bcgov / bcgov/entity

Address Was scan vulnerability issues

Open
#9,277 0 comments 0 reactions 0 assignees View on GitHub
techdebt
Dominant language
JavaScript
Stars
23
Forks
62
Avg merge
24m
Merged PRs (30d)
1

Description

## What is the problem?

Few items which can be improved are reported in the wav scan

Missing or Insecure "Object-Src" policy in "Content-Security-Policy” header
Missing or Insecure "Script-Src" policy in "Content-Security-Policy” header
Cookie with Insecure or Improper or Missing SameSite attribute
Unnecessary Http Response Headers found in the Application
Cacheable SSL Page Found

## What is the impact?

Improving this will help WAV scan results.

## Proposed solution

Contributor guide

No contributing guide indexed for this repository

Research direction

The issue lists WAV scan findings for Content-Security-Policy directives, cookie SameSite attributes, unnecessary response headers, and cacheable SSL pages, but names no files or tests. Start by identifying which application responses produce these findings, then rerun the WAV scan to verify that the reported items are resolved.

Written by the indexing model from the issue text.

Assessment

Domain
security
Issue type
Bug
Difficulty
4/5
Estimated time
3-5 days
Activity status
Stale
Clarity
Needs clarification
Newbie friendliness
25/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.