-
Notifications
You must be signed in to change notification settings - Fork 349
ruby3.2-faraday/2.9.1 package update #21387
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Conversation
octo-sts
bot
commented
Jun 5, 2024
Signed-off-by: wolfi-bot <121097084+wolfi-bot@users.noreply.github.com>
Package ruby3.2-faraday: Click to expand/collapsePackage ruby3.2-faraday:
Added: /usr/lib/ruby/gems/3.2.0/gems/faraday-2.9.1/CHANGELOG.md bincapz found differences: Click to expand/collapsetime=2024-06-05T16:22:23.469Z level=ERROR msg=error namespace=evasion/hidden-functions.yara id=php_hidden_eval "disabled due to unexpected warning"="string "$func" may slow down scanning" Deleted: ruby3.2-faraday/usr/lib/ruby/gems/3.2.0/gems/faraday-2.9.0/spec/faraday/request/url_encoded_spec.rb [
|
RISK | KEY | DESCRIPTION | EVIDENCE |
---|---|---|---|
-MEDIUM | net/url/encode | encodes URL, likely to pass GET variables | urlencode |
Deleted: ruby3.2-faraday/usr/lib/ruby/gems/3.2.0/gems/faraday-2.9.0/spec/faraday/response/logger_spec.rb [✅ LOW]
RISK | KEY | DESCRIPTION | EVIDENCE |
---|---|---|---|
-LOW | ref/words/password | references a 'password' | password |
Deleted: ruby3.2-faraday/usr/lib/ruby/gems/3.2.0/gems/faraday-2.9.0/lib/faraday/rack_builder.rb [✅ LOW]
RISK | KEY | DESCRIPTION | EVIDENCE |
---|---|---|---|
-LOW | ref/site/url | contains embedded HTTPS URLs | https://lostisland.github.io/faraday/usage/. |
-LOW | ref/words/password | references a 'password' | - Proxy server password |
Deleted: ruby3.2-faraday/usr/lib/ruby/gems/3.2.0/gems/faraday-2.9.0/lib/faraday/response.rb [⚠️ MEDIUM]
RISK | KEY | DESCRIPTION | EVIDENCE |
---|---|---|---|
-MEDIUM | ref/words/exclamation | gets very excited | !! |
Deleted: ruby3.2-faraday/usr/lib/ruby/gems/3.2.0/gems/faraday-2.9.0/spec/faraday/adapter/test_spec.rb [⚠️ MEDIUM]
RISK | KEY | DESCRIPTION | EVIDENCE |
---|---|---|---|
-MEDIUM | ref/words/agent | references an 'agent' | with_user_agent |
-LOW | encoding/json/decode | Decodes JSON messages | JSON.parse |
-LOW | net/http/request | makes HTTP requests | User-Agent |
-LOW | ref/site/url | contains embedded HTTP URLs | http://domain.test/bait http://domain.test/hello http://foo.com/foo?a=1 http://wrong.test/bait http://wrong.test/hello |
Deleted: ruby3.2-faraday/usr/lib/ruby/gems/3.2.0/gems/faraday-2.9.0/spec/faraday/options/proxy_options_spec.rb [✅ LOW]
RISK | KEY | DESCRIPTION | EVIDENCE |
---|---|---|---|
-LOW | ref/site/url | contains embedded HTTP URLs | http://example.org |
-LOW | ref/words/password | references a 'password' | password |
Deleted: ruby3.2-faraday/usr/lib/ruby/gems/3.2.0/gems/faraday-2.9.0/lib/faraday/adapter/test.rb [⚠️ MEDIUM]
RISK | KEY | DESCRIPTION | EVIDENCE |
---|---|---|---|
-MEDIUM | ref/words/agent | references an 'agent' | with_user_agent |
-MEDIUM | ref/words/exclamation | gets very excited | !! |
-LOW | encoding/json/decode | Decodes JSON messages | JSON.parse |
-LOW | net/http/request | makes HTTP requests | User-Agent |
-LOW | ref/site/url | contains embedded HTTPS URLs | lostisland/faraday#1444 |
Deleted: ruby3.2-faraday/usr/lib/ruby/gems/3.2.0/gems/faraday-2.9.0/spec/faraday/request_spec.rb [✅ LOW]
