{"id":51124546,"url":"https://github.com/google/nginx-sxg-module","last_synced_at":"2026-06-25T06:01:28.502Z","repository":{"id":45698289,"uuid":"212476728","full_name":"google/nginx-sxg-module","owner":"google","description":"NGINX SXG module","archived":true,"fork":false,"pushed_at":"2021-11-03T17:30:56.000Z","size":203,"stargazers_count":85,"open_issues_count":19,"forks_count":16,"subscribers_count":7,"default_branch":"main","last_synced_at":"2026-06-11T18:28:57.963Z","etag":null,"topics":[],"latest_commit_sha":null,"homepage":"","language":"C","has_issues":true,"has_wiki":null,"has_pages":null,"mirror_url":null,"source_name":null,"license":"apache-2.0","status":null,"scm":"git","pull_requests_enabled":true,"icon_url":"https://github.com/google.png","metadata":{"files":{"readme":"README.md","changelog":null,"contributing":"CONTRIBUTING.md","funding":null,"license":"LICENSE","code_of_conduct":null,"threat_model":null,"audit":null,"citation":null,"codeowners":null,"security":null,"support":null}},"created_at":"2019-10-03T01:40:18.000Z","updated_at":"2026-03-10T05:57:47.000Z","dependencies_parsed_at":"2022-08-30T17:11:52.603Z","dependency_job_id":null,"html_url":"https://github.com/google/nginx-sxg-module","commit_stats":null,"previous_names":[],"tags_count":27,"template":false,"template_full_name":null,"purl":"pkg:github/google/nginx-sxg-module","repository_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/google%2Fnginx-sxg-module","tags_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/google%2Fnginx-sxg-module/tags","releases_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/google%2Fnginx-sxg-module/releases","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/google%2Fnginx-sxg-module/manifests","owner_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners/google","download_url":"https://codeload.github.com/google/nginx-sxg-module/tar.gz/refs/heads/main","sbom_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/google%2Fnginx-sxg-module/sbom","scorecard":{"id":437536,"data":{"date":"2025-08-11","repo":{"name":"github.com/google/nginx-sxg-module","commit":"606cd1a85dbf543feff14cdbc33284a0442e5ae2"},"scorecard":{"version":"v5.2.1-40-gf6ed084d","commit":"f6ed084d17c9236477efd66e5b258b9d4cc7b389"},"score":5.6,"checks":[{"name":"Code-Review","score":10,"reason":"all changesets reviewed","details":null,"documentation":{"short":"Determines if the project requires human code review before pull requests (aka merge requests) are merged.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#code-review"}},{"name":"Maintained","score":0,"reason":"0 commit(s) and 0 issue activity found in the last 90 days -- score normalized to 0","details":null,"documentation":{"short":"Determines if the project is \"actively maintained\".","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#maintained"}},{"name":"Packaging","score":-1,"reason":"packaging workflow not detected","details":["Warn: no GitHub/GitLab publishing workflow detected."],"documentation":{"short":"Determines if the project is published as a package that others can easily download, install, easily update, and uninstall.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#packaging"}},{"name":"Dangerous-Workflow","score":10,"reason":"no dangerous workflow patterns detected","details":null,"documentation":{"short":"Determines if the project's GitHub Action workflows avoid dangerous patterns.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#dangerous-workflow"}},{"name":"Binary-Artifacts","score":10,"reason":"no binaries found in the repo","details":null,"documentation":{"short":"Determines if the project has generated executable (binary) artifacts in the source repository.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#binary-artifacts"}},{"name":"CII-Best-Practices","score":0,"reason":"no effort to earn an OpenSSF best practices badge detected","details":null,"documentation":{"short":"Determines if the project has an OpenSSF (formerly CII) Best Practices Badge.