**Description of the false positive** <!-- Please explain briefly why you think it shouldn't be included. --> tez-common/src/main/java/org/apache/tez/common/web/ProfileOutputServlet.java:63 **URL to the alert on GitHub code scanning (optional)** https://github.com/OSS-Security-Assessments/apache__tez/security/code-scanning/16 False positive of Cross-Site Scripting because the content-type in the response has been set to `MimeType.TEXT`