Passive scanner rules (beta) version 31
·
6583 commits
to main
since this release
Added
- The following scan rules were added, having been promoted from Alpha:
- Content Cacheable
- In Page Banner Info Leak
- JS Function
- JSO
- Permissions Policy
- Sub Resource Integrity Attribute
Changed
- Update minimum ZAP version to 2.12.0.
- Content Cacheability scan rule now has functionality to generate example alerts for documentation purposes (Issue 7502).
Removed
- The following scan rules were removed, having been promoted to Release:
- Big Redirects
- Directory Browsing
- Hash Disclosure
- HeartBleed
- Insecure Form Load
- Insecure Form Post
- Link Target
- Modern App Detection
- PII
- Retrieved From Cache
- Server Header Info Leak
- Strict Transport Security
- User Controlled Charset
- User Controlled Cookie
- User Controlled HTML Attributes
- User Controlled Javascript Event
- User Controlled Open Redirect
- X-Backend-Server Information Leak
- X-ChromeLogger-Data Info Leak