bcgov / bcgov/quickstart-openshift-demo
ZAP: Backend
- Dominant language
- TypeScript
- Stars
- 0
- Forks
- 0
- PR merge metrics
- No merged PRs in 30d
Description
- Site: [https://quickstart-openshift-demo-test-frontend.apps.silver.devops.gov.bc.ca](https://quickstart-openshift-demo-test-frontend.apps.silver.devops.gov.bc.ca)
**New Alerts**
- **Sec-Fetch-Dest Header is Missing** [90005] total: 1:
- [https://quickstart-openshift-demo-test-frontend.apps.silver.devops.gov.bc.ca/api](https://quickstart-openshift-demo-test-frontend.apps.silver.devops.gov.bc.ca/api)
- **Sec-Fetch-Mode Header is Missing** [90005] total: 1:
- [https://quickstart-openshift-demo-test-frontend.apps.silver.devops.gov.bc.ca/api](https://quickstart-openshift-demo-test-frontend.apps.silver.devops.gov.bc.ca/api)
- **Sec-Fetch-Site Header is Missing** [90005] total: 1:
- [https://quickstart-openshift-demo-test-frontend.apps.silver.devops.gov.bc.ca/api](https://quickstart-openshift-demo-test-frontend.apps.silver.devops.gov.bc.ca/api)
- **Sec-Fetch-User Header is Missing** [90005] total: 1:
- [https://quickstart-openshift-demo-test-frontend.apps.silver.devops.gov.bc.ca/api](https://quickstart-openshift-demo-test-frontend.apps.silver.devops.gov.bc.ca/api)
View the [following link](https://github.com/bcgov/quickstart-openshift-demo/actions/runs/27870116680) to download the report.
RunnerID:27870116680
---
[ZAP by Checkmarx](https://checkmarx.com/)
Contributor guide
Research direction
Start by reviewing the ZAP report from workflow run 27870116680 and reproduce the alerts against the /api endpoint. Identify where the backend response headers are configured; done means the four Sec-Fetch header alerts no longer appear in the ZAP report for that endpoint.
Written by the indexing model from the issue text.
Assessment
- Tech stack
- typescript
- Domain
- api, backend, security
- Issue type
- Bug
- Difficulty
- 4/5
- Estimated time
- 3-5 days
- Activity status
- Quiet
- Clarity
- Needs clarification
- Newbie friendliness
- 42/100