# Source register

Accessed 4 October 2026 unless stated otherwise. Dates and deployment observations are snapshots. URLs in slides are clickable references in notes; the live presentation uses no network resources.

## Chromium / XSLT

| Title | Publisher | URL | Supports |
| --- | --- | --- | --- |
| Removing XSLT for a more secure browser | Chrome Developers, Google | https://developer.chrome.com/docs/web-platform/deprecating-xslt | Native XSLTProcessor and XSLT processing-instruction execution removal; XML and XML/CSS retained; current Chrome 158 / 17 Nov 2026 plan; temporary extensions ending Chrome 176 / 17 Aug 2027. Published 29 Oct 2025; schedule rechecked. |
| Deprecate and remove XSLT | Chrome Platform Status | https://chromestatus.com/feature/4709671889534976 | Authoritative feature-tracking link from Chrome's notice. This is a JavaScript-driven page; readable timeline came from the notice above. |
| Associating Style Sheets with XML documents 1.0 (Second Edition) | W3C | https://www.w3.org/TR/xml-stylesheet/ | Processing-instruction syntax and association mechanism. |
| XSL Transformations (XSLT) Version 1.0 | W3C | https://www.w3.org/TR/xslt-10/ | Transformation model and processor/version compatibility context. |

## HTTP

| Title | Publisher | URL | Supports |
| --- | --- | --- | --- |
| RFC 9110: HTTP Semantics, sections 3 and 12 | IETF / RFC Editor | https://www.rfc-editor.org/rfc/rfc9110.html | Resource/representation distinction and negotiation architecture. |
| Accept, section 12.5.1 | IETF / RFC Editor | https://www.rfc-editor.org/rfc/rfc9110.html#section-12.5.1 | Media ranges, quality, specificity, absent/wildcard preferences. |
| Content-Type, section 8.3 | IETF / RFC Editor | https://www.rfc-editor.org/rfc/rfc9110.html#section-8.3 | Response representation's media type. |
| Vary, section 12.5.5 | IETF / RFC Editor | https://www.rfc-editor.org/rfc/rfc9110.html#section-12.5.5 | Selection dimensions exposed to caches. |
| 406 Not Acceptable, section 15.5.7 | IETF / RFC Editor | https://www.rfc-editor.org/rfc/rfc9110.html#section-15.5.7 | Strict rejection policy; HTTP permits disregard as an alternative. |
| RFC 9111: HTTP Caching, section 4.1 | IETF / RFC Editor | https://www.rfc-editor.org/rfc/rfc9111.html#section-4.1 | Stored response selection with Vary. |

## CAP

| Title | Publisher | URL | Supports |
| --- | --- | --- | --- |
| Common Alerting Protocol Version 1.2, OASIS Standard, 1 July 2010 | OASIS | https://docs.oasis-open.org/emergency/cap/v1.2/CAP-v1.2-os.html | CAP structure, namespace, alert semantics and Test status. |
| CAP 1.2 XML Schema | OASIS | https://docs.oasis-open.org/emergency/cap/v1.2/CAP-v1.2.xsd | Validation of the fictional sample supplied with examples. |

## .NET

| Title | Publisher | URL | Supports |
| --- | --- | --- | --- |
| Format response data in ASP.NET Core Web API (.NET 10 view) | Microsoft Learn | https://learn.microsoft.com/en-us/aspnet/core/web-api/advanced/formatting?view=aspnetcore-10.0 | Controller negotiation, browser Accept handling and ReturnHttpNotAcceptable. |
| Custom formatters in ASP.NET Core Web API | Microsoft Learn | https://learn.microsoft.com/en-us/aspnet/core/web-api/advanced/custom-formatters?view=aspnetcore-10.0 | TextOutputFormatter, supported types/encodings, CanWriteType, WriteResponseBodyAsync. |
| MediaTypeHeaderValue.IsSubsetOf | Microsoft Learn | https://learn.microsoft.com/en-us/dotnet/api/microsoft.net.http.headers.mediatypeheadervalue.issubsetof?view=aspnetcore-10.0 | Typed matching used in the example's explicit quality/exclusion policy. |
| XslCompiledTransform | Microsoft Learn | https://learn.microsoft.com/en-us/dotnet/api/system.xml.xsl.xslcompiledtransform?view=net-10.0 | Server XSLT option, settings/resolvers and runtime constraints. Not executed by the example. |