RISK | KEY | DESCRIPTION | EVIDENCE |
---|---|---|---|
-LOW | ref/site/url | contains embedded HTTP URLs | http://httpbingo.org/api/foo.json?a=1 http://proxy.com |
Deleted: ruby3.2-faraday/usr/lib/ruby/gems/3.2.0/gems/faraday-2.9.0/examples/client_spec.rb [✅ LOW]
RISK | KEY | DESCRIPTION | EVIDENCE |
---|---|---|---|
-LOW | encoding/json/decode | Decodes JSON messages | JSON.parse |
Deleted: ruby3.2-faraday/usr/lib/ruby/gems/3.2.0/gems/faraday-2.9.0/lib/faraday/utils/headers.rb [⚠️ MEDIUM]
RISK | KEY | DESCRIPTION | EVIDENCE |
---|---|---|---|
-MEDIUM | ref/words/agent | references an 'agent' | user_agent |
-LOW | net/http/request | makes HTTP requests | User-Agent |
Deleted: ruby3.2-faraday/usr/lib/ruby/gems/3.2.0/gems/faraday-2.9.0/spec/support/shared_examples/request_method.rb [⚠️ MEDIUM]
RISK | KEY | DESCRIPTION | EVIDENCE |
---|---|---|---|
-MEDIUM | ref/words/agent | references an 'agent' | user_agent |
-LOW | compression/gzip | works with gzip files | gzip |
-LOW | net/http/accept/encoding | set HTTP response encoding format (example: gzip) | Accept-Encoding |
-LOW | net/http/request | makes HTTP requests | User-Agent |
-LOW | net/socket/send | send a message to a socket | send socket |
-LOW | ref/site/url | contains embedded HTTPS URLs | lostisland/faraday#718 |
Deleted: ruby3.2-faraday/usr/lib/ruby/gems/3.2.0/gems/faraday-2.9.0/lib/faraday/request.rb [✅ LOW]
RISK | KEY | DESCRIPTION | EVIDENCE |
---|---|---|---|
-LOW | ref/site/url | contains embedded HTTP URLs | http://localhost?a=1 |
Deleted: ruby3.2-faraday/usr/lib/ruby/gems/3.2.0/gems/faraday-2.9.0/lib/faraday/request/authorization.rb [✅ LOW]
RISK | KEY | DESCRIPTION | EVIDENCE |
---|---|---|---|
-LOW | ref/words/password | references a 'password' | be a login and password pair |
Deleted: ruby3.2-faraday/usr/lib/ruby/gems/3.2.0/gems/faraday-2.9.0/lib/faraday/options/env.rb [⚠️ MEDIUM]
RISK | KEY | DESCRIPTION | EVIDENCE |
---|---|---|---|
-MEDIUM | ref/words/exclamation | gets very excited | !! |
-LOW | ref/words/password | references a 'password' | - Proxy server password |
Deleted: ruby3.2-faraday/usr/lib/ruby/gems/3.2.0/gems/faraday-2.9.0/spec/faraday/connection_spec.rb [⚠️ MEDIUM]
RISK | KEY | DESCRIPTION | EVIDENCE |
---|---|---|---|
-MEDIUM | ref/words/agent | references an 'agent' | user_agent |
-LOW | net/http/request | makes HTTP requests | User-Agent |
-LOW | net/http_proxy | discover proxy address via environment | HTTP_PROXY |
-LOW | ref/site/url | contains embedded HTTPS URLs | https://ahttpbingo.org/sake.html https://google.co.uk https://httpbingo.org/foo https://httpbingo.org/get/sake.html https://proxy.com |
-LOW | ref/words/password | references a 'password' | password |
Deleted: ruby3.2-faraday/usr/lib/ruby/gems/3.2.0/gems/faraday-2.9.0/spec/faraday/utils/headers_spec.rb [✅ LOW]
RISK | KEY | DESCRIPTION | EVIDENCE |
---|---|---|---|
-LOW | net/http/request | makes HTTP requests | HTTP/1. |
-LOW | ref/site/url | contains embedded HTTP URLs | http://httpbingo.org/ |
Deleted: ruby3.2-faraday/usr/lib/ruby/gems/3.2.0/gems/faraday-2.9.0/examples/client_test.rb [✅ LOW]
RISK | KEY | DESCRIPTION | EVIDENCE |
