Skip to content

Commit eccf0cc

Browse files
Add security scan reports [skip ci]
1 parent 9ecb08f commit eccf0cc

4 files changed

Lines changed: 32 additions & 166 deletions

File tree

docs/reports/README.md

Lines changed: 14 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -30,3 +30,17 @@ Generated on Sun Sep 7 16:43:57 UTC 2025
3030
- [report_json.json](./report_json.json)
3131
- [report_md.md](./report_md.md)
3232
- [trufflehog-results.json](./trufflehog-results.json)
33+
- **zap-reports**
34+
- [README.md](./README.md)
35+
- [angular-xss-api-sbom.json](./angular-xss-api-sbom.json)
36+
- [angular-xss-frontend-sbom.json](./angular-xss-frontend-sbom.json)
37+
- [angular-xss-sbom.json](./angular-xss-sbom.json)
38+
- [api-bom.xml](./api-bom.xml)
39+
- [codeql-results.sarif](./codeql-results.sarif)
40+
- [dependency-check-report.sarif](./dependency-check-report.sarif)
41+
- [frontend-bom.xml](./frontend-bom.xml)
42+
- [proper-zap-format.xml](./proper-zap-format.xml)
43+
- [report_html.html](./report_html.html)
44+
- [report_json.json](./report_json.json)
45+
- [report_md.md](./report_md.md)
46+
- [trufflehog-results.json](./trufflehog-results.json)

docs/reports/report_html.html

Lines changed: 9 additions & 133 deletions
Original file line numberDiff line numberDiff line change
@@ -212,7 +212,7 @@ <h2>
212212
</h2>
213213

214214
<h3>
215-
Generated on Sun, 7 Sept 2025 18:21:18
215+
Generated on Sun, 7 Sept 2025 18:42:36
216216
</h3>
217217

218218
<h3>
@@ -358,22 +358,22 @@ <h3>Alerts</h3>
358358
<tr>
359359
<td><a href="#90005">Sec-Fetch-Dest Header is Missing</a></td>
360360
<td align="center" class="risk-0">Informational</td>
361-
<td align="center">3</td>
361+
<td align="center">2</td>
362362
</tr>
363363
<tr>
364364
<td><a href="#90005">Sec-Fetch-Mode Header is Missing</a></td>
365365
<td align="center" class="risk-0">Informational</td>
366-
<td align="center">3</td>
366+
<td align="center">2</td>
367367
</tr>
368368
<tr>
369369
<td><a href="#90005">Sec-Fetch-Site Header is Missing</a></td>
370370
<td align="center" class="risk-0">Informational</td>
371-
<td align="center">3</td>
371+
<td align="center">2</td>
372372
</tr>
373373
<tr>
374374
<td><a href="#90005">Sec-Fetch-User Header is Missing</a></td>
375375
<td align="center" class="risk-0">Informational</td>
376-
<td align="center">3</td>
376+
<td align="center">2</td>
377377
</tr>
378378
<tr>
379379
<td><a href="#10049">Storable and Cacheable Content</a></td>
@@ -3012,40 +3012,9 @@ <h3>Alert Detail</h3>
30123012
<td width="80%"></td>
30133013
</tr>
30143014

3015-
<tr>
3016-
<td width="20%"
3017-
class="indent1">URL</td>
3018-
<td width="80%"><a href="http://localhost:4200/sitemap.xml">http://localhost:4200/sitemap.xml</a></td>
3019-
</tr>
3020-
<tr>
3021-
<td width="20%"
3022-
class="indent2">Method</td>
3023-
<td width="80%">GET</td>
3024-
</tr>
3025-
<tr>
3026-
<td width="20%"
3027-
class="indent2">Parameter</td>
3028-
<td width="80%">Sec-Fetch-Dest</td>
3029-
</tr>
3030-
<tr>
3031-
<td width="20%"
3032-
class="indent2">Attack</td>
3033-
<td width="80%"></td>
3034-
</tr>
3035-
<tr>
3036-
<td width="20%"
3037-
class="indent2">Evidence</td>
3038-
<td width="80%"></td>
3039-
</tr>
3040-
<tr>
3041-
<td width="20%"
3042-
class="indent2">Other Info</td>
3043-
<td width="80%"></td>
3044-
</tr>
3045-
30463015
<tr>
30473016
<td width="20%">Instances</td>
3048-
<td width="80%">3</td>
3017+
<td width="80%">2</td>
30493018
</tr>
30503019
<tr>
30513020
<td width="20%">Solution</td>
@@ -3158,40 +3127,9 @@ <h3>Alert Detail</h3>
31583127
<td width="80%"></td>
31593128
</tr>
31603129

