Skip to content

Commit 517c14c

Browse files
💄 beautify drheader jsonfiles (#13672)
* 💄 beautify drheader jsonfiles * add more json
1 parent c484229 commit 517c14c

9 files changed

Lines changed: 201 additions & 16 deletions

File tree

Lines changed: 72 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -1 +1,72 @@
1-
[{"rule": "Content-Security-Policy", "severity": "high", "message": "Must-Contain-One directive missed", "expected": ["default-src 'none'", "default-src 'self'"], "delimiter": ";", "value": "default-src 'self' service.maxymiser.net; child-src 'self' 'unsafe-inline' https://www.googleadservices.com https://*.fls.doubleclick.net/ https://*.santander.co.uk https://santander.demdex.net; script-src 'self' 'unsafe-inline' https://track.omguk.com https://cdn.usersnap.com https://screencapture.kampyle.com https://nebula-cdn.kampyle.com https://resources.digital-cloud-uk.medallia.eu https://pagead2.googlesyndication.com https://js-cdn.dynatrace.com https://activitymap.adobe.com https://cdn-ukwest.onetrust.com https://cdn.mouseflow.com https://googleads.g.doubleclick.net lptag.liveperson.net lo.v.liveperson.net lo.msg.liveperson.net accdn.lpsnmedia.net lpcdn.lpsnmedia.net https://www.googletagservices.com https://ad.doubleclick.net service.maxymiser.net https://connect.facebook.net https://*.fls.doubleclick.net/ https://www.googleadservices.com https://www.googletagmanager.com https://assets.adobedtm.com https://dpm.demdex.net/ https://*.santander.co.uk 'unsafe-eval'; connect-src 'self' 'unsafe-inline' https://udc-neb.kampyle.com https://*.bf.dynatrace.com https://privacyportal-uk.onetrust.com https://cdn-ukwest.onetrust.com https://o2.mouseflow.com https://googleads4.g.doubleclick.net wss://lo.msg.liveperson.net https://dpm.demdex.net https://*.santander.co.uk; img-src 'self' https://lpcdn.lpsnmedia.net service.maxymiser.net 'unsafe-inline' https://*.santander.co.uk data: https:; style-src 'self' service.maxymiser.net 'unsafe-inline'; font-src 'self'; frame-src 'self' 'unsafe-inline' https://www.youtube-nocookie.com https://resources.digital-cloud-uk.medallia.eu https://lo.tokenizer.liveperson.net https://lo.msghist.liveperson.net https://lo.msg.liveperson.net https://lpcdn.lpsnmedia.net lo.idp.liveperson.net server.lon.liveperson.net https://authorize.omniture.com https://sitecatalyst.omniture.com service.maxymiser.net https://edigitalsurvey.com https://www.youtube.com https://santander.demdex.net https://*.fls.doubleclick.net; object-src 'self'; media-src lpcdn.lpsnmedia.net; worker-src blob:;", "anomaly": ["default-src 'none'", "default-src 'self'"]}, {"rule": "Content-Security-Policy", "severity": "medium", "message": "Must-Avoid directive included", "avoid": ["unsafe-inline", "unsafe-eval"], "delimiter": ";", "value": "default-src 'self' service.maxymiser.net; child-src 'self' 'unsafe-inline' https://www.googleadservices.com https://*.fls.doubleclick.net/ https://*.santander.co.uk https://santander.demdex.net; script-src 'self' 'unsafe-inline' https://track.omguk.com https://cdn.usersnap.com https://screencapture.kampyle.com https://nebula-cdn.kampyle.com https://resources.digital-cloud-uk.medallia.eu https://pagead2.googlesyndication.com https://js-cdn.dynatrace.com https://activitymap.adobe.com https://cdn-ukwest.onetrust.com https://cdn.mouseflow.com https://googleads.g.doubleclick.net lptag.liveperson.net lo.v.liveperson.net lo.msg.liveperson.net accdn.lpsnmedia.net lpcdn.lpsnmedia.net