github/secure_headers

Manages application of security headers with many safe defaults

View on GitHub ↗Jump to charts ↓Open shareable report →

Data as of . Signed-in members get hourly updates — create a free account.

Summary Information

Updated 37 minutes ago
Added to GitGenius on September 21st, 2026
Created on December 12th, 2012
Open Issues & Pull Requests: 13 (+0)
GitHub issues: Enabled
Number of forks: 251
Total Stargazers: 3,227 (+0)
Total Subscribers: 166 (+0)

Repository Insights (GitGenius)

Median issue/PR response: 17.5 hours
Mean response time: 272.3 days
90th percentile: 748.5 days
Tracked items: 21

Maintainer activity

1 person did triage or write work on this repository in the last 12 months.

Counts unlabeled, assigned, unassigned, milestoned, demilestoned, locked, unlocked over the last 12 months. These are issue and pull request events that require triage or write permission. Commits and code review are not counted. labeled and renamed are excluded because GitHub issue forms record the issue author as the actor. Figures from October 7, 2026. This count is not comparable across projects: each project's automation decides which of these events a person emits.

Charts & Analytics

Fetching additional details & charts...

Issue Activity (beta)

Open issues: 4
New in 7 days: 0
Closed in 7 days: 0
Avg open age: 1,137 days
Stale 30+ days: 4
Stale 90+ days: 4

Recent activity

Opened in 7 days: 0
Closed in 7 days: 0
Comments in 7 days: 0
Events in 7 days: 0

Top labels

  • feature (2)
  • 3.x (1)
  • 4.x (1)
  • bug (1)
  • enhancement (1)
  • good first issue (1)
  • question (1)

Most active issues this week

Sign in to see which issues are moving.
Sign in

Detailed Description

secure_headers is a Ruby middleware that manages the application of HTTP security headers with safe defaults.

The tool addresses the challenge of consistently applying security headers across web applications. Rather than requiring developers to manually configure each header, it provides sensible defaults for common security headers including content security policy, HSTS, X-Frame-Options, referrer policy, and cookie security settings. The middleware integrates into the Rack request-response cycle, allowing centralized header management that applies across an entire application.

Developers building Ruby web applications should consider this tool if they want to enforce security headers without extensive manual configuration. It suits projects that need to meet security compliance requirements or follow defense-in-depth practices. The approach of providing safe defaults means teams can adopt strong security postures immediately while retaining the ability to customize headers for specific application needs.

The project shows consistent maintenance with regular updates addressing security concerns and evolving web standards. Development activity demonstrates responsiveness to issues and pull requests, indicating active stewardship of the codebase. The maintainers engage with the community on security-related discussions and incorporate feedback into the tool's evolution.