3161-
<tr>
3162-
<td width="20%"
3163-
class="indent1">URL</td>
3164-
<td width="80%"><a href="http://localhost:4200/sitemap.xml">http://localhost:4200/sitemap.xml</a></td>
3165-
</tr>
3166-
<tr>
3167-
<td width="20%"
3168-
class="indent2">Method</td>
3169-
<td width="80%">GET</td>
3170-
</tr>
3171-
<tr>
3172-
<td width="20%"
3173-
class="indent2">Parameter</td>
3174-
<td width="80%">Sec-Fetch-Mode</td>
3175-
</tr>
3176-
<tr>
3177-
<td width="20%"
3178-
class="indent2">Attack</td>
3179-
<td width="80%"></td>
3180-
</tr>
3181-
<tr>
3182-
<td width="20%"
3183-
class="indent2">Evidence</td>
3184-
<td width="80%"></td>
3185-
</tr>
3186-
<tr>
3187-
<td width="20%"
3188-
class="indent2">Other Info</td>
3189-
<td width="80%"></td>
3190-
</tr>
3191-
31923130
<tr>
31933131
<td width="20%">Instances</td>
3194-
<td width="80%">3</td>
3132+
<td width="80%">2</td>
31953133
</tr>
31963134
<tr>
31973135
<td width="20%">Solution</td>
@@ -3304,40 +3242,9 @@ <h3>Alert Detail</h3>
33043242
<td width="80%"></td>
33053243
</tr>
33063244

3307-
<tr>
3308-
<td width="20%"
3309-
class="indent1">URL</td>
3310-
<td width="80%"><a href="http://localhost:4200/sitemap.xml">http://localhost:4200/sitemap.xml</a></td>
3311-
</tr>
3312-
<tr>
3313-
<td width="20%"
3314-
class="indent2">Method</td>
3315-
<td width="80%">GET</td>
3316-
</tr>
3317-
<tr>
3318-
<td width="20%"
3319-
class="indent2">Parameter</td>
3320-
<td width="80%">Sec-Fetch-Site</td>
3321-
</tr>
3322-
<tr>
3323-
<td width="20%"
3324-
class="indent2">Attack</td>
3325-
<td width="80%"></td>
3326-
</tr>
3327-
<tr>
3328-
<td width="20%"
3329-
class="indent2">Evidence</td>
3330-
<td width="80%"></td>
3331-
</tr>
3332-
<tr>
3333-
<td width="20%"
3334-
class="indent2">Other Info</td>
3335-
<td width="80%"></td>
3336-
</tr>
3337-
33383245
<tr>
33393246
<td width="20%">Instances</td>
3340-
<td width="80%">3</td>
3247+
<td width="80%">2</td>
33413248
</tr>
33423249
<tr>
33433250
<td width="20%">Solution</td>
@@ -3450,40 +3357,9 @@ <h3>Alert Detail</h3>
34503357
<td width="80%"></td>
34513358
</tr>
34523359

