HTTP/2 200 server: Apache x-frame-options: SAMEORIGIN last-modified: Thu, 18 Dec 2025 12:10:01 GMT etag: "45e2-64638d71bcbae" access-control-allow-origin: * content-security-policy: default-src 'self' data: blob: 'unsafe-inline' 'unsafe-eval' https://www.apachecon.com/ https://www.communityovercode.org/ https://*.apache.org/ https://apache.org/ https://*.scarf.sh/ ; script-src 'self' data: blob: 'unsafe-inline' 'unsafe-eval' https://www.apachecon.com/ https://www.communityovercode.org/ https://*.apache.org/ https://apache.org/ https://*.scarf.sh/ ; style-src 'self' data: blob: 'unsafe-inline' 'unsafe-eval' https://www.apachecon.com/ https://www.communityovercode.org/ https://*.apache.org/ https://apache.org/ https://*.scarf.sh/ ; frame-ancestors 'self'; frame-src 'self' data: blob: 'unsafe-inline' 'unsafe-eval' https://www.apachecon.com/ https://www.communityovercode.org/ https://*.apache.org/ https://apache.org/ https://*.scarf.sh/ ; worker-src 'self' data: blob:; x-content-type-options: nosniff x-xss-protection: 1; mode=block referrer-policy: strict-origin content-type: text/html via: 1.1 varnish, 1.1 varnish accept-ranges: bytes age: 0 date: Sun, 19 Jul 2026 08:35:18 GMT x-served-by: cache-hel1410028-HEL, cache-nyc-kteb1890088-NYC x-cache: HIT, MISS x-cache-hits: 264, 0 x-timer: S1784450119.727285,VS0,VE101 vary: Accept-Encoding strict-transport-security: max-age=31536000; includeSubDomains; preload content-length: 17890