---|---|---|---|
-LOW | encoding/json/decode | Decodes JSON messages | JSON.parse |
Deleted: ruby3.2-faraday/usr/lib/ruby/gems/3.2.0/gems/faraday-2.9.0/lib/faraday/options/proxy_options.rb [✅ LOW]
RISK | KEY | DESCRIPTION | EVIDENCE |
---|---|---|---|
-LOW | ref/words/password | references a 'password' | password |
Deleted: ruby3.2-faraday/usr/lib/ruby/gems/3.2.0/gems/faraday-2.9.0/spec/faraday/response/json_spec.rb [✅ LOW]
RISK | KEY | DESCRIPTION | EVIDENCE |
---|---|---|---|
-LOW | encoding/json/decode | Decodes JSON messages | JSON.parse |
Deleted: ruby3.2-faraday/usr/lib/ruby/gems/3.2.0/gems/faraday-2.9.0/lib/faraday/request/url_encoded.rb [⚠️ MEDIUM]
RISK | KEY | DESCRIPTION | EVIDENCE |
---|---|---|---|
-MEDIUM | net/url/encode | encodes URL, likely to pass GET variables | urlencode |
Deleted: ruby3.2-faraday/usr/lib/ruby/gems/3.2.0/gems/faraday-2.9.0/spec/faraday/response_spec.rb [✅ LOW]
RISK | KEY | DESCRIPTION | EVIDENCE |
---|---|---|---|
-LOW | ref/site/url | contains embedded HTTPS URLs | https://lostisland.github.io/faraday |
Deleted: ruby3.2-faraday/usr/lib/ruby/gems/3.2.0/gems/faraday-2.9.0/lib/faraday/options/ssl_options.rb [⚠️ MEDIUM]
RISK | KEY | DESCRIPTION | EVIDENCE |
---|---|---|---|
-MEDIUM | builtin/openssl | This binary includes OpenSSL source code | OpenSSL/ |
-LOW | ref/site/url | contains embedded HTTPS URLs | ruby/openssl#60 https://ruby-doc.org/stdlib-2.5.1/libdoc/openssl/rdoc/OpenSSL/SSL.html https://ruby-doc.org/stdlib-2.5.1/libdoc/openssl/rdoc/OpenSSL/SSL/SSLCont |
-LOW | secrets/private_key | References private keys | private_key |
Deleted: ruby3.2-faraday/usr/lib/ruby/gems/3.2.0/gems/faraday-2.9.0/spec/faraday/utils_spec.rb [⚠️ MEDIUM]
RISK | KEY | DESCRIPTION | EVIDENCE |
---|---|---|---|
-MEDIUM | ref/words/agent | references an 'agent' | user_agent |
-LOW | net/http/request | makes HTTP requests | HTTP/1. |
-LOW | ref/site/url | contains embedded HTTP URLs | http://example.com/abc |
-LOW | secrets/private_key | References private keys | private_key |
Deleted: ruby3.2-faraday/usr/lib/ruby/gems/3.2.0/gems/faraday-2.9.0/lib/faraday.rb [✅ LOW]
RISK | KEY | DESCRIPTION | EVIDENCE |
---|---|---|---|
-LOW | ref/site/url | contains embedded HTTPS URLs | https://faraday.com |
Deleted: ruby3.2-faraday/usr/lib/ruby/gems/3.2.0/gems/faraday-2.9.0/lib/faraday/connection.rb [⚠️ MEDIUM]
RISK | KEY | DESCRIPTION | EVIDENCE |
---|---|---|---|
-MEDIUM | net/http/post | submit content to websites | HTTP POST http |
-MEDIUM | ref/words/agent | references an 'agent' | user_agent |
-MEDIUM | ref/words/exclamation | gets very excited | !! |
-LOW | ref/site/url | contains embedded HTTPS URLs | https://api.github.com/gists/GIST_ID/star https://httpbingo.org/api/nigiri?token=abc https://httpbingo.org/api?token=abc |
-LOW | ref/words/password | references a 'password' | any password from URI username and password yieldparam password |
Deleted: ruby3.2-faraday/usr/lib/ruby/gems/3.2.0/gems/faraday-2.9.0/spec/spec_helper.rb [⚠️ MEDIUM]
RISK | KEY | DESCRIPTION | EVIDENCE |
---|---|---|---|
-MEDIUM | ref/path/relative | references and possibly executes relative path | ./lib ./spec |