https://www.googletagservices.com https://ad.doubleclick.net service.maxymiser.net https://connect.facebook.net https://*.fls.doubleclick.net/ https://www.googleadservices.com https://www.googletagmanager.com https://assets.adobedtm.com https://dpm.demdex.net/ https://*.santander.co.uk 'unsafe-eval'; connect-src 'self' 'unsafe-inline' https://udc-neb.kampyle.com https://*.bf.dynatrace.com https://privacyportal-uk.onetrust.com https://cdn-ukwest.onetrust.com https://o2.mouseflow.com https://googleads4.g.doubleclick.net wss://lo.msg.liveperson.net https://dpm.demdex.net https://*.santander.co.uk; img-src 'self' https://lpcdn.lpsnmedia.net service.maxymiser.net 'unsafe-inline' https://*.santander.co.uk data: https:; style-src 'self' service.maxymiser.net 'unsafe-inline'; font-src 'self'; frame-src 'self' 'unsafe-inline' https://www.youtube-nocookie.com https://resources.digital-cloud-uk.medallia.eu https://lo.tokenizer.liveperson.net https://lo.msghist.liveperson.net https://lo.msg.liveperson.net https://lpcdn.lpsnmedia.net lo.idp.liveperson.net server.lon.liveperson.net https://authorize.omniture.com https://sitecatalyst.omniture.com service.maxymiser.net https://edigitalsurvey.com https://www.youtube.com https://santander.demdex.net https://*.fls.doubleclick.net; object-src 'self'; media-src lpcdn.lpsnmedia.net; worker-src blob:;", "anomaly": "unsafe-inline"}, {"rule": "Content-Security-Policy", "severity": "medium", "message": "Must-Avoid directive included", "avoid": ["unsafe-inline", "unsafe-eval"], "delimiter": ";", "value": "default-src 'self' service.maxymiser.net; child-src 'self' 'unsafe-inline' https://www.googleadservices.com https://*.fls.doubleclick.net/ https://*.santander.co.uk https://santander.demdex.net; script-src 'self' 'unsafe-inline' https://track.omguk.com https://cdn.usersnap.com https://screencapture.kampyle.com https://nebula-cdn.kampyle.com https://resources.digital-cloud-uk.medallia.eu https://pagead2.googlesyndication.com https://js-cdn.dynatrace.com https://activitymap.adobe.com https://cdn-ukwest.onetrust.com https://cdn.mouseflow.com https://googleads.g.doubleclick.net lptag.liveperson.net lo.v.liveperson.net lo.msg.liveperson.net accdn.lpsnmedia.net lpcdn.lpsnmedia.net https://www.googletagservices.com https://ad.doubleclick.net service.maxymiser.net https://connect.facebook.net https://*.fls.doubleclick.net/ https://www.googleadservices.com https://www.googletagmanager.com https://assets.adobedtm.com https://dpm.demdex.net/ https://*.santander.co.uk 'unsafe-eval'; connect-src 'self' 'unsafe-inline' https://udc-neb.kampyle.com https://*.bf.dynatrace.com https://privacyportal-uk.onetrust.com https://cdn-ukwest.onetrust.com https://o2.mouseflow.com https://googleads4.g.doubleclick.net wss://lo.msg.liveperson.net https://dpm.demdex.net https://*.santander.co.uk; img-src 'self' https://lpcdn.lpsnmedia.net service.maxymiser.net 'unsafe-inline' https://*.santander.co.uk data: https:; style-src 'self' service.maxymiser.net 'unsafe-inline'; font-src 'self'; frame-src 'self' 'unsafe-inline' https://www.youtube-nocookie.com https://resources.digital-cloud-uk.medallia.eu https://lo.tokenizer.liveperson.net https://lo.msghist.liveperson.net https://lo.msg.liveperson.net https://lpcdn.lpsnmedia.net lo.idp.liveperson.net server.lon.liveperson.net https://authorize.omniture.com https://sitecatalyst.omniture.com service.maxymiser.net https://edigitalsurvey.com https://www.youtube.com