Replies: 7 comments 5 replies
-
💬 Your Product Feedback Has Been Submitted 🎉 Thank you for taking the time to share your insights with us! Your feedback is invaluable as we build a better GitHub experience for all our users. Here's what you can expect moving forward ⏩
Where to look to see what's shipping 👀
What you can do in the meantime 💻
As a member of the GitHub community, your participation is essential. While we can't promise that every suggestion will be implemented, we want to emphasize that your feedback is instrumental in guiding our decisions and priorities. Thank you once again for your contribution to making GitHub even better! We're grateful for your ongoing support and collaboration in shaping the future of our platform. ⭐ |
BetaWas this translation helpful?Give feedback.
This comment was marked as off-topic.
This comment was marked as off-topic.
-
Have the issue as well It is affecting New Token generation, and it is quite a huge problem in light of Strengthening npm security: Important changes to authentication and token management |
BetaWas this translation helpful?Give feedback.
Uh oh!
There was an error while loading. Please reload this page.
Uh oh!
There was an error while loading. Please reload this page.
-
This is still an issue after login: Happens in Chrome, Brave and Firefox. Context for: GET: Headers direct access in browser address bar (opens the contents correctly): GET: Header (Network resources when on npmjs.com): After additional testing: It works when I use my mobile network to connect but not my normal internet connection; |
BetaWas this translation helpful?Give feedback.
-
Just use the mobile hotpot, it works well... |
BetaWas this translation helpful?Give feedback.
-
Refused to connect to 'https://static-production.npmjs.com/commons.149ed37e6f8137f65e39.js.map' because it violates the following Content Security Policy directive: "connect-src 'self' checkout.stripe.com https://checkout.stripe.comhttps://billing.stripe.com/sessionhttps://api.funcaptcha.comhttps://api.arkoselabs.com sentry.io api.github.com www.npmjs.com". same thing when logging in after changing password! |
BetaWas this translation helpful?Give feedback.
-
BetaWas this translation helpful?Give feedback.

Uh oh!
There was an error while loading. Please reload this page.
-
Select Topic Area
Bug
Body
I’m experiencing an issue with the npmjs admin dashboard where it fails to load correctly due to a Content Security Policy (CSP) violation. The browser console shows the following error:
Refused to connect to 'https://static-production.npmjs.com/styles.4ddf61b895c5feda30f4.css.map'
because it violates the following Content Security Policy directive:
"connect-src 'self' checkout.stripe.com https://checkout.stripe.com
https://billing.stripe.com/sessionhttps://api.funcaptcha.com
https://api.arkoselabs.com sentry.io api.github.com www.npmjs.com".
This appears to be preventing some parts of the dashboard UI from functioning properly.
BetaWas this translation helpful?Give feedback.
All reactions