-
Updated
Oct 13, 2021 - Shell
security-scanner
Here are 307 public repositories matching this topic...
-
Updated
Oct 13, 2021 - Go
-
Updated
Oct 10, 2021 - Ruby
-
Updated
Sep 13, 2021 - C#
Describe the bug
In the docs found here:
https://bandit.readthedocs.io/en/latest/plugins/index.html#complete-test-plugin-listing
B109 and B111 show a description instead of a plugin name. This looks inconsistent since all the other plugin names are listed. I believe this is a result of a recent change to remove these deprecated plugins.
To Reproduce
- Navigate to https://bandit
🐞 Bug report
Description
In vscode, whenever I set the "extends" property in my tsconfig.json file, webhint gives the following error message:
Unexpected token } in JSON at position 705 (typescript-config/is-valid)
Details
-
Updated
Sep 20, 2021 - C#
-
Updated
Jun 30, 2021 - Python
-
Updated
Aug 7, 2020
-
Updated
Aug 18, 2021
-
Updated
Oct 2, 2021 - Python
-
Updated
Sep 2, 2021 - Lua
-
Updated
Oct 10, 2021 - CSS
-
Updated
Jul 6, 2020 - Python
-
Updated
Sep 8, 2021 - Python
-
Updated
Oct 13, 2021 - Go
-
Updated
Jan 15, 2021 - C++
-
Updated
Oct 12, 2021 - Ruby
-
Updated
Aug 19, 2020
-
Updated
Sep 20, 2021 - Python
-
Updated
Apr 26, 2020 - Python
-
Updated
Sep 15, 2021 - Perl
-
Updated
Oct 4, 2021 - Rust
-
Updated
Feb 3, 2020 - Python
-
Updated
Jul 31, 2021 - Python
-
Updated
Feb 23, 2021 - Go
-
Updated
Nov 20, 2020
-
Updated
Sep 16, 2021 - Python
-
Updated
Aug 6, 2021 - Python
Improve this page
Add a description, image, and links to the security-scanner topic page so that developers can more easily learn about it.
Add this topic to your repo
To associate your repository with the security-scanner topic, visit your repo's landing page and select "manage topics."


Hi,
I am getting some XSS Reflected and persistent alerts generated when a .xls or .pdf file contains unsantised XSS injection strings. I do not want to add an alert filter because it is an .asp page that generates these files and so there could be another XSS vulnerability on the page.
I was wondering if the XSS rule could check the Content-Type header and the file identifying line (first