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#cii-best-practices"}},{"name":"Pinned-Dependencies","score":0,"reason":"dependency not pinned by hash detected -- score normalized to 0","details":["Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/clang-format-validation.yml:8: update your workflow using https://app.stepsecurity.io/secureworkflow/google/nginx-sxg-module/clang-format-validation.yml/main?enable=pin","Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/end-to-end-test.yml:19: update your workflow using https://app.stepsecurity.io/secureworkflow/google/nginx-sxg-module/end-to-end-test.yml/main?enable=pin","Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/end-to-end-test.yml:57: update your workflow using https://app.stepsecurity.io/secureworkflow/google/nginx-sxg-module/end-to-end-test.yml/main?enable=pin","Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/make-debs.yml:19: update your workflow using https://app.stepsecurity.io/secureworkflow/google/nginx-sxg-module/make-debs.yml/main?enable=pin","Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/make-debs.yml:28: update your workflow using https://app.stepsecurity.io/secureworkflow/google/nginx-sxg-module/make-debs.yml/main?enable=pin","Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/release-action.yml:19: update your workflow using https://app.stepsecurity.io/secureworkflow/google/nginx-sxg-module/release-action.yml/main?enable=pin","Warn: third-party GitHubAction not pinned by hash: .github/workflows/release-action.yml:29: update your workflow using https://app.stepsecurity.io/secureworkflow/google/nginx-sxg-module/release-action.yml/main?enable=pin","Warn: containerImage not pinned by hash: packaging/deb.dockerfile:2","Warn: containerImage not pinned by hash: test/Dockerfile:2","Info:   0 out of   6 GitHub-owned GitHubAction dependencies pinned","Info:   0 out of   1 third-party GitHubAction dependencies pinned","Info:   0 out of   2 containerImage dependencies pinned"],"documentation":{"short":"Determines if the project has declared and pinned the dependencies of its build process.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#pinned-dependencies"}},{"name":"Token-Permissions","score":0,"reason":"detected GitHub workflow tokens with excessive permissions","details":["Warn: no topLevel permission defined: .github/workflows/clang-format-validation.yml:1","Warn: no topLevel permission defined: .github/workflows/end-to-end-test.yml:1","Warn: no topLevel permission defined: .github/workflows/make-debs.yml:1","Warn: no topLevel permission defined: .github/workflows/release-action.yml:1","Info: no jobLevel write permissions found"],"documentation":{"short":"Determines if the project's workflows follow the principle of least privilege.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#token-permissions"}},{"name":"Fuzzing","score":10,"reason":"project is fuzzed","details":["Info: CppLibFuzzer integration found: accept_parser_fuzzer.cc:24","Info: CppLibFuzzer integration found: get_term_length_fuzzer.cc:24","Info: CppLibFuzzer integration found: param_is_preload_fuzzer.cc:24","Info: CppLibFuzzer integration found: accept_parser_fuzzer.cc:24","Info: CppLibFuzzer integration found: get_term_length_fuzzer.cc:24","Info: CppLibFuzzer integration found: param_is_preload_fuzzer.cc:24"],"documentation":{"short":"Determines if the project uses fuzzing.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#fuzzing"}},{"name":"Vulnerabilities","score":10,"reason":"0 existing vulnerabilities detected","details":null,"documentation":{"short":"Determines if the project has open, known unfixed vulnerabilities.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#vulnerabilities"}},{"name":"License","score":10,"reason":"license file detected","details":["Info: project has a license file: LICENSE:0","Info: FSF or OSI recognized license: Apache License 2.0: LICENSE:0"],"documentation":{"short":"Determines if the project has defined a license.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#license"}},{"name":"Signed-Releases","score":0,"reason":"Project has not signed or included provenance with any releases.","details":["Warn: release artifact v4.5 not signed: https://api.github.com/repos/google/nginx-sxg-module/releases/39638326","Warn: release artifact v4.4 not signed: https://api.github.com/repos/google/nginx-sxg-module/releases/38143300","Warn: release artifact v4.3 not signed: https://api.github.com/repos/google/nginx-sxg-module/releases/36264026","Warn: release artifact v4.2 not signed: https://api.github.com/repos/google/nginx-sxg-module/releases/33541775","Warn: release artifact v4.1 not signed: https://api.github.com/repos/google/nginx-sxg-module/releases/33094471","Warn: release artifact v4.5 does not have provenance: https://api.github.com/repos/google/nginx-sxg-module/releases/39638326","Warn: release artifact v4.4 does not have provenance: https://api.github.com/repos/google/nginx-sxg-module/releases/38143300","Warn: release artifact v4.3 does not have provenance: https://api.github.com/repos/google/nginx-sxg-module/releases/36264026","Warn: release artifact v4.2 does not have provenance: https://api.github.com/repos/google/nginx-sxg-module/releases/33541775","Warn: release artifact v4.1 does not have provenance: https://api.github.com/repos/google/nginx-sxg-module/releases/33094471"],"documentation":{"short":"Determines if the project cryptographically signs release artifacts.