https://santander.demdex.net https://*.fls.doubleclick.net; object-src 'self'; media-src lpcdn.lpsnmedia.net; worker-src blob:;", "anomaly": "unsafe-eval"}, {"rule": "Strict-Transport-Security", "severity": "high", "message": "Header not included in response", "expected": ["max-age=31536000", "includesubdomains"], "delimiter": ";"}, {"rule": "Cache-Control", "severity": "high", "message": "Value does not match security policy", "expected": ["no-cache", "no-store", "must-revalidate"], "delimiter": ",", "value": "private, must-revalidate, max-age=900"}, {"rule": "Pragma", "severity": "high", "message": "Header not included in response", "expected": ["no-cache"], "delimiter": ";"}]
1+
[
2+
{
3+
"rule": "Content-Security-Policy",
4+
"severity": "high",
5+
"message": "Must-Contain-One directive missed",
6+
"expected": [
7+
"default-src 'none'",
8+
"default-src 'self'"
9+
],
10+
"delimiter": ";",
11+
"value": "default-src 'self' service.maxymiser.net; child-src 'self' 'unsafe-inline' https://www.googleadservices.com https://*.fls.doubleclick.net/ https://*.santander.co.uk https://santander.demdex.net; script-src 'self' 'unsafe-inline' https://track.omguk.com https://cdn.usersnap.com https://screencapture.kampyle.com https://nebula-cdn.kampyle.com https://resources.digital-cloud-uk.medallia.eu https://pagead2.googlesyndication.com https://js-cdn.dynatrace.com https://activitymap.adobe.com https://cdn-ukwest.onetrust.com https://cdn.mouseflow.com https://googleads.g.doubleclick.net lptag.liveperson.net lo.v.liveperson.net lo.msg.liveperson.net accdn.lpsnmedia.net lpcdn.lpsnmedia.net https://www.googletagservices.com https://ad.doubleclick.net service.maxymiser.net https://connect.facebook.net https://*.fls.doubleclick.net/ https://www.googleadservices.com https://www.googletagmanager.com https://assets.adobedtm.com https://dpm.demdex.net/ https://*.santander.co.uk 'unsafe-eval'; connect-src 'self' 'unsafe-inline' https://udc-neb.kampyle.com https://*.bf.dynatrace.com https://privacyportal-uk.onetrust.com https://cdn-ukwest.onetrust.com https://o2.mouseflow.com https://googleads4.g.doubleclick.net wss://lo.msg.liveperson.net https://dpm.demdex.net https://*.santander.co.uk; img-src 'self' https://lpcdn.lpsnmedia.net service.maxymiser.net 'unsafe-inline' https://*.santander.co.uk data: https:; style-src 'self' service.maxymiser.net 'unsafe-inline'; font-src 'self'; frame-src 'self' 'unsafe-inline' https://www.youtube-nocookie.com https://resources.digital-cloud-uk.medallia.eu https://lo.tokenizer.liveperson.net https://lo.msghist.liveperson.net https://lo.msg.liveperson.net https://lpcdn.lpsnmedia.net lo.idp.liveperson.net server.lon.liveperson.net https://authorize.omniture.com https://sitecatalyst.omniture.com service.maxymiser.net https://edigitalsurvey.com https://www.youtube.com https://santander.demdex.net https://*.fls.doubleclick.net; object-src 'self'; media-src lpcdn.lpsnmedia.net; worker-src blob:;",
12+
"anomaly": [
13+
"default-src 'none'",
14+
"default-src 'self'"
15+
]
16+
},
17+
{
18+
"rule": "Content-Security-Policy",
19+
"severity": "medium",
20+
"message": "Must-Avoid directive included",
21+
"avoid": [
22+
"unsafe-inline",
23+
"unsafe-eval"
24+
],
25+
"delimiter": ";",
26+
