-
# Summary
A Reflected Cross-Site Scripting (XSS) vulnerability has been identified in the Xinhu RockOA v2.6.3.
# Details
The XSS vulnerability originates from `/include/chajian/inputChajian.php`:
…
-
Dear team,
**Issue**
I am experiencing issues on the SQL performance of DefectDojo Webapplication.
I have a 3000 users, 1000 product types, 3000 products and around 5 million Findings registered …
-
# Security Scan Report: PharmaLedger-IMI/fgt-workspace
![img](https://img.shields.io/badge/SCA%20-%2045%20HIGH%20vuln.%20found-red.svg) ![img](https://img.shields.io/badge/SAST%20-%2031%20MEDIUM%20v…
-
As suggested in https://github.com/ossf-cve-benchmark/ossf-cve-benchmark/issues/67#issuecomment-770846153.
(Remember to check licensing for the data set)
-
> This prev. open PR could contain useful inputs: https://github.com/OWASP/owasp-mastg/pull/2604/files#diff-a6472df266173afc665035280a844525ce81374d2b343070dfd37a24deffa541
## Description
Create…
-
First, I think this benchmark is much needed and can bring great value.
I am personally working on vulnerabilities for `Python`, `Java` and `C`.
Is there is any plan to add support for other lang…
-
### What needs to be done
Implement SAST (Static Application Security Testing).
### Why it needs to be done
Currently, static code analysis is not implemented. We can introduce SAST for suppo…
-
## What/Why
### What are you proposing?
_Analyze overall code quality in the automated pipeline._
### What problems are you trying to solve?
_When make PR pull , a contributors wants to check up…
-
The "Code security and analysis" personal org settings page lists several options for Dependabot SCA third party security scans, but lists no option for CodeQL SAST first party security scans.
This…
-
### What's the problem this feature will solve?
https://github.com/ossf/scorecard is a useful tool for analysing the project's security best-practices. It would be nice to see the pip project add th…
wwuck updated
6 months ago