Skip to content

Commit

Permalink
Browse files Browse the repository at this point in the history
  • Loading branch information
DashlordBetaGouvBot committed Nov 13, 2022
1 parent bd2f378 commit ca2edbd
Show file tree
Hide file tree
Showing 14 changed files with 1,771 additions and 1,848 deletions.
2 changes: 1 addition & 1 deletion results/aHR0cHM6Ly9vcGVudGVybXNhcmNoaXZlLm9yZw==/http.json
Original file line number Diff line number Diff line change
@@ -1 +1 @@
{"url":"https://opentermsarchive.org","algorithm_version":2,"end_time":"Sun, 06 Nov 2022 01:46:59 GMT","grade":"B","hidden":false,"likelihood_indicator":"MEDIUM","response_headers":{"Cache-Control":"s-maxage=31536000, stale-while-revalidate","Connection":"keep-alive","Content-Encoding":"gzip","Content-Security-Policy":"default-src 'self'; script-src 'self' 'unsafe-eval' https://stats.data.gouv.fr; object-src 'none'; style-src 'self' 'unsafe-inline'; connect-src 'self' https://stats.data.gouv.fr; img-src 'self' data: https://media-exp1.licdn.com https://www.gravatar.com https://avatars.githubusercontent.com https://pbs.twimg.com https://sibyll.in; frame-src 'self' https://stats.data.gouv.fr","Content-Type":"text/html; charset=utf-8","Date":"Sun, 06 Nov 2022 01:46:56 GMT","ETag":"\"14up4hipkp51lg2\"","Strict-Transport-Security":"max-age=63072000; includeSubDomains; preload","Transfer-Encoding":"chunked","Vary":"Accept-Encoding","X-Content-Type-Options":"nosniff","X-Frame-Options":"DENY","X-Powered-By":"Next.js","X-Request-ID":"5e1589f1-351d-4474-83e4-7377a7c43676","X-XSS-Protection":"1; mode=block","x-nextjs-cache":"HIT"},"scan_id":30683112,"score":70,"start_time":"Sun, 06 Nov 2022 01:46:53 GMT","state":"FINISHED","status_code":200,"tests_failed":2,"tests_passed":10,"tests_quantity":12,"details":{"content-security-policy":{"expectation":"csp-implemented-with-no-unsafe","name":"content-security-policy","output":{"data":{"connect-src":["'self'","https://stats.data.gouv.fr"],"default-src":["'self'"],"frame-src":["'self'","https://stats.data.gouv.fr"],"img-src":["https://www.gravatar.com","'self'","https://media-exp1.licdn.com","https://avatars.githubusercontent.com","data:","https://sibyll.in","https://pbs.twimg.com"],"object-src":["'none'"],"script-src":["'self'","https://stats.data.gouv.fr","'unsafe-eval'"],"style-src":["'self'","'unsafe-inline'"]},"http":true,"meta":false,"numPolicies":1,"policy":{"antiClickjacking":false,"defaultNone":false,"insecureBaseUri":true,"insecureFormAction":true,"insecureSchemeActive":false,"insecureSchemePassive":false,"strictDynamic":false,"unsafeEval":true,"unsafeInline":false,"unsafeInlineStyle":true,"unsafeObjects":false}},"pass":false,"result":"csp-implemented-with-unsafe-eval","score_description":"Content Security Policy (CSP) implemented, but allows 'unsafe-eval'","score_modifier":-10},"contribute":{"expectation":"contribute-json-only-required-on-mozilla-properties","name":"contribute","output":{"data":null},"pass":true,"result":"contribute-json-only-required-on-mozilla-properties","score_description":"Contribute.json isn't required on websites that don't belong to Mozilla","score_modifier":0},"cookies":{"expectation":"cookies-secure-with-httponly-sessions","name":"cookies","output":{"data":null,"sameSite":null},"pass":true,"result":"cookies-not-found","score_description":"No cookies detected","score_modifier":0},"cross-origin-resource-sharing":{"expectation":"cross-origin-resource-sharing-not-implemented","name":"cross-origin-resource-sharing","output":{"data":{"acao":null,"clientaccesspolicy":null,"crossdomain":null}},"pass":true,"result":"cross-origin-resource-sharing-not-implemented","score_description":"Content is not visible via cross-origin resource sharing (CORS) files or headers","score_modifier":0},"public-key-pinning":{"expectation":"hpkp-not-implemented","name":"public-key-pinning","output":{"data":null,"includeSubDomains":false,"max-age":null,"numPins":null,"preloaded":false},"pass":true,"result":"hpkp-not-implemented","score_description":"HTTP Public Key Pinning (HPKP) header not