google / csp-evaluator

https://csp-evaluator.withgoogle.com
Apache License 2.0
315 stars 45 forks source link

Remove dev.virtualearth.net #59

Open tosmolka opened 1 year ago

tosmolka commented 1 year ago

This endpoint now validates JSONP callback and is no longer vulnerable.

Can we remove it from the list? Or are there any other known vulnerable endpoints behind dev.virtualearth.net that still need fixing? Thanks.

image