"value": "default-src 'self' service.maxymiser.net; child-src 'self' 'unsafe-inline' https://www.googleadservices.com https://*.fls.doubleclick.net/ https://*.santander.co.uk https://santander.demdex.net; script-src 'self' 'unsafe-inline' https://track.omguk.com https://cdn.usersnap.com https://screencapture.kampyle.com https://nebula-cdn.kampyle.com https://resources.digital-cloud-uk.medallia.eu https://pagead2.googlesyndication.com https://js-cdn.dynatrace.com https://activitymap.adobe.com https://cdn-ukwest.onetrust.com https://cdn.mouseflow.com https://googleads.g.doubleclick.net lptag.liveperson.net lo.v.liveperson.net lo.msg.liveperson.net accdn.lpsnmedia.net lpcdn.lpsnmedia.net https://www.googletagservices.com https://ad.doubleclick.net service.maxymiser.net https://connect.facebook.net https://*.fls.doubleclick.net/ https://www.googleadservices.com https://www.googletagmanager.com https://assets.adobedtm.com https://dpm.demdex.net/ https://*.santander.co.uk 'unsafe-eval'; connect-src 'self' 'unsafe-inline' https://udc-neb.kampyle.com https://*.bf.dynatrace.com https://privacyportal-uk.onetrust.com https://cdn-ukwest.onetrust.com https://o2.mouseflow.com https://googleads4.g.doubleclick.net wss://lo.msg.liveperson.net https://dpm.demdex.net https://*.santander.co.uk; img-src 'self' https://lpcdn.lpsnmedia.net service.maxymiser.net 'unsafe-inline' https://*.santander.co.uk data: https:; style-src 'self' service.maxymiser.net 'unsafe-inline'; font-src 'self'; frame-src 'self' 'unsafe-inline' https://www.youtube-nocookie.com https://resources.digital-cloud-uk.medallia.eu https://lo.tokenizer.liveperson.net https://lo.msghist.liveperson.net https://lo.msg.liveperson.net https://lpcdn.lpsnmedia.net lo.idp.liveperson.net server.lon.liveperson.net https://authorize.omniture.com https://sitecatalyst.omniture.com service.maxymiser.net https://edigitalsurvey.com https://www.youtube.com https://santander.demdex.net https://*.fls.doubleclick.net; object-src 'self'; media-src lpcdn.lpsnmedia.net; worker-src blob:;",
27+
"anomaly": "unsafe-inline"
28+
},
29+
{
30+
"rule": "Content-Security-Policy",
31+
"severity": "medium",
32+
"message": "Must-Avoid directive included",
33+
"avoid": [
34+
"unsafe-inline",
35+
"unsafe-eval"
36+
],
37+
"delimiter": ";",
38+
"value": "default-src 'self' service.maxymiser.net; child-src 'self' 'unsafe-inline' https://www.googleadservices.com https://*.fls.doubleclick.net/ https://*.santander.co.uk https://santander.demdex.net; script-src 'self' 'unsafe-inline' https://track.omguk.com https://cdn.usersnap.com https://screencapture.kampyle.com https://nebula-cdn.kampyle.com https://resources.digital-cloud-uk.medallia.eu https://pagead2.googlesyndication.com https://js-cdn.dynatrace.com https://activitymap.adobe.com https://cdn-ukwest.onetrust.com https://cdn.mouseflow.com https://googleads.g.doubleclick.net lptag.liveperson.net lo.v.liveperson.net lo.msg.liveperson.net accdn.lpsnmedia.net lpcdn.lpsnmedia.net https://www.googletagservices.com https://ad.doubleclick.net service.maxymiser.net https://connect.facebook.net https://*.fls.doubleclick.net/ https://www.googleadservices.com https://www.googletagmanager.com https://assets.adobedtm.com https://dpm.demdex.net/ https://*.santander.co.uk 'unsafe-eval'; connect-src 'self' 'unsafe-inline' https://udc-neb.kampyle.com https://*.bf.dynatrace.com https://privacyportal-uk.onetrust.com https://cdn-ukwest.onetrust.com https://o2.mouseflow.com https://googleads4.g.doubleclick.net wss://lo.msg.liveperson.net https://dpm.demdex.net https://*.santander.co.uk; img-src 'self' https://lpcdn.lpsnmedia.net service.maxymiser.net 'unsafe-inline' https://*.santander.co.uk data: