google / google/csp-evaluator

script-src-elem 'self' 'unsafe-inline' 'unsafe-eval' reported as "all good"

Open
#24 1 comment 5 reactions 0 assignees View on GitHub
Dominant language
TypeScript
Stars
404
Forks
59
PR merge metrics
No merged PRs in 30d

Description

I would like to highlight the fact that the above policy is reported as safe. Is this intended? From what I understood 'unsafe-inline' could remove the defense. I would expect this reported as an High severity finding. Am I missing something? Thanks
![image](https://user-images.githubusercontent.com/45259951/103342995-3a107a00-4a8b-11eb-98e1-d830a10c80d8.png)

Contributor guide

Open the contributing guide

Assessment

This issue has not been assessed yet.

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.