diff --git a/audit.json b/audit.json index 8ee1c6f2..96b17d0a 100644 --- a/audit.json +++ b/audit.json @@ -2,5 +2,16 @@ "10010_Cookie No HttpOnly Flag_http://ccpay-notifications-service-aat.service.core-compute-aat.internal/v2/api-docs_GET":"ignore", "10054_Cookie without SameSite Attribute_http://ccpay-notifications-service-aat.service.core-compute-aat.internal/v2/api-docs_GET":"ignore", "100000_A Client Error response code was returned by the server_http://ccpay-notifications-service-aat.service.core-compute-aat.internal/v2/api-docs_GET":"ignore", - "90033_Loosely Scoped Cookie_http://ccpay-notifications-service-aat.service.core-compute-aat.internal/v2/api-docs_GET": "ignore" + "90033_Loosely Scoped Cookie_http://ccpay-notifications-service-aat.service.core-compute-aat.internal/v2/api-docs_GET": "ignore", + "10096_Timestamp Disclosure - Unix_http://ccpay-notifications-service-aat.service.core-compute-aat.internal/v2/api-docs_GET":"ignore", + "10010_Cookie No HttpOnly Flag_http://ccpay-notifications-service-aat.service.core-compute-aat.internal_GET":"ignore", + "10010_Cookie No HttpOnly Flag_http://ccpay-notifications-service-aat.service.core-compute-aat.internal/_GET":"ignore", + "10010_Cookie No HttpOnly Flag_http://ccpay-notifications-service-aat.service.core-compute-aat.internal/robots.txt_GET":"ignore", + "10054_Cookie without SameSite Attribute_http://ccpay-notifications-service-aat.service.core-compute-aat.internal_GET":"ignore", + "10054_Cookie without SameSite Attribute_http://ccpay-notifications-service-aat.service.core-compute-aat.internal/_GET":"ignore", + "10054_Cookie without SameSite Attribute_http://ccpay-notifications-service-aat.service.core-compute-aat.internal/robots.txt_GET":"ignore", + "10096_Timestamp Disclosure - Unix_http://ccpay-notifications-service-aat.service.core-compute-aat.internal/sitemap.xml_GET":"ignore", + "90033_Loosely Scoped Cookie_http://ccpay-notifications-service-aat.service.core-compute-aat.internal_GET":"ignore", + "90033_Loosely Scoped Cookie_http://ccpay-notifications-service-aat.service.core-compute-aat.internal/_GET":"ignore", + "90033_Loosely Scoped Cookie_http://ccpay-notifications-service-aat.service.core-compute-aat.internal/robots.txt_GET":"ignore" } diff --git a/charts/ccpay-notifications-service/Chart.yaml b/charts/ccpay-notifications-service/Chart.yaml index 950cdfae..2167e730 100644 --- a/charts/ccpay-notifications-service/Chart.yaml +++ b/charts/ccpay-notifications-service/Chart.yaml @@ -3,7 +3,7 @@ appVersion: "1.0" description: A Helm chart for notifications-service App name: ccpay-notifications-service home: https://github.com/hmcts/ccpay-notifications-service -version: 1.0.3 +version: 1.0.4 maintainers: - name: HMCTS Fees and Pay team dependencies: diff --git a/security.sh b/security.sh deleted file mode 100644 index 7be03ed9..00000000 --- a/security.sh +++ /dev/null @@ -1,13 +0,0 @@ -#!/usr/bin/env bash -echo ${TEST_URL} -zap-api-scan.py -t ${TEST_URL}/v2/api-docs -f openapi -S -d -u ${SecurityRules} -P 1001 -l FAIL -cat zap.out -echo "ZAP has successfully started" -export LC_ALL=C.UTF-8 -export LANG=C.UTF-8 -curl --fail http://0.0.0.0:1001/OTHER/core/other/jsonreport/?formMethod=GET --output report.json -zap-cli --zap-url http://0.0.0.0 -p 1001 report -o /zap/api-report.html -f html -zap-cli --zap-url http://0.0.0.0 -p 1001 alerts -l High --exit-code False -mkdir -p functional-output -chmod a+wx functional-output -cp /zap/api-report.html functional-output/