h3xstream / burp-retire-js

Burp/ZAP/Maven extension that integrate Retire.js repository to find vulnerable Javascript libraries.
Apache License 2.0
200 stars 56 forks source link

Tweaks for the ZAP Extension #40

Closed kingthorin closed 6 years ago

kingthorin commented 6 years ago

I have other changes in mind (like leveraging the Messages.properties file), and populating the evidence field (I can see how to get the regex from lib, but couldn't figure out how to get the match without re-analyzing the response. Any hints?)

kingthorin commented 6 years ago

@h3xstream look ok?

kingthorin commented 6 years ago

@h3xstream anything I can do to help move this?

h3xstream commented 6 years ago

@kingthorin Everything looks good! (I just have too many Github notifications.)

kingthorin commented 6 years ago

Thanks!

kingthorin commented 6 years ago

@h3xstream I know you're a busy guy, but if you have any input on this:

I have other changes in mind (like leveraging the Messages.properties file), and populating the evidence field (I can see how to get the regex from lib, but couldn't figure out how to get the match without re-analyzing the response. Any hints?)

I'd be glad to make a few more contributions.