Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

fx-breach-alerts.herokuapp.com has failed the web security baseline #1295

Closed
mozcloudsec opened this issue Oct 22, 2019 · 4 comments
Closed

Comments

@mozcloudsec
Copy link

Site https://fx-breach-alerts.herokuapp.com has failed the web security baseline scan.

The failing tests are:

Strict-Transport-Security Header Not Set [10035] x 15

Absence of Anti-CSRF Tokens [10202] x 1

This issue was automatically raised.

This issue is managed automatically by the baseline scan:

  • If the failing tests change then it will be updated
  • If it is closed before the tests pass then a new one will be opened
  • When all of the tests pass then it will be closed

Full details, including how to test for these issues locally, can be found on this Security Baseline Service dashboard.
If you have any questions or concerns please get in contact with @psiinon

@mozcloudsec
Copy link
Author

The following test(s) for site https://fx-breach-alerts.herokuapp.com have now passed:

  • Absence of Anti-CSRF Tokens

Keep up the good work!

groovecoder added a commit that referenced this issue Nov 14, 2019
groovecoder added a commit that referenced this issue Nov 14, 2019
@ghost
Copy link

ghost commented Feb 1, 2020

The web security baseline scan results for site https://fx-breach-alerts.herokuapp.com has new failures:

Content Security Policy (CSP) Header Not Set [10038] x 3

@ghost
Copy link

ghost commented Feb 1, 2020

The web security baseline for site https://fx-breach-alerts.herokuapp.com is still failing, this issue should stay open.

@ghost ghost reopened this Feb 1, 2020
@ghost ghost closed this as completed Feb 5, 2020
@ghost
Copy link

ghost commented May 14, 2020

The web security baseline scan for site https://fx-breach-alerts.herokuapp.com now passes - well done team!

This issue was closed.
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

1 participant