## Java

| Title | Publisher | URL | Supports |
| --- | --- | --- | --- |
| Mapping Requests | Spring project | https://docs.spring.io/spring-framework/reference/web/webmvc/mvc-controller/ann-requestmapping.html | GetMapping/produces and response mapping. |
| Content Types | Spring project | https://docs.spring.io/spring-framework/reference/web/webmvc/mvc-config/content-negotiation.html | Accept-based negotiation and WebMvcConfigurer. |
| Message Converters | Spring project | https://docs.spring.io/spring-framework/reference/web/webmvc/mvc-config/message-converters.html | MVC message converter configuration. |
| ContentNegotiationStrategy API | Spring project | https://docs.spring.io/spring-framework/docs/current/javadoc-api/org/springframework/web/accept/ContentNegotiationStrategy.html | Custom policy extension retaining Spring's header parser. |
| MediaType API | Spring project | https://docs.spring.io/spring-framework/docs/current/javadoc-api/org/springframework/http/MediaType.html | Media ranges, includes and quality values. |
| System Requirements, Spring Boot 4.1.1 | Spring project | https://docs.spring.io/spring-boot/system-requirements.html | Java 17 minimum and supported build tools. Artifact 4.1.1 availability also verified in Maven Central. |
| JAXP Security Guide, Java 25 | Oracle | https://docs.oracle.com/en/java/javase/25/security/java-api-xml-processing-jaxp-security-guide.html | XML/XSLT external-resource restrictions and processing limits. |

## PHP

| Title | Publisher | URL | Supports |
| --- | --- | --- | --- |
| HttpFoundation Component | Symfony project | https://symfony.com/doc/current/components/http_foundation.html | Request, Response, AcceptHeader and quality/wildcard APIs. |
| AcceptHeader source, v8.1.8 | Symfony project | https://github.com/symfony/http-foundation/blob/v8.1.8/AcceptHeader.php | get() specificity/quality matching; pinned example API. |
| Package metadata, HttpFoundation | Packagist / Symfony | https://repo.packagist.org/p2/symfony/http-foundation.json | 8.1.8 availability and PHP >=8.4.1 requirement. |
| XSLTProcessor::setSecurityPrefs | PHP project | https://www.php.net/manual/en/xsltprocessor.setsecurityprefs.php | Server stylesheet file/network restriction options. Not executed by the example. |

## Security

| Title | Publisher | URL | Supports |
| --- | --- | --- | --- |
| SSRF Prevention Cheat Sheet | OWASP | https://cheatsheetseries.owasp.org/cheatsheets/Server_Side_Request_Forgery_Prevention_Cheat_Sheet.html | Destination validation, allowlisting and network-layer defences. |

## Alert-Hub example resources

| Title | Publisher | URL | Evidence/limitation |
| --- | --- | --- | --- |
| CAP aggregator console | Alert-Hub | https://console.alerting-apps.net/cap-aggregator/ | HTTP 403 access challenge to command-line checks. No claim to have inspected page contents. |
| Mexico SMN source page | Alert-Hub | https://console.alerting-apps.net/cap-aggregator/sources/mx-smn-es | Same challenge. Source identity also present in public feed response and supplied brief. |
| Mexico SMN upstream feed | CONAGUA / SMN | https://smn.conagua.gob.mx/tools/PHP/feedsmn/cap.php | HTTP 200 application/xml; Atom document observed. |
| Public reflector feed | Alert-Hub | https://ah-node-v2.api.alerting-apps.net/public/reflector/mx-smn-es | Direct negotiation, suffix and Vary checks. Feed is RSS/XML, not a CAP alert. |
| Individual reflected alert used during inspection | Alert-Hub | https://ah-node-v2.api.alerting-apps.net/public/reflector/mx-smn-es/9d151f44-db97-5fa0-baf0-dc61e66bc2f0 | CAP/HTML negotiation and fixed suffixes observed. Historical sample may expire. |

See [LIVE-CHECKS.md](LIVE-CHECKS.md) and [live-results.json](live-results.json) for the deployment snapshot.

Local code evidence: `alert-hub-v2-node`, HEAD `8efbda6650531cd57a27edca2342e12e0221c37c`, inspected 4 Oct 2026. Unrelated working changes existed in monthly-report files; the following inspected files were unchanged:

- `alerthub-node/src/main/java/org/alerthub/controllers/PublicAlertReflectorController.java`: unsuffixed negotiation, fixed suffix routes, RSS feed media type.
- `alerthub-node/src/main/java/org/alerthub/services/publicfeed/PublicReflectorHtmlRenderer.java`: approved stylesheet registry use, cache keyed by hash, server transformations, bundled/template selection.

Code inspection demonstrates supported paths, not proof that a specific deployed response used publisher XSLT or that every transformation failure automatically falls back. No Alert-Hub implementation changes form part of this package.

## Presentation branding and contact links

Accessed 4 October 2026.

| Title | Publisher | URL | Supports |
| --- | --- | --- | --- |
| Alert-Hub.org CTO Journal | Alert-Hub | https://blog.alert-hub.org/ | Speaker branding: red Alert-Hub icon, ink/blue/cyan/magenta/green/yellow site palette. The deck uses high-contrast tints on a dark background. |
| Alert-Hub blog icon | Alert-Hub | https://blog.alert-hub.org/assets/alert-hub-icon-96.png | Original 96px icon, identical to the blog repository asset. Embedded unchanged in the presentation. |
| CAP community | Telegram group administrators | https://t.me/CAP_community | Public page identifies the Common Alerting Protocol (CAP) Community discussion group. Speaker participation and email supplied by Ian. |