3453-
<tr>
3454-
<td width="20%"
3455-
class="indent1">URL</td>
3456-
<td width="80%"><a href="http://localhost:4200/sitemap.xml">http://localhost:4200/sitemap.xml</a></td>
3457-
</tr>
3458-
<tr>
3459-
<td width="20%"
3460-
class="indent2">Method</td>
3461-
<td width="80%">GET</td>
3462-
</tr>
3463-
<tr>
3464-
<td width="20%"
3465-
class="indent2">Parameter</td>
3466-
<td width="80%">Sec-Fetch-User</td>
3467-
</tr>
3468-
<tr>
3469-
<td width="20%"
3470-
class="indent2">Attack</td>
3471-
<td width="80%"></td>
3472-
</tr>
3473-
<tr>
3474-
<td width="20%"
3475-
class="indent2">Evidence</td>
3476-
<td width="80%"></td>
3477-
</tr>
3478-
<tr>
3479-
<td width="20%"
3480-
class="indent2">Other Info</td>
3481-
<td width="80%"></td>
3482-
</tr>
3483-
34843360
<tr>
34853361
<td width="20%">Instances</td>
3486-
<td width="80%">3</td>
3362+
<td width="80%">2</td>
34873363
</tr>
34883364
<tr>
34893365
<td width="20%">Solution</td>

docs/reports/report_json.json

Lines changed: 1 addition & 1 deletion
Large diffs are not rendered by default.

docs/reports/report_md.md

Lines changed: 8 additions & 32 deletions
Original file line numberDiff line numberDiff line change
@@ -31,10 +31,10 @@ ZAP by [Checkmarx](https://checkmarx.com/).
3131
| Base64 Disclosure | Informational | 4 |
3232
| Information Disclosure - Suspicious Comments | Informational | 4 |
3333
| Modern Web Application | Informational | 2 |
34-
| Sec-Fetch-Dest Header is Missing | Informational | 3 |
35-
| Sec-Fetch-Mode Header is Missing | Informational | 3 |
36-
| Sec-Fetch-Site Header is Missing | Informational | 3 |
37-
| Sec-Fetch-User Header is Missing | Informational | 3 |
34+
| Sec-Fetch-Dest Header is Missing | Informational | 2 |
35+
| Sec-Fetch-Mode Header is Missing | Informational | 2 |
36+
| Sec-Fetch-Site Header is Missing | Informational | 2 |
37+
| Sec-Fetch-User Header is Missing | Informational | 2 |
3838
| Storable and Cacheable Content | Informational | 10 |
3939

4040

@@ -800,14 +800,8 @@ Specifies how and where the data would be used. For instance, if the value is au
800800
* Attack: ``
801801
* Evidence: ``
802802
* Other Info: ``
803-
* URL: http://localhost:4200/sitemap.xml
804-
* Method: `GET`
805-
* Parameter: `Sec-Fetch-Dest`
806-
* Attack: ``
807-
* Evidence: ``
808-
* Other Info: ``
809803

810-
Instances: 3
804+
Instances: 2
811805

812806
### Solution
813807

@@ -848,14 +842,8 @@ Allows to differentiate between requests for navigating between HTML pages and r
848842
* Attack: ``
849843
* Evidence: ``
850844
* Other Info: ``
851-
* URL: http://localhost:4200/sitemap.xml
852-
* Method: `GET`
853-
* Parameter: `Sec-Fetch-Mode`
854-
* Attack: ``
855-
* Evidence: ``
856-
* Other Info: ``
857845

858-
Instances: 3
846+
Instances: 2
859847

860848
### Solution
861849

@@ -896,14 +884,8 @@ Specifies the relationship between request initiator's origin and target's origi
896884
* Attack: ``
897885
* Evidence: ``
898886
* Other Info: ``
899-
* URL: http://localhost:4200/sitemap.xml
900-
* Method: `GET`
901-
* Parameter: `Sec-Fetch-Site`
902-
* Attack: ``
903-
* Evidence: ``
904-
* Other Info: ``
905887

906-
Instances: 3
888+
Instances: 2
907889

908890
### Solution
909891

@@ -944,14 +926,8 @@ Specifies if a navigation request was initiated by a user.
944926
* Attack: ``
945927
* Evidence: ``
946928
* Other Info: ``
947-
* URL: http://localhost:4200/sitemap.xml
948-
* Method: `GET`
949-
* Parameter: `Sec-Fetch-User`
950-
* Attack: ``
951-
* Evidence: ``
952-
* Other Info: ``
953929

954-
Instances: 3
930+
Instances: 2
955931

956932
### Solution
957933

0 commit comments

Comments
 (0)