bcgov / bcgov/quickstart-openshift-demo

ZAP: Frontend

Open
#16 0 comments 0 reactions 0 assignees View on GitHub
Dominant language
TypeScript
Stars
0
Forks
0
PR merge metrics
No merged PRs in 30d

Description

- Site: [https://quickstart-openshift-demo-test-frontend.apps.silver.devops.gov.bc.ca](https://quickstart-openshift-demo-test-frontend.apps.silver.devops.gov.bc.ca)
**New Alerts**
- **Sec-Fetch-Dest Header is Missing** [90005] total: 1:
- [https://quickstart-openshift-demo-test-frontend.apps.silver.devops.gov.bc.ca/](https://quickstart-openshift-demo-test-frontend.apps.silver.devops.gov.bc.ca/)
- **Sec-Fetch-Mode Header is Missing** [90005] total: 1:
- [https://quickstart-openshift-demo-test-frontend.apps.silver.devops.gov.bc.ca/](https://quickstart-openshift-demo-test-frontend.apps.silver.devops.gov.bc.ca/)
- **Sec-Fetch-Site Header is Missing** [90005] total: 1:
- [https://quickstart-openshift-demo-test-frontend.apps.silver.devops.gov.bc.ca/](https://quickstart-openshift-demo-test-frontend.apps.silver.devops.gov.bc.ca/)
- **Sec-Fetch-User Header is Missing** [90005] total: 1:
- [https://quickstart-openshift-demo-test-frontend.apps.silver.devops.gov.bc.ca/](https://quickstart-openshift-demo-test-frontend.apps.silver.devops.gov.bc.ca/)

View the [following link](https://github.com/bcgov/quickstart-openshift-demo/actions/runs/27870116680) to download the report.
RunnerID:27870116680

---
[ZAP by Checkmarx](https://checkmarx.com/)

Contributor guide

Open the contributing guide

Research direction

Start with the ZAP report linked in the issue and inspect the deployed frontend at the listed site to reproduce the four missing Sec-Fetch-* header alerts. Trace how requests or response headers are configured in the frontend and verify the result by rerunning the ZAP scan; done means the four reported alerts no longer appear.

Written by the indexing model from the issue text.

Assessment

Tech stack
typescript
Domain
frontend, security
Issue type
Bug
Difficulty
3/5
Estimated time
1-2 days
Activity status
Quiet
Clarity
Needs clarification
Newbie friendliness
45/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.