script-src-elem 'self' 'unsafe-inline' 'unsafe-eval' reported as "all good"
Open
- Dominant language
- TypeScript
- Stars
- 404
- Forks
- 59
- PR merge metrics
- No merged PRs in 30d
Description
I would like to highlight the fact that the above policy is reported as safe. Is this intended? From what I understood 'unsafe-inline' could remove the defense. I would expect this reported as an High severity finding. Am I missing something? Thanks

Contributor guide
Assessment
This issue has not been assessed yet.