https:; style-src 'self' service.maxymiser.net 'unsafe-inline'; font-src 'self'; frame-src 'self' 'unsafe-inline' https://www.youtube-nocookie.com https://resources.digital-cloud-uk.medallia.eu https://lo.tokenizer.liveperson.net https://lo.msghist.liveperson.net https://lo.msg.liveperson.net https://lpcdn.lpsnmedia.net lo.idp.liveperson.net server.lon.liveperson.net https://authorize.omniture.com https://sitecatalyst.omniture.com service.maxymiser.net https://edigitalsurvey.com https://www.youtube.com https://santander.demdex.net https://*.fls.doubleclick.net; object-src 'self'; media-src lpcdn.lpsnmedia.net; worker-src blob:;",
39+
"anomaly": "unsafe-eval"
40+
},
41+
{
42+
"rule": "Strict-Transport-Security",
43+
"severity": "high",
44+
"message": "Header not included in response",
45+
"expected": [
46+
"max-age=31536000",
47+
"includesubdomains"
48+
],
49+
"delimiter": ";"
50+
},
51+
{
52+
"rule": "Cache-Control",
53+
"severity": "high",
54+
"message": "Value does not match security policy",
55+
"expected": [
56+
"no-cache",
57+
"no-store",
58+
"must-revalidate"
59+
],
60+
"delimiter": ",",
61+
"value": "private, must-revalidate, max-age=900"
62+
},
63+
{
64+
"rule": "Pragma",
65+
"severity": "high",
66+
"message": "Header not included in response",
67+
"expected": [
68+
"no-cache"
69+
],
70+
"delimiter": ";"
71+
}
72+
]
Lines changed: 104 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -1 +1,104 @@
1-
[{"rule": "Content-Security-Policy", "severity": "high", "message": "Header not included in response"}, {"rule": "X-XSS-Protection", "severity": "high", "message": "Value does not match security policy", "expected": ["1", "mode=block"], "delimiter": ";", "value": "0"}, {"rule": "Server", "severity": "high", "message": "Header should not be returned"}, {"rule": "Strict-Transport-Security", "severity": "high", "message": "Header not included in response", "expected": ["max-age=31536000", "includesubdomains"], "delimiter": ";"}, {"rule": "X-Content-Type-Options", "severity": "high", "message": "Header not included in response", "expected": ["nosniff"], "delimiter": ";"}, {"rule": "Set-Cookie", "severity": "high", "message": "Must-Contain directive missed", "expected": ["httponly", "secure"], "delimiter": ";", "value": "nid=208=d8xko0gp8g_pycvdqrwtvdpdiu_7es-hyvqugfqshzyjz5sozpy3y0ayn4kzdkpuzz-ylqjsydscnyuf58liz54ytg7by8smauul5noxicgela-oyi5lu4d_juan8geufgyxg1xao2bqronqyiplvbivs-nndfbywyjwnz0myso; expires=wed, 11-aug-2021 16:59:02 gmt; path=/; domain=.google.com; httponly", "anomaly": "secure"}, {"rule": "Set-Cookie", "severity": "medium", "message": "Must-Contain directive missed", "expected": ["httponly", "secure"], "delimiter": ";", "value": "consent=pending+061; expires=fri, 01-jan-2038 00:00:00 gmt; path=/; domain=.google.com", "anomaly": "httponly"}, {"rule": "Set-Cookie", "severity": "high", "message": "Must-Contain directive missed", "expected": ["httponly", "secure"], "delimiter": ";", "value": "consent=pending+061; expires=fri, 01-jan-2038 00:00:00 gmt; path=/; domain=.google.com", "anomaly": "secure"}, {"rule": "Referrer-Policy", "severity": "high", "message": "Header not included in response"}, {"rule": "Cache-Control", "severity": "high", "message": "Value does not match security policy", "expected": ["no-cache", "no-store", "must-revalidate"], "delimiter": ",", "value": "private, max-age=0"}, {"rule": "Pragma", "severity": "high", "message": "Header not included in response", "expected": ["no-cache"], "delimiter": ";"}]