implemented","score_modifier":0},"redirection":{"expectation":"redirection-to-https","name":"redirection","output":{"destination":"http://opentermsarchive.org/","redirects":false,"route":["http://opentermsarchive.org/"],"status_code":200},"pass":false,"result":"redirection-missing","score_description":"Does not redirect to an HTTPS site","score_modifier":-20},"referrer-policy":{"expectation":"referrer-policy-private","name":"referrer-policy","output":{"data":null,"http":false,"meta":false},"pass":true,"result":"referrer-policy-not-implemented","score_description":"Referrer-Policy header not implemented","score_modifier":0},"strict-transport-security":{"expectation":"hsts-implemented-max-age-at-least-six-months","name":"strict-transport-security","output":{"data":"max-age=63072000; includeSubDomains; preload","includeSubDomains":true,"max-age":63072000,"preload":true,"preloaded":false},"pass":true,"result":"hsts-implemented-max-age-at-least-six-months","score_description":"HTTP Strict Transport Security (HSTS) header set to a minimum of six months (15768000)","score_modifier":0},"subresource-integrity":{"expectation":"sri-implemented-and-external-scripts-loaded-securely","name":"subresource-integrity","output":{"data":{}},"pass":true,"result":"sri-not-implemented-but-all-scripts-loaded-from-secure-origin","score_description":"Subresource Integrity (SRI) not implemented, but all scripts are loaded from a similar origin","score_modifier":0},"x-content-type-options":{"expectation":"x-content-type-options-nosniff","name":"x-content-type-options","output":{"data":"nosniff"},"pass":true,"result":"x-content-type-options-nosniff","score_description":"X-Content-Type-Options header set to \"nosniff\"","score_modifier":0},"x-frame-options":{"expectation":"x-frame-options-sameorigin-or-deny","name":"x-frame-options","output":{"data":"DENY"},"pass":true,"result":"x-frame-options-sameorigin-or-deny","score_description":"X-Frame-Options (XFO) header set to SAMEORIGIN or DENY","score_modifier":0},"x-xss-protection":{"expectation":"x-xss-protection-1-mode-block","name":"x-xss-protection","output":{"data":"1; mode=block"},"pass":true,"result":"x-xss-protection-enabled-mode-block","score_description":"X-XSS-Protection header set to \"1; mode=block\"","score_modifier":0}}}
{"url":"https://opentermsarchive.org","algorithm_version":2,"end_time":"Sun, 13 Nov 2022 01:42:12 GMT","grade":"B","hidden":false,"likelihood_indicator":"MEDIUM","response_headers":{"Cache-Control":"s-maxage=31536000, stale-while-revalidate","Connection":"keep-alive","Content-Encoding":"gzip","Content-Security-Policy":"default-src 'self'; script-src 'self' 'unsafe-eval' https://stats.data.gouv.fr; object-src 'none'; style-src 'self' 'unsafe-inline'; connect-src 'self' https://stats.data.gouv.fr; img-src 'self' data: https://media-exp1.licdn.com https://www.gravatar.com https://avatars.githubusercontent.com https://pbs.twimg.com https://sibyll.in; frame-src 'self' https://stats.data.gouv.fr","Content-Type":"text/html; charset=utf-8","Date":"Sun, 13 Nov 2022 01:42:09 GMT","ETag":"\"j9blin6a5j1lfq\"","Strict-Transport-Security":"max-age=63072000; includeSubDomains; preload","Transfer-Encoding":"chunked","Vary":"Accept-Encoding","X-Content-Type-Options":"nosniff","X-Frame-Options":"DENY","X-Powered-By":"Next.js","X-Request-ID":"575de383-1fed-4189-b5ae-88b3653e9087","X-XSS-Protection":"1; mode=block","x-nextjs-cache":"HIT"},"scan_id":30866267,"score":70,"start_time":"Sun, 13 Nov 2022 01:40:07 GMT","state":"FINISHED","status_code":200,"tests_failed":2,"tests_passed":10,"tests_quantity":12,"details":{"content-security-policy":{"expectation":"csp-implemented-with-no-unsafe","name":"content-security-policy","output":{"data":{"connect-src":["'self'","https://stats.data.gouv.fr"],"default-src":["'self'"],"frame-src":["'self'","https://stats.data.gouv.fr"],"img-src":["https://sibyll.in","https://avatars.githubusercontent.com","https://www.gravatar.com","data:","'self'","https://media-exp1.licdn.com","https://pbs.twimg.com"],"object-src":["'none'"],"script-src":["'self'","'unsafe-eval'","https://stats.data.gouv.fr"],"style-src":["'unsafe-inline'","'self'"]},"http":true,"meta":false,"numPolicies":1,"policy":{"antiClickjacking":false,"defaultNone":false,"insecureBaseUri":true,"insecureFormAction":true,"insecureSchemeActive":false,"insecureSchemePassive":false,"strictDynamic":false,"unsafeEval":true,"unsafeInline":false,"unsafeInlineStyle":true,"unsafeObjects":false}},"pass":false,"result":"csp-implemented-with-unsafe-eval","score_description":"Content