A third party vulnerability scan of our domain found an issue with our public status page due a missing CSP HTTP header. Are there any plans by Atlassian to add this header?
(I know I can add the header via a META tag, but that would require upgrading my plan. Seems like I should not have to pay extra for basic XSS protection in 2021.)