eclipse-tractusx / managed-identity-wallet

Apache License 2.0
9 stars 22 forks source link

Fix DAST scan reports openly #256

Closed borisrizov-zf closed 7 months ago

borisrizov-zf commented 7 months ago

Description

The DAST scan reports security issues openly at the moment. This should be minimized by removing the report step and furthermore adding a minimal retention time for the report files. This way the report files can be downloaded after a scan and examined. Third parties would have only a limited window to examine these, given they know when a scan is run, thus minimizing the risk of accidental security issue leaks.

Pre-review checks

Please ensure to do as many of the following checks as possible, before asking for committer review:

sonarcloud[bot] commented 7 months ago

Quality Gate Passed Quality Gate passed

Issues
8 New issues

Measures
0 Security Hotspots
No data about Coverage
0.0% Duplication on New Code

See analysis details on SonarCloud

github-actions[bot] commented 7 months ago

:tada: This PR is included in version 0.5.0-develop.3 :tada:

The release is available on GitHub release

Your semantic-release bot :package::rocket:

github-actions[bot] commented 3 months ago

:tada: This issue has been resolved in version 0.5.0 :tada:

The release is available on GitHub release

Your semantic-release bot :package::rocket: