Skip to content

Conversation

@ratesangelo
Copy link

The Expect-CT header is deprecated. This header was used to enforce Certificate Transparency (CT) requirements, but it is no longer recommended for use. Chromium-based browsers, such as Google Chrome, deprecated the Expect-CT header starting from version 107, as they now enforce CT by default

Summary

Screenshots (optional)

Documentation checklist

  • The documentation style guide has been adhered to.
  • If a larger change - such as adding a new page- an issue has been opened in relation to any incorrect or out of date information that this PR fixes.
  • Files which have changed name or location have been allocated redirects.

The Expect-CT header is deprecated. This header was used to enforce Certificate Transparency (CT) requirements, but it is no longer recommended for use. Chromium-based browsers, such as Google Chrome, deprecated the Expect-CT header starting from version 107, as they now enforce CT by default
@ratesangelo ratesangelo requested review from a team and pedrosousa as code owners April 15, 2025 14:59
@hyperlint-ai
Copy link
Contributor

hyperlint-ai bot commented Apr 15, 2025

Howdy and thanks for contributing to our repo. The Cloudflare team reviews new, external PRs within two (2) weeks. If it's been two weeks or longer without any movement, please tag the PR Assignees in a comment.

We review internal PRs within 1 week. If it's something urgent or has been sitting without a comment, start a thread in the Developer Docs space internally.


PR Change Summary

Updated documentation to reflect the deprecation of the Expect-CT header in Chromium-based browsers.

  • Removed the Expect-CT header from the security-related HTTP response headers section.
  • Clarified that Chromium-based browsers enforce Certificate Transparency by default starting from version 107.

Modified Files

  • src/content/docs/rules/transform/managed-transforms/reference.mdx

How can I customize these reviews?

Check out the Hyperlint AI Reviewer docs for more information on how to customize the review.

If you just want to ignore it on this PR, you can add the hyperlint-ignore label to the PR. Future changes won't trigger a Hyperlint review.

Note specifically for link checks, we only check the first 30 links in a file and we cache the results for several hours (for instance, if you just added a page, you might experience this). Our recommendation is to add hyperlint-ignore to the PR to ignore the link check for this PR.

@github-actions github-actions bot added the product:rules Related to rules label Apr 15, 2025
@pedrosousa
Copy link
Contributor

Hello @ratesangelo
Thank you for the heads up. I've shared this information internally.
However, the "Add security headers" Managed Transform, when enabled, still adds the header, so we will keep the documentation as is for now.

@pedrosousa pedrosousa closed this Apr 15, 2025
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

product:rules Related to rules size/xs

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants