Skip to content

Option to hide "Server: Puma PUMA_VERSION" header #3037

@daisy1754

Description

@daisy1754

Is your feature request related to a problem? Please describe.
Currently we use Puma 5.6.4. Our security auditor asks if we can remove Server: Puma 5.6.4 in HTTP response header because it can potentially give bad actor hints about exploiting our server, if vulnerability is found in certain puma version.

Describe the solution you'd like
Add configuration to allow suppressing "server" response header

Describe alternatives you've considered
Remove this header on our load balancer level could be another option but I prefer if we can omit on puma-level

Additional context
Add any other context or screenshots about the feature request here.

Metadata

Metadata

Assignees

No one assigned

    Labels

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions