Avoid disabling core Helmet protections
Helmet should keep nosniff, HSTS, DNS prefetch control, Expect-CT, and referrer policy enabled unless another gateway enforces them.
#Metadata
#Why it matters
Turning off individual Helmet middlewares removes baseline HTTP hardening that is a high-signal misconfiguration risk.
#Remediation
Remove false overrides for nosniff, HSTS, DNS prefetch control, Expect-CT, and referrer policy unless a documented compensating control applies.
#Repository path
The generated metadata points to critiq-rules/libs/rules/catalog/rules/typescript/ts.security.insecure-helmet-hardening-options.rule.yaml.