG.md#v0200 for more details.
Apply "document" headers to text/javascript responses
Features:
text/javascript responsesAdd support for applying document headers (such as CSP) to all responses
Features:
unsafe-hashes and wasm-unsafe-eval (#125)Bugfix:
application/javascript in addition to text/html (#130)Fix Cross-Origin-Embedder-Policy (COEP) not being added to non-HTML requests
Bugfix:
Cross-Origin-Embedder-Policy (COEP) not being added to non-HTML requestsFix Cross-Origin-Resource-Policy (CORP) not being added to non-HTML requests
Bugfix:
Cross-Origin-Resource-Policy (CORP) not being added to non-HTML requestsAdded support for Cross-Origin-Opener-Policy (COOP), Cross-Origin-Embedder-Policy (COEP) and Cross-Origin-Resource-Policy (CORP) (Thanks @jeremylindsa
Features:
Cross-Origin-Opener-Policy (COOP), Cross-Origin-Embedder-Policy (COEP) and Cross-Origin-Resource-Policy (CORP) (Thanks @jeremylindsayni!)Add support for creating custom CSP directives with CspDirectiveBuilder. Enables creating custom directives (for example unsupported, draft, directive
Features:
CspDirectiveBuilder. Enables creating custom directives (for example unsupported, draft, directives) that require nonce or hash valuesBugFix:
EncryptedMedia directive to permissions policy (Thanks @jotoledo)Rename AddFrameSource() -> AddFrameSrc() for consistency, and deprecate AddFrameSource()
Features:
interest-cohort=() in Permissions-Policy directive (Thanks @jeremylindsayni!)BugFix:
AddFrameSource() -> AddFrameSrc() for consistency, and deprecate AddFrameSource()Add support for report-sample in style-src directive for CSP (Thanks @jeremylindsayni!)
Features:
report-sample in style-src directive for CSP (Thanks @jeremylindsayni!)Fix API inconsistencies between Permissions-Policy and Feature-Policy (Thanks @Rtalos!)
BugFix:
Add support for manifest-src directive in CSP (Thanks @jotatoledo!)
Features:
manifest-src directive in CSP (Thanks @jotatoledo!)Permissions-Policy (supersedes Feature-Policy) (Thanks @Rtalos!)Switch to standard MIT SPDX license
Minor:
Nothing published for this version
Add support for Expect-CT header. Allows excluding domains that will not have the Expect-CT header applied. By default, the Expect-CT header will not
Features:
Expect-CT header. Allows excluding domains that will not have the Expect-CT header applied. By default, the Expect-CT header will not be applied to localhost. It is also only applied to HTTPS requestsworker-src directive for Content-Security-Policy headerDrop support for ASP.NET Core 1.x
Breaking Changes:
If you're using the recommended builders and extension methods, you should not have any build-time breaking changes, but the package is not runtime-co…
Features:
Content-Security-Policy headers. See README.md for detailsStrict-Transport-SecurityStrict-Transport-Security. Similar to the Microsoft HstsMiddleware, you can skip applying Strict-Transport-Security to specific hostsBreaking Changes:
Strict-Transport-Security header is no longer applied to localhost by default. Generally speaking, this isn't something you should do anyway.Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Your coding agent can read these notes before it upgrades. Set up the MCP server →