Josh Soref

Results 732 issues of Josh Soref

### Is your feature request related to a problem? Please describe. I'm trying to review the domains for sampled alerts based on the first line of each HTTP request When...

enhancement

### Describe the bug https://github.com/zaproxy/zap-extensions/blob/b24dd355a0975e985b391e4cd4eebaf2079410bf/addOns/ascanrulesBeta/src/main/java/org/zaproxy/zap/extension/ascanrulesBeta/ForbiddenBypassScanRule.java#L92 has code to look at various pages, but it has no code to say "oh, this matches the SPA page, and therefore isn't exceptional". ###...

bug

### Describe the bug UserAgentScanRule is a bit overzealous. If it was used against an endpoint [`/clock`](https://www.timeanddate.com/) which returned the current time or [`/random`](https://www.random.org/integers/?num=1&min=1&max=100&col=5&base=10&format=html&rnd=new) that returned a random number, or...

FalsePositive
add-on

### Describe the bug HiddenFilesScanRule complains about http->https redirects or cases where the response is a generic /index page ### Steps to reproduce the behavior 1. Go to http://mozilla.org/ 2....

FalsePositive
add-on

### Describe the bug I have a server which will freely respond with `x-forwarded` headers: https://api.test.glaypen.garnercorp.com/say-what-you-want When the ProxyDisclosureScanRule rule runs, it will generate this report item: ```yaml 1 proxy...

FalsePositive
add-on

0. If necessary, set up and start your Screen Reader (which will be very disappointed by blank column headers/menu items) 1. Install ZAP 2.15.0 (arm64, on macOS 14.5) 2. Open...

Component-UI
Usability
assistive

Please consider changing your 504 error page to not embed 5 woff, 2 eot, and 1 truetype fonts as data: urls. The page is 3/4mb. >1/4mb of that is fonts...

enhancement

Fixes misspellings identified by the [check-spelling action](https://github.com/marketplace/actions/check-spelling). The misspellings have been reported at https://github.com/jsoref/viamillipede/actions/runs/10508412502#summary-29112253598 The action will report that the changes in this PR would make it happy: https://github.com/jsoref/viamillipede/actions/runs/10508412524#summary-29112253587

https://github.com/actions/runner/blob/8b9a81c952a0c2a2a13a23b952c6a083c97f2a1b/src/Runner.Listener/JobDispatcher.cs#L370 I'm self-hosting a runner in an organization. The organization has a lot of repositories many of which have workflows with the same name. I'd expect a log item to...

https://www.ibm.com/docs/en/cloud-private/3.2.x?topic=manager-using-acme-issue-certificates > The issuer is used primarily with the ACME server that is hosted at letsencrypt.org. For more information about the ACME HTTP issuer and the letsencrypt.org certificate authority, see:...