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#signed-releases"}},{"name":"Branch-Protection","score":-1,"reason":"internal error: error during branchesHandler.setup: internal error: githubv4.Query: Resource not accessible by integration","details":null,"documentation":{"short":"Determines if the default and release branches are protected with GitHub's branch protection settings.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#branch-protection"}},{"name":"Security-Policy","score":10,"reason":"security policy file detected","details":["Info: security policy file detected: github.com/google/.github/SECURITY.md:1","Info: Found linked content: github.com/google/.github/SECURITY.md:1","Info: Found disclosure, vulnerability, and/or timelines in security policy: github.com/google/.github/SECURITY.md:1","Info: Found text in security policy: github.com/google/.github/SECURITY.md:1"],"documentation":{"short":"Determines if the project has published a security policy.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#security-policy"}},{"name":"SAST","score":0,"reason":"SAST tool is not run on all commits -- score normalized to 0","details":["Warn: 0 commits out of 30 are checked with a SAST tool"],"documentation":{"short":"Determines if the project uses static code analysis.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#sast"}}]},"last_synced_at":"2025-08-19T05:01:47.354Z","repository_id":45698289,"created_at":"2025-08-19T05:01:47.354Z","updated_at":"2025-08-19T05:01:47.354Z"},"host":{"name":"GitHub","url":"https://github.com","kind":"github","repositories_count":286080680,"owners_count":34761847,"icon_url":"https://github.com/github.png","version":null,"created_at":"2022-05-30T11:31:42.601Z","updated_at":"2026-05-26T15:22:16.424Z","status":"online","status_checked_at":"2026-06-25T02:00:05.521Z","response_time":101,"last_error":null,"robots_txt_status":"success","robots_txt_updated_at":"2025-07-24T06:49:26.215Z","robots_txt_url":"https://github.com/robots.txt","online":true,"can_crawl_api":true,"host_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub","repositories_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories","repository_names_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repository_names","owners_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners"}},"keywords":[],"created_at":"2026-06-25T06:01:23.871Z","updated_at":"2026-06-25T06:01:28.495Z","avatar_url":"https://github.com/google.png","language":"C","funding_links":[],"categories":["Performance and optimization"],"sub_categories":[],"readme":"# NGINX SXG module\n\n[![Build Status](https://travis-ci.org/google/nginx-sxg-module.svg?branch=master)](https://travis-ci.org/google/nginx-sxg-module)\n\nSigned HTTP Exchange (SXG) support for nginx. Nginx will convert responses from\nthe upstream application into SXG when client requests include the `Accept:\napplication/signed-exchange;v=b3` HTTP header with highest qvalue.\n\n## Installation\n\nThere are two options for installation: Debian package or build from source. See\n[this article](https://web.dev/how-to-set-up-signed-http-exchanges/) for more\ndetails.\n\nIf building from source and you have libsxg installed in a non-system\ndirectory, edit `config` to add `ngx_module_incs=path/to/include` and add\n`-Lpath/to/lib` to the existing `ngx_module_libs`, and launch nginx with\n`LD_LIBRARY_PATH=path/to/lib`.\n\n## Configuration\n\nNginx-SXG module requires configuration on nginx.\n\n### Directives\n\n#### sxg\n\nActivation flag of SXG module. This can be set or overriden inside `server`\nand `location` directives.\n\n- `on`: Enable this plugin.\n- `off`: Disable this plugin.\n\nDefault value is `off`.\n\n#### sxg\\_certificate\n\nFull path for the certificate file. The certificate requires all of the\nconditions below to match. This and all below directives can only be set\ninside `server` directives.\n\n- Has `CanSignHttpExchanges` extension.\n- Uses ECDSA256 or ECDSA384.\n\nThis directive is always required.\n\n#### sxg\\_certificate\\_key\n\nFull path for the private key for the certificate.\n\nThis directive is always required.\n\n#### sxg\\_cert\\_url\n\nURL for CBOR encoded certificate file. The protocol must be `https`.\n\nThis directive is always required.