Skip to content

Remove Swagger Secret & Version Detector active scan rule#505

Merged
thc202 merged 1 commit intomainfrom
revert-487-add-swagger-secret-detector
Jan 21, 2026
Merged

Remove Swagger Secret & Version Detector active scan rule#505
thc202 merged 1 commit intomainfrom
revert-487-add-swagger-secret-detector

Conversation

@ricekot
Copy link
Member

@ricekot ricekot commented Jan 21, 2026

Reverts #487, now that the script was added to the openapi add-on in zaproxy/zap-extensions#6853.

Copilot AI review requested due to automatic review settings January 21, 2026 03:58
Signed-off-by: ricekot <git@ricekot.com>
@ricekot ricekot force-pushed the revert-487-add-swagger-secret-detector branch from e4428f9 to a0395e1 Compare January 21, 2026 03:59
Copy link

Copilot AI left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

This PR removes the SwaggerSecretDetector.js active scan rule script that was previously added in PR #487. The script has been migrated to the openapi add-on (zaproxy/zap-extensions#6853), making this community script redundant.

Changes:

  • Complete removal of the SwaggerSecretDetector.js file from the active scripts directory
  • Removal of the corresponding changelog entry from the Unreleased "Added" section

Reviewed changes

Copilot reviewed 2 out of 2 changed files in this pull request and generated no comments.

File Description
active/SwaggerSecretDetector.js Complete deletion of the 353-line active scan rule script
CHANGELOG.md Removed the entry for SwaggerSecretDetector.js from the Unreleased Added section

💡 Add Copilot custom instructions for smarter, more guided reviews. Learn how to get started.

@psiinon
Copy link
Member

psiinon commented Jan 21, 2026

Logo
Checkmarx One – Scan Summary & Details34b31abd-5de1-4703-9ba1-b38da3c62348

New Issues (5)

Checkmarx found the following issues in this Pull Request

# Severity Issue Source File / Package Checkmarx Insight
1 HIGH Last User Is 'root' /docker-wrapper: 10
detailsLeaving the last user as root can cause security risks. Change to another user after running the commands that need privileges
2 LOW MAINTAINER Instruction Being Used /docker-wrapper: 3
detailsThe MAINTAINER instruction sets the Author field of the generated images. The LABEL instruction is a much more flexible version of this and you sh...
3 LOW Unpinned Actions Full Length Commit SHA /codeql.yml: 31
detailsPinning an action to a full length commit SHA is currently the only way to use an action as an immutable release. Pinning to a particular SHA help...
4 LOW Unpinned Actions Full Length Commit SHA /codeql.yml: 34
detailsPinning an action to a full length commit SHA is currently the only way to use an action as an immutable release. Pinning to a particular SHA help...
5 LOW Unpinned Actions Full Length Commit SHA /codeql.yml: 35
detailsPinning an action to a full length commit SHA is currently the only way to use an action as an immutable release. Pinning to a particular SHA help...
Fixed Issues (1)

Great job! The following issues were fixed in this Pull Request

Severity Issue Source File / Package
HIGH CVE-2026-21441 Python-urllib3-2.6.2

Use @Checkmarx to interact with Checkmarx PR Assistant.
Examples:
@Checkmarx how are you able to help me?
@Checkmarx rescan this PR

@thc202 thc202 merged commit 86cb067 into main Jan 21, 2026
9 checks passed
@thc202
Copy link
Member

thc202 commented Jan 21, 2026

Thank you!

@ricekot ricekot deleted the revert-487-add-swagger-secret-detector branch January 21, 2026 08:55
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Development

Successfully merging this pull request may close these issues.

4 participants