Security Policy (CSP) implemented, but allows 'unsafe-eval'","score_modifier":-10},"contribute":{"expectation":"contribute-json-only-required-on-mozilla-properties","name":"contribute","output":{"data":null},"pass":true,"result":"contribute-json-only-required-on-mozilla-properties","score_description":"Contribute.json isn't required on websites that don't belong to Mozilla","score_modifier":0},"cookies":{"expectation":"cookies-secure-with-httponly-sessions","name":"cookies","output":{"data":null,"sameSite":null},"pass":true,"result":"cookies-not-found","score_description":"No cookies detected","score_modifier":0},"cross-origin-resource-sharing":{"expectation":"cross-origin-resource-sharing-not-implemented","name":"cross-origin-resource-sharing","output":{"data":{"acao":null,"clientaccesspolicy":null,"crossdomain":null}},"pass":true,"result":"cross-origin-resource-sharing-not-implemented","score_description":"Content is not visible via cross-origin resource sharing (CORS) files or headers","score_modifier":0},"public-key-pinning":{"expectation":"hpkp-not-implemented","name":"public-key-pinning","output":{"data":null,"includeSubDomains":false,"max-age":null,"numPins":null,"preloaded":false},"pass":true,"result":"hpkp-not-implemented","score_description":"HTTP Public Key Pinning (HPKP) header not implemented","score_modifier":0},"redirection":{"expectation":"redirection-to-https","name":"redirection","output":{"destination":"http://opentermsarchive.org/","redirects":false,"route":["http://opentermsarchive.org/"],"status_code":200},"pass":false,"result":"redirection-missing","score_description":"Does not redirect to an HTTPS site","score_modifier":-20},"referrer-policy":{"expectation":"referrer-policy-private","name":"referrer-policy","output":{"data":null,"http":false,"meta":false},"pass":true,"result":"referrer-policy-not-implemented","score_description":"Referrer-Policy header not implemented","score_modifier":0},"strict-transport-security":{"expectation":"hsts-implemented-max-age-at-least-six-months","name":"strict-transport-security","output":{"data":"max-age=63072000; includeSubDomains; preload","includeSubDomains":true,"max-age":63072000,"preload":true,"preloaded":false},"pass":true,"result":"hsts-implemented-max-age-at-least-six-months","score_description":"HTTP Strict Transport Security (HSTS) header set to a minimum of six months (15768000)","score_modifier":0},"subresource-integrity":{"expectation":"sri-implemented-and-external-scripts-loaded-securely","name":"subresource-integrity","output":{"data":{}},"pass":true,"result":"sri-not-implemented-but-all-scripts-loaded-from-secure-origin","score_description":"Subresource Integrity (SRI) not implemented, but all scripts are loaded from a similar origin","score_modifier":0},"x-content-type-options":{"expectation":"x-content-type-options-nosniff","name":"x-content-type-options","output":{"data":"nosniff"},"pass":true,"result":"x-content-type-options-nosniff","score_description":"X-Content-Type-Options header set to \"nosniff\"","score_modifier":0},"x-frame-options":{"expectation":"x-frame-options-sameorigin-or-deny","name":"x-frame-options","output":{"data":"DENY"},"pass":true,"result":"x-frame-options-sameorigin-or-deny","score_description":"X-Frame-Options (XFO) header set to SAMEORIGIN or DENY","score_modifier":0},"x-xss-protection":{"expectation":"x-xss-protection-1-mode-block","name":"x-xss-protection","output":{"data":"1; mode=block"},"pass":true,"result":"x-xss-protection-enabled-mode-block","score_description":"X-XSS-Protection header set to \"1; mode=block\"","score_modifier":0}}}

Large diffs are not rendered by default.

Loading

0 comments on commit ca2edbd

Please sign in to comment.