\n\n#### sxg\\_validity\\_url\n\nURL for the validity information file. It must be `https` and must be the same\norigin with the website.\n\nThis directive is always required.\n\n#### sxg\\_max\\_payload\n\nMaximum HTTP body size this module can generate SXG from. Default value is\n`67108864` (64 MiB).\n\n\n#### sxg\\_cert\\_path\n\nThis directive is optional. If specified, this should be an absolute path\ncorresponding to a file that will be served at the URL specified by\n`sxg_cert_url`. This plugin will then automatically generate and refresh the\nCBOR-encoded certificate file, given the PEM located at `sxg_certificate`. It\nrequires that the OCSP responder for the certificate is accessible from your\nnginx server to get OCSP responses.\n\nAlternatively, use\n[`gen-certurl`](https://github.com/WICG/webpackage/blob/main/go/signedexchange/README.md)\nto generate a new `cert-chain+cbor` daily, and serve it statically at the URL\nspecified by `sxg_cert_url`.\n\n#### sxg\\_expiry\\_seconds\n\nThe life-span of generated SXG file in seconds.\nIt must not be bigger than 604800 (1 week).\nThis directive is optional.\nThe default value is `86400` (1 day).\n\n#### sxg\\_fallback\\_host\n\nThe hostname of fallback url of generated SXG file.\nThis directive is optional.\nThe default value is Host field parameter of HTTP request header.\n\n### Config Example\n\n```\nload_module \"modules/ngx_http_sxg_filter_module.so\";\n\nhttp {\n    upstream app {\n        server 127.0.0.1:3000;\n    }\n    include       mime.types;\n    default_type  application/octet-stream;\n    subrequest_output_buffer_size   4096k;\n\n    server {\n        listen    80;\n        server_name  example.com;\n\n        sxg on;\n        sxg_certificate     /path/to/certificate-ecdsa.pem;\n        sxg_certificate_key /path/to/private-key-ecdsa.key;\n        sxg_cert_url        https://cdn.test.com/example.com.cert.cbor;\n        sxg_validity_url    https://example.com/validity/resource.msg;\n        sxg_expiry_seconds 604800;\n        sxg_fallback_host  example.com;\n\n        location / {\n            proxy_pass http://app;\n        }\n    }\n}\n```\n\n### Subresource support\n\nnginx-sxg-module automatically includes signatures of subresources in its responses, allowing end users to prefetch it from distributor.\nWhen finding `link: rel=\"preload\"` entry in HTTP response header from upstream, this plugin will collect the specified resource to the upstream and append `rel=\"allowed-alt-sxg\";header-integrity=\"sha256-....\"` to the original HTTP response automatically.\nThis functionality is essential to subresource preloading for faster cross-site navigation.\n\n  - Preload URLs must be [relative references](https://tools.ietf.org/html/rfc3986#section-4.2)\n    of the `path-absolute` form, such as: `Link: \u003c/app.js\u003e;rel=preload;as=script`.\n  - The [`server_name`](https://nginx.org/en/docs/http/ngx_http_core_module.html#server_name)\n    must match the externally-addressable host:port of the subresources.\n  - Their responses must be no larger than the configured\n    [`subrequest_output_buffer_size`](https://nginx.org/en/docs/http/ngx_http_core_module.html#subrequest_output_buffer_size).\n  - Their responses must come from an upstream server, such as via\n    [`proxy_pass`](https://nginx.org/en/docs/http/ngx_http_proxy_module.html#proxy_pass).\n    The upstream may optionally be named via\n    [`upstream`](https://nginx.org/en/docs/http/ngx_http_upstream_module.html#upstream).\n  - If [using variables in\n    `proxy_pass`](http://nginx.org/en/docs/http/ngx_http_proxy_module.html#non_idempotent:~:text=When%20variables%20are%20used%20in%20proxy_pass),\n    use\n    [`$uri`](http://nginx.org/en/docs/http/ngx_http_core_module.html#var_uri:~:text=1.2.7%29-,%24uri,current%20URI%20in%20request)\n    instead of\n    [`$request_uri`](http://nginx.org/en/docs/http/ngx_http_core_module.html#var_request_uri:~:text=%24request_uri,full%20original%20request%20URI).\n\nTo ensure subresource prefetching works, verify that the `header-integrity` in:\n\n```bash\ncurl -H 'Accept: application/signed-exchange;v=b3' https://url/of/page.html | dump-signedexchange -payload=false | grep Link:\n```\n\nequals the value of:\n\n```bash\ncurl -H 'Accept: application/signed-exchange;v=b3' https://url/of/subresource.jpg | dump-signedexchange -headerIntegrity\n```\n","project_url":"https://awesome.ecosyste.ms/api/v1/projects/github.com%2Fgoogle%2Fnginx-sxg-module","html_url":"https://awesome.ecosyste.ms/projects/github.com%2Fgoogle%2Fnginx-sxg-module","lists_url":"https://awesome.ecosyste.ms/api/v1/projects/github.com%2Fgoogle%2Fnginx-sxg-module/lists"}