ZAP API Scan Report
- Dominant language
- Java
- Stars
- 0
- Forks
- 0
- PR merge metrics
- No merged PRs in 30d
Description
- Site: [https://coreg-api--dev.apps.silver.devops.gov.bc.ca](https://coreg-api--dev.apps.silver.devops.gov.bc.ca)
**New Alerts**
- **Content Security Policy (CSP) Header Not Set** [10038] total: 1:
- [https://coreg-api--dev.apps.silver.devops.gov.bc.ca/v3/api-docs](https://coreg-api--dev.apps.silver.devops.gov.bc.ca/v3/api-docs)
- **Permissions Policy Header Not Set** [10063] total: 1:
- [https://coreg-api--dev.apps.silver.devops.gov.bc.ca/v3/api-docs](https://coreg-api--dev.apps.silver.devops.gov.bc.ca/v3/api-docs)
- **Strict-Transport-Security Header Not Set** [10035] total: 1:
- [https://coreg-api--dev.apps.silver.devops.gov.bc.ca/v3/api-docs](https://coreg-api--dev.apps.silver.devops.gov.bc.ca/v3/api-docs)
- **Unexpected Content-Type was returned** [100001] total: 13:
- [https://coreg-api--dev.apps.silver.devops.gov.bc.ca](https://coreg-api--dev.apps.silver.devops.gov.bc.ca)
- [https://coreg-api--dev.apps.silver.devops.gov.bc.ca/](https://coreg-api--dev.apps.silver.devops.gov.bc.ca/)
- [https://coreg-api--dev.apps.silver.devops.gov.bc.ca/5194362967183356894](https://coreg-api--dev.apps.silver.devops.gov.bc.ca/5194362967183356894)
- [https://coreg-api--dev.apps.silver.devops.gov.bc.ca/actuator/health](https://coreg-api--dev.apps.silver.devops.gov.bc.ca/actuator/health)
- [https://coreg-api--dev.apps.silver.devops.gov.bc.ca/computeMetadata/v1/](https://coreg-api--dev.apps.silver.devops.gov.bc.ca/computeMetadata/v1/)
- ..
- **Non-Storable Content** [10049] total: 1:
- [https://coreg-api--dev.apps.silver.devops.gov.bc.ca/v3/api-docs](https://coreg-api--dev.apps.silver.devops.gov.bc.ca/v3/api-docs)
View the [following link](https://github.com/bcgov/EDUC-COREG-API/actions/runs/13317413279) to download the report.
RunnerID:13317413279
---
ZAP is supported by the [Crash Override Open Source Fellowship](https://crashoverride.com/?zap=act)
Contributor guide
No contributing guide indexed for this repository
Research direction
Start with the linked ZAP report from GitHub Actions and inspect the API entry points serving the listed endpoints. Determine which reported headers and unexpected content types are actionable, then rerun the scan to confirm the selected alerts are resolved.
Written by the indexing model from the issue text.
Assessment
- Tech stack
- github-actions, java
- Domain
- api, security
- Issue type
- Bug
- Difficulty
- 4/5
- Estimated time
- 3-5 days
- Activity status
- Stale
- Clarity
- Needs clarification
- Newbie friendliness
- 25/100