google / csp-evaluator

https://csp-evaluator.withgoogle.com
Apache License 2.0
335 stars 46 forks source link

Remove dev.virtualearth.net #59

Open tosmolka opened 1 year ago

tosmolka commented 1 year ago

This endpoint now validates JSONP callback and is no longer vulnerable.

Can we remove it from the list? Or are there any other known vulnerable endpoints behind dev.virtualearth.net that still need fixing? Thanks.

image