-LOW | random/insecure | generate random numbers insecurely | srand |
-LOW | ref/site/url | contains embedded HTTP URLs | http://rspec.info/blog/2012/06/rspecs-new-expectation-syntax/ http://rspec.info/blog/2014/05/notable-changes-in-rspec-3/ http://rubydoc.info/gems/rspec-core/RSpec/Core/Configuration http://www.teaisaweso.me/blog/2013/05/27/rspecs-new-message-expectation- |
Added: ruby3.2-faraday/usr/lib/ruby/gems/3.2.0/gems/faraday-2.9.1/lib/faraday/request/authorization.rb [✅ LOW]
RISK | KEY | DESCRIPTION | EVIDENCE |
---|---|---|---|
+LOW | ref/words/password | references a 'password' | be a login and password pair |
Added: ruby3.2-faraday/usr/lib/ruby/gems/3.2.0/gems/faraday-2.9.1/spec/faraday/request/url_encoded_spec.rb [⚠️ MEDIUM]
RISK | KEY | DESCRIPTION | EVIDENCE |
---|---|---|---|
+MEDIUM | net/url/encode | encodes URL, likely to pass GET variables | urlencode |
Added: ruby3.2-faraday/usr/lib/ruby/gems/3.2.0/gems/faraday-2.9.1/lib/faraday/request/url_encoded.rb [⚠️ MEDIUM]
RISK | KEY | DESCRIPTION | EVIDENCE |
---|---|---|---|
+MEDIUM | net/url/encode | encodes URL, likely to pass GET variables | urlencode |
Added: ruby3.2-faraday/usr/lib/ruby/gems/3.2.0/gems/faraday-2.9.1/spec/faraday/adapter/test_spec.rb [⚠️ MEDIUM]
RISK | KEY | DESCRIPTION | EVIDENCE |
---|---|---|---|
+MEDIUM | ref/words/agent | references an 'agent' | with_user_agent |
+LOW | encoding/json/decode | Decodes JSON messages | JSON.parse |
+LOW | net/http/request | makes HTTP requests | User-Agent |
+LOW | ref/site/url | contains embedded HTTP URLs | http://domain.test/bait http://domain.test/hello http://foo.com/foo?a=1 http://wrong.test/bait http://wrong.test/hello |
Added: ruby3.2-faraday/usr/lib/ruby/gems/3.2.0/gems/faraday-2.9.1/spec/faraday/response/json_spec.rb [✅ LOW]
RISK | KEY | DESCRIPTION | EVIDENCE |
---|---|---|---|
+LOW | encoding/json/decode | Decodes JSON messages | JSON.parse |
Added: ruby3.2-faraday/usr/lib/ruby/gems/3.2.0/gems/faraday-2.9.1/lib/faraday/rack_builder.rb [✅ LOW]
RISK | KEY | DESCRIPTION | EVIDENCE |
---|---|---|---|
+LOW | ref/site/url | contains embedded HTTPS URLs | https://lostisland.github.io/faraday/usage/. |
+LOW | ref/words/password | references a 'password' | - Proxy server password |
Added: ruby3.2-faraday/usr/lib/ruby/gems/3.2.0/gems/faraday-2.9.1/spec/spec_helper.rb [⚠️ MEDIUM]
RISK | KEY | DESCRIPTION | EVIDENCE |
---|---|---|---|
+MEDIUM | ref/path/relative | references and possibly executes relative path | ./lib ./spec |
+LOW | random/insecure | generate random numbers insecurely | srand |
+LOW | ref/site/url | contains embedded HTTP URLs | http://rspec.info/blog/2012/06/rspecs-new-expectation-syntax/ http://rspec.info/blog/2014/05/notable-changes-in-rspec-3/ http://rubydoc.info/gems/rspec-core/RSpec/Core/Configuration http://www.teaisaweso.me/blog/2013/05/27/rspecs-new-message-expectation- |
Added: ruby3.2-faraday/usr/lib/ruby/gems/3.2.0/gems/faraday-2.9.1/examples/client_test.rb [✅ LOW]
RISK | KEY | DESCRIPTION | EVIDENCE |
---|---|---|---|
+LOW | encoding/json/decode | Decodes JSON messages | JSON.parse |
Added: ruby3.2-faraday/usr/lib/ruby/gems/3.2.0/gems/faraday-2.9.1/spec/faraday/utils_spec.rb [⚠️ MEDIUM]