1+
[
2+
{
3+
"rule": "Content-Security-Policy",
4+
"severity": "high",
5+
"message": "Header not included in response"
6+
},
7+
{
8+
"rule": "X-XSS-Protection",
9+
"severity": "high",
10+
"message": "Value does not match security policy",
11+
"expected": [
12+
"1",
13+
"mode=block"
14+
],
15+
"delimiter": ";",
16+
"value": "0"
17+
},
18+
{
19+
"rule": "Server",
20+
"severity": "high",
21+
"message": "Header should not be returned"
22+
},
23+
{
24+
"rule": "Strict-Transport-Security",
25+
"severity": "high",
26+
"message": "Header not included in response",
27+
"expected": [
28+
"max-age=31536000",
29+
"includesubdomains"
30+
],
31+
"delimiter": ";"
32+
},
33+
{
34+
"rule": "X-Content-Type-Options",
35+
"severity": "high",
36+
"message": "Header not included in response",
37+
"expected": [
38+
"nosniff"
39+
],
40+
"delimiter": ";"
41+
},
42+
{
43+
"rule": "Set-Cookie",
44+
"severity": "high",
45+
"message": "Must-Contain directive missed",
46+
"expected": [
47+
"httponly",
48+
"secure"
49+
],
50+
"delimiter": ";",
51+
"value": "nid=208=d8xko0gp8g_pycvdqrwtvdpdiu_7es-hyvqugfqshzyjz5sozpy3y0ayn4kzdkpuzz-ylqjsydscnyuf58liz54ytg7by8smauul5noxicgela-oyi5lu4d_juan8geufgyxg1xao2bqronqyiplvbivs-nndfbywyjwnz0myso; expires=wed, 11-aug-2021 16:59:02 gmt; path=/; domain=.google.com; httponly",
52+
"anomaly": "secure"
53+
},
54+
{
55+
"rule": "Set-Cookie",
56+
"severity": "medium",
57+
"message": "Must-Contain directive missed",
58+
"expected": [
59+
"httponly",
60+
"secure"
61+
],
62+
"delimiter": ";",
63+
"value": "consent=pending+061; expires=fri, 01-jan-2038 00:00:00 gmt; path=/; domain=.google.com",
64+
"anomaly": "httponly"
65+
},
66+
{
67+
"rule": "Set-Cookie",
68+
"severity": "high",
69+
"message": "Must-Contain directive missed",
70+
"expected": [
71+
"httponly",
72+
"secure"
73+
],
74+
"delimiter": ";",
75+
"value": "consent=pending+061; expires=fri, 01-jan-2038 00:00:00 gmt; path=/; domain=.google.com",
76+
"anomaly": "secure"
77+
},
78+
{
79+
"rule": "Referrer-Policy",
80+
"severity": "high",
81+
"message": "Header not included in response"
82+
},
83+
{
84+
"rule": "Cache-Control",
85+
"severity": "high",
86+
"message": "Value does not match security policy",
87+
"expected": [
88+
"no-cache",
89+
"no-store",
90+
"must-revalidate"
91+
],
92+
"delimiter": ",",
93+
"value": "private, max-age=0"
94+
},
95+
{
96+
"rule": "Pragma",
97+
"severity": "high",
98+
"message": "Header not included in response",
99+
"expected": [
100+
"no-cache"
101+
],
102+
"delimiter": ";"
103+
}
104+
]
Lines changed: 3 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -1 +1,3 @@
1-
{"Alerts": []}
1+
{
2+
"Alerts": []
3+
}
Lines changed: 8 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -1 +1,8 @@
1-
{"additionalData": {"totalItems": 0, "paging": {}}, "supportToken": "123442284e284dddb0652ff65c9f3ebd1731540952924", "response": []}
1+
{
2+
"additionalData": {
3+
"totalItems": 0,
4+
"paging": {}
5+
},
6+
"supportToken": "123442284e284dddb0652ff65c9f3ebd1731540952924",
7+
"response": []
8+
}
Lines changed: 2 additions & 4 deletions
Original file line numberDiff line numberDiff line change
@@ -1,5 +1,3 @@
1-
{
2-
"vulnerabilities":[
3-
4-
]
1+
{
2+
"vulnerabilities": []
53
}

unittests/scans/semgrep/empty.json

Lines changed: 4 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -1 +1,4 @@
1-
{"results": [], "errors": []}
1+
{
2+
"results": [],
3+
"errors": []
4+
}

0 commit comments

Comments
 (0)