bcgov / bcgov/EDUC-GRAD-ALGORITHM-API
ZAP API Scan Report
- Dominant language
- Java
- Stars
- 0
- Forks
- 0
- PR merge metrics
- No merged PRs in 30d
Description
- Site: [https://educ-grad-algorithm-api-e8a97a-dev-dev.apps.silver.devops.gov.bc.ca](https://educ-grad-algorithm-api-e8a97a-dev-dev.apps.silver.devops.gov.bc.ca)
**New Alerts**
- **Content Security Policy (CSP) Header Not Set** [10038] total: 1:
- [https://educ-grad-algorithm-api-e8a97a-dev-dev.apps.silver.devops.gov.bc.ca/api/v1/api-docs](https://educ-grad-algorithm-api-e8a97a-dev-dev.apps.silver.devops.gov.bc.ca/api/v1/api-docs)
- **A Server Error response code was returned by the server** [100000] total: 76:
- [https://educ-grad-algorithm-api-e8a97a-dev-dev.apps.silver.devops.gov.bc.ca](https://educ-grad-algorithm-api-e8a97a-dev-dev.apps.silver.devops.gov.bc.ca)
- [https://educ-grad-algorithm-api-e8a97a-dev-dev.apps.silver.devops.gov.bc.ca/](https://educ-grad-algorithm-api-e8a97a-dev-dev.apps.silver.devops.gov.bc.ca/)
- [https://educ-grad-algorithm-api-e8a97a-dev-dev.apps.silver.devops.gov.bc.ca/._darcs](https://educ-grad-algorithm-api-e8a97a-dev-dev.apps.silver.devops.gov.bc.ca/._darcs)
- [https://educ-grad-algorithm-api-e8a97a-dev-dev.apps.silver.devops.gov.bc.ca/.bzr](https://educ-grad-algorithm-api-e8a97a-dev-dev.apps.silver.devops.gov.bc.ca/.bzr)
- [https://educ-grad-algorithm-api-e8a97a-dev-dev.apps.silver.devops.gov.bc.ca/.DS_Store](https://educ-grad-algorithm-api-e8a97a-dev-dev.apps.silver.devops.gov.bc.ca/.DS_Store)
- ..
- **Permissions Policy Header Not Set** [10063] total: 1:
- [https://educ-grad-algorithm-api-e8a97a-dev-dev.apps.silver.devops.gov.bc.ca/api/v1/api-docs](https://educ-grad-algorithm-api-e8a97a-dev-dev.apps.silver.devops.gov.bc.ca/api/v1/api-docs)
- **Strict-Transport-Security Header Not Set** [10035] total: 1:
- [https://educ-grad-algorithm-api-e8a97a-dev-dev.apps.silver.devops.gov.bc.ca/api/v1/api-docs](https://educ-grad-algorithm-api-e8a97a-dev-dev.apps.silver.devops.gov.bc.ca/api/v1/api-docs)
- **Unexpected Content-Type was returned** [100001] total: 78:
- [https://educ-grad-algorithm-api-e8a97a-dev-dev.apps.silver.devops.gov.bc.ca](https://educ-grad-algorithm-api-e8a97a-dev-dev.apps.silver.devops.gov.bc.ca)
- [https://educ-grad-algorithm-api-e8a97a-dev-dev.apps.silver.devops.gov.bc.ca/](https://educ-grad-algorithm-api-e8a97a-dev-dev.apps.silver.devops.gov.bc.ca/)
- [https://educ-grad-algorithm-api-e8a97a-dev-dev.apps.silver.devops.gov.bc.ca/._darcs](https://educ-grad-algorithm-api-e8a97a-dev-dev.apps.silver.devops.gov.bc.ca/._darcs)
- [https://educ-grad-algorithm-api-e8a97a-dev-dev.apps.silver.devops.gov.bc.ca/.bzr](https://educ-grad-algorithm-api-e8a97a-dev-dev.apps.silver.devops.gov.bc.ca/.bzr)
- [https://educ-grad-algorithm-api-e8a97a-dev-dev.apps.silver.devops.gov.bc.ca/.DS_Store](https://educ-grad-algorithm-api-e8a97a-dev-dev.apps.silver.devops.gov.bc.ca/.DS_Store)
- ..
- **A Client Error response code was returned by the server** [100000] total: 2:
- [https://educ-grad-algorithm-api-e8a97a-dev-dev.apps.silver.devops.gov.bc.ca?aaa=bbb](https://educ-grad-algorithm-api-e8a97a-dev-dev.apps.silver.devops.gov.bc.ca?aaa=bbb)
- [https://educ-grad-algorithm-api-e8a97a-dev-dev.apps.silver.devops.gov.bc.ca?class.module.classLoader.DefaultAssertionStatus=nonsense](https://educ-grad-algorithm-api-e8a97a-dev-dev.apps.silver.devops.gov.bc.ca?class.module.classLoader.DefaultAssertionStatus=nonsense)
- **Non-Storable Content** [10049] total: 1:
- [https://educ-grad-algorithm-api-e8a97a-dev-dev.apps.silver.devops.gov.bc.ca/api/v1/api-docs](https://educ-grad-algorithm-api-e8a97a-dev-dev.apps.silver.devops.gov.bc.ca/api/v1/api-docs)
View the [following link](https://github.com/bcgov/EDUC-GRAD-ALGORITHM-API/actions/runs/8793679345) to download the report.
RunnerID:8793679345
---
ZAP is supported by the [Crash Override Open Source Fellowship](https://crashoverride.com/?zap=act)
Contributor guide
No contributing guide indexed for this repository
Research direction
Download the ZAP report from GitHub Actions run 8793679345 and review the listed findings for the API root and /api/v1/api-docs endpoints. Determine the intended remediation for the missing security headers, server and client errors, unexpected content types, and non-storable content, then rerun the scan to verify the findings are resolved.
Written by the indexing model from the issue text.
Assessment
- Domain
- api, security
- Issue type
- Bug
- Difficulty
- 4/5
- Estimated time
- 3-5 days
- Activity status
- Stale
- Clarity
- Needs clarification
- Newbie friendliness
- 20/100