bcgov / bcgov/EDUC-STUDENT-PROFILE
ZAP Full Scan Report
Open
Nobody has claimed this yet.
- Dominant language
- JavaScript
- Stars
- 4
- Forks
- 1
- PR merge metrics
- No merged PRs in 30d
Description
- Site: https://dev.getmypen.gov.bc.ca
New Alerts- CSP: Failure to Define Directive with No Fallback [10055] total: 4:
- CSP: style-src unsafe-inline [10055] total: 4:
- Proxy Disclosure [40025] total: 5:
- Sub Resource Integrity Attribute Missing [90003] total: 5:
- Cookie with SameSite Attribute None [10054] total: 2:
- Cross-Origin-Embedder-Policy Header Missing or Invalid [90004] total: 3:
- Cross-Origin-Opener-Policy Header Missing or Invalid [90004] total: 3:
- Cross-Origin-Resource-Policy Header Missing or Invalid [90004] total: 4:
- Deprecated Feature Policy Header Set [10063] total: 5:
- Cookie Slack Detector [90027] total: 5:
- Modern Web Application [10109] total: 4:
- Non-Storable Content [10049] total: 5:
- Session Management Response Identified [10112] total: 2:
View the following link to download the report.
RunnerID:32880251329
Contributor guide
No contributing guide indexed for this repository
First steps
- Read the whole issue, then the project's contributing guide.
- Comment on the issue to say you are picking it up — it saves two people doing the same work.
- Fork the repository and make your change on a branch.
- Open a pull request that references the issue number.
Research direction
Download the ZAP report from the linked GitHub Actions run and review the listed alerts against the deployed frontend URLs. No source files or tests are named, so first locate where the frontend responses and security headers are configured. Done means the reported findings are addressed or explicitly assessed and the scan results are verified.
Written by the indexing model from the issue text.
Assessment
- Tech stack
- javascript
- Domain
- frontend, security
- Issue type
- Bug
- Difficulty
- 4/5
- Estimated time
- 3-5 days
- Activity status
- Active
- Clarity
- Needs clarification
- Newbie friendliness
- 35/100