All security headers were supposed to be added by gin-contrib/secure middleware (https://github.com/gin-contrib/secure). However, your comment made me verify that it actually works as it was doing at the time of starting to use that. I noticed that headers were not present - it seems that somehow the order of registering middlewares had made it not work. I've released a new version where they all work https://github.com/jarmo/secrets-web/releases/tag/v1.0.1
Thanks for making me look into it and finding out about this problem.