RISK | KEY | DESCRIPTION | EVIDENCE |
---|---|---|---|
+MEDIUM | ref/words/agent | references an 'agent' | user_agent |
+LOW | net/http/request | makes HTTP requests | HTTP/1. |
+LOW | ref/site/url | contains embedded HTTP URLs | http://example.com/abc |
+LOW | secrets/private_key | References private keys | private_key |
Added: ruby3.2-faraday/usr/lib/ruby/gems/3.2.0/gems/faraday-2.9.1/lib/faraday/options/env.rb [⚠️ MEDIUM]
RISK | KEY | DESCRIPTION | EVIDENCE |
---|---|---|---|
+MEDIUM | ref/words/exclamation | gets very excited | !! |
+LOW | ref/words/password | references a 'password' | - Proxy server password |
Added: ruby3.2-faraday/usr/lib/ruby/gems/3.2.0/gems/faraday-2.9.1/spec/faraday/utils/headers_spec.rb [✅ LOW]
RISK | KEY | DESCRIPTION | EVIDENCE |
---|---|---|---|
+LOW | net/http/request | makes HTTP requests | HTTP/1. |
+LOW | ref/site/url | contains embedded HTTP URLs | http://httpbingo.org/ |
Added: ruby3.2-faraday/usr/lib/ruby/gems/3.2.0/gems/faraday-2.9.1/spec/faraday/options/proxy_options_spec.rb [✅ LOW]
RISK | KEY | DESCRIPTION | EVIDENCE |
---|---|---|---|
+LOW | ref/site/url | contains embedded HTTP URLs | http://example.org |
+LOW | ref/words/password | references a 'password' | password |
Added: ruby3.2-faraday/usr/lib/ruby/gems/3.2.0/gems/faraday-2.9.1/lib/faraday/connection.rb [⚠️ MEDIUM]
RISK | KEY | DESCRIPTION | EVIDENCE |
---|---|---|---|
+MEDIUM | net/http/post | submit content to websites | HTTP POST http |
+MEDIUM | ref/words/agent | references an 'agent' | user_agent |
+MEDIUM | ref/words/exclamation | gets very excited | !! |
+LOW | ref/site/url | contains embedded HTTPS URLs | https://api.github.com/gists/GIST_ID/star https://httpbingo.org/api/nigiri?token=abc https://httpbingo.org/api?token=abc |
+LOW | ref/words/password | references a 'password' | any password from URI username and password yieldparam password |
Added: ruby3.2-faraday/usr/lib/ruby/gems/3.2.0/gems/faraday-2.9.1/examples/client_spec.rb [✅ LOW]
RISK | KEY | DESCRIPTION | EVIDENCE |
---|---|---|---|
+LOW | encoding/json/decode | Decodes JSON messages | JSON.parse |
Added: ruby3.2-faraday/usr/lib/ruby/gems/3.2.0/gems/faraday-2.9.1/lib/faraday.rb [✅ LOW]
RISK | KEY | DESCRIPTION | EVIDENCE |
---|---|---|---|
+LOW | ref/site/url | contains embedded HTTPS URLs | https://faraday.com |
Added: ruby3.2-faraday/usr/lib/ruby/gems/3.2.0/gems/faraday-2.9.1/spec/faraday/response_spec.rb [✅ LOW]
RISK | KEY | DESCRIPTION | EVIDENCE |
---|---|---|---|
+LOW | ref/site/url | contains embedded HTTPS URLs | https://lostisland.github.io/faraday |
Added: ruby3.2-faraday/usr/lib/ruby/gems/3.2.0/gems/faraday-2.9.1/spec/faraday/request_spec.rb [✅ LOW]
RISK | KEY | DESCRIPTION | EVIDENCE |
---|---|---|---|
+LOW | ref/site/url | contains embedded HTTP URLs | http://httpbingo.org/api/foo.json?a=1 http://proxy.com |
Added: ruby3.2-faraday/usr/lib/ruby/gems/3.2.0/gems/faraday-2.9.1/spec/faraday/response/logger_spec.rb [✅ LOW]
RISK | KEY | DESCRIPTION | EVIDENCE |
---|---|---|---|
+LOW | ref/words/password | references a 'password' | password |
Added: ruby3.2-faraday/usr/lib/ruby/gems/3.2.0/gems/faraday-2.9.1/lib/faraday/utils/headers.rb [⚠️ MEDIUM]
