diff --git a/package.json b/package.json index 54f64cef12..39b2af7a62 100644 --- a/package.json +++ b/package.json @@ -57,7 +57,7 @@ "express-state": "^1.2.0", "express-validator": "^2.18.0", "fetchr": "~0.5.12", - "frameguard": "~1.1.0", + "frameguard": "^2.0.0", "gulp": "^3.9.0", "gulp-babel": "^6.1.1", "gulp-concat": "^2.6.0", diff --git a/server/middlewares/csp.js b/server/middlewares/csp.js index b64036275b..599964bc45 100644 --- a/server/middlewares/csp.js +++ b/server/middlewares/csp.js @@ -9,7 +9,7 @@ if (process.env.NODE_ENV !== 'production') { } export default function csp() { - return helmet.csp({ + return helmet.contentSecurityPolicy({ directives: { defaultSrc: trusted, scriptSrc: [