Skip to content

Conversation

kingthorin
Copy link
Member

@kingthorin kingthorin commented Sep 25, 2025

Overview

  • Remove unnecessary try/catch when raising alert.
  • Move always used variable assignment to be a constant.
  • Ensure Evidence values are literal and not assembled.
  • Adjust Confidence when findings are based on 40x authn/authz type responses.
  • Corrected regex quantifier on third party content matching.
  • May now raise more alerts because the HTTP method/verb comparison previously may have been values with leading or trailing space which would not have matched.

@psiinon
Copy link
Member

psiinon commented Sep 25, 2025

Logo
Checkmarx One – Scan Summary & Details6862df0c-dc94-4423-97ea-eb3c3caaec65

Great job! No new security vulnerabilities introduced in this pull request


Use @Checkmarx to reach out to us for assistance.

Just send a PR comment with @Checkmarx followed by a natural language request.

Examples: @Checkmarx how are you able to help me? @Checkmarx rescan this PR

@kingthorin kingthorin force-pushed the http-methods-fixes branch 6 times, most recently from 464ca24 to f85bce4 Compare September 30, 2025 16:32
@kingthorin kingthorin marked this pull request as ready for review September 30, 2025 16:34
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Development

Successfully merging this pull request may close these issues.

2 participants