RISK | KEY | DESCRIPTION | EVIDENCE |
---|---|---|---|
+MEDIUM | ref/words/agent | references an 'agent' | user_agent |
+LOW | net/http/request | makes HTTP requests | User-Agent |
Added: ruby3.2-faraday/usr/lib/ruby/gems/3.2.0/gems/faraday-2.9.1/lib/faraday/options/proxy_options.rb [✅ LOW]
RISK | KEY | DESCRIPTION | EVIDENCE |
---|---|---|---|
+LOW | ref/words/password | references a 'password' | password |
Added: ruby3.2-faraday/usr/lib/ruby/gems/3.2.0/gems/faraday-2.9.1/lib/faraday/response.rb [⚠️ MEDIUM]
RISK | KEY | DESCRIPTION | EVIDENCE |
---|---|---|---|
+MEDIUM | ref/words/exclamation | gets very excited | !! |
Added: ruby3.2-faraday/usr/lib/ruby/gems/3.2.0/gems/faraday-2.9.1/lib/faraday/request.rb [✅ LOW]
RISK | KEY | DESCRIPTION | EVIDENCE |
---|---|---|---|
+LOW | ref/site/url | contains embedded HTTP URLs | http://localhost?a=1 |
Added: ruby3.2-faraday/usr/lib/ruby/gems/3.2.0/gems/faraday-2.9.1/spec/support/shared_examples/request_method.rb [⚠️ MEDIUM]
RISK | KEY | DESCRIPTION | EVIDENCE |
---|---|---|---|
+MEDIUM | ref/words/agent | references an 'agent' | user_agent |
+LOW | compression/gzip | works with gzip files | gzip |
+LOW | net/http/accept/encoding | set HTTP response encoding format (example: gzip) | Accept-Encoding |
+LOW | net/http/request | makes HTTP requests | User-Agent |
+LOW | net/socket/send | send a message to a socket | send socket |
+LOW | ref/site/url | contains embedded HTTPS URLs | lostisland/faraday#718 |
Added: ruby3.2-faraday/usr/lib/ruby/gems/3.2.0/gems/faraday-2.9.1/lib/faraday/options/ssl_options.rb [⚠️ MEDIUM]
RISK | KEY | DESCRIPTION | EVIDENCE |
---|---|---|---|
+MEDIUM | builtin/openssl | This binary includes OpenSSL source code | OpenSSL/ |
+LOW | ref/site/url | contains embedded HTTPS URLs | ruby/openssl#60 https://ruby-doc.org/stdlib-2.5.1/libdoc/openssl/rdoc/OpenSSL/SSL.html https://ruby-doc.org/stdlib-2.5.1/libdoc/openssl/rdoc/OpenSSL/SSL/SSLCont |
+LOW | secrets/private_key | References private keys | private_key |
Added: ruby3.2-faraday/usr/lib/ruby/gems/3.2.0/gems/faraday-2.9.1/spec/faraday/connection_spec.rb [⚠️ MEDIUM]
RISK | KEY | DESCRIPTION | EVIDENCE |
---|---|---|---|
+MEDIUM | ref/words/agent | references an 'agent' | user_agent |
+LOW | net/http/request | makes HTTP requests | User-Agent |
+LOW | net/http_proxy | discover proxy address via environment | HTTP_PROXY |
+LOW | ref/site/url | contains embedded HTTPS URLs | https://ahttpbingo.org/sake.html https://google.co.uk https://httpbingo.org/foo https://httpbingo.org/get/sake.html https://proxy.com |
+LOW | ref/words/password | references a 'password' | password |
Added: ruby3.2-faraday/usr/lib/ruby/gems/3.2.0/gems/faraday-2.9.1/lib/faraday/adapter/test.rb [⚠️ MEDIUM]
RISK | KEY | DESCRIPTION | EVIDENCE |
---|---|---|---|
+MEDIUM | ref/words/agent | references an 'agent' | with_user_agent |
+MEDIUM | ref/words/exclamation | gets very excited | !! |
+LOW | encoding/json/decode | Decodes JSON messages | JSON.parse |
+LOW | net/http/request | makes HTTP requests | User-Agent |
+LOW | ref/site/url | contains embedded HTTPS URLs | lostisland/faraday#1444 |