Closing as intentional: compliance-dast is a security scanner and must be able to probe targets with self-signed/invalid certificates, so danger_accept_invalid_certs(true) is by design. It…
Closing as intentional: compliance-dast is a security scanner and must be able to probe targets with self-signed/invalid certificates, so danger_accept_invalid_certs(true) is by design. It…
Closing as intentional: the ws:// here is the Chrome DevTools Protocol connection to the internal headless-Chrome container (CHROME_WS_URL) used for PDF rendering. It never leaves the internal…
Closing as intentional: the ws:// here is the Chrome DevTools Protocol connection to the internal headless-Chrome container (CHROME_WS_URL) used for PDF rendering. It never leaves the internal…
Closing as false positive: match is key:"_getDistanceToBezierEdge2" inside the vendored/minified vis-network.min.js — a JS object property name, not a secret. Vendored assets should be…
Closing as false positive: these are hardcoded test vectors in the #[cfg(test)] module of compliance-agent/src/pentest/crypto.rs (obvious sequential hex like 0123456789abcdef...), not real…
Closing as false positive: these are hardcoded test vectors in the #[cfg(test)] module of compliance-agent/src/pentest/crypto.rs (obvious sequential hex like 0123456789abcdef...), not real…
Closing as false positive: these are hardcoded test vectors in the #[cfg(test)] module of compliance-agent/src/pentest/crypto.rs (obvious sequential hex like 0123456789abcdef...), not real…
Closing as false positive: this finding points at the scanner's own pattern unit tests in compliance-agent/src/pipeline/patterns.rs (test assertions like is_match(...) containing the trigger…
Closing as false positive: this finding points at the scanner's own pattern unit tests in compliance-agent/src/pipeline/patterns.rs (test assertions like is_match(...) containing the trigger…