Skip to content

Conversation

kingthorin
Copy link
Member

@kingthorin kingthorin commented Oct 7, 2025

Overview

The PII Disclosure scan rule now only evaluates visible text and script blocks at Medium or High alert threshold, while the entire response body is considered at Low alert threshold.

This is intended to reduce false positives related to values present in non-visible HTML elements such as attributes, etc.

@kingthorin kingthorin requested a review from Copilot October 7, 2025 17:31
Copilot

This comment was marked as outdated.

@psiinon
Copy link
Member

psiinon commented Oct 7, 2025

Logo
Checkmarx One – Scan Summary & Detailsffa7ec3b-f3cd-4e38-8301-845f991eb911

Great job! No new security vulnerabilities introduced in this pull request


Use @Checkmarx to reach out to us for assistance.

Just send a PR comment with @Checkmarx followed by a natural language request.

Examples: @Checkmarx how are you able to help me? @Checkmarx rescan this PR

@kingthorin kingthorin force-pushed the pii-fps branch 3 times, most recently from 0aa3ba3 to cfbf4aa Compare October 7, 2025 20:28
@kingthorin
Copy link
Member Author

Note the diff probably seems like a lot of change but part of that is because an extra loop was introduced which changed indentation on a bunch of lines, and another block of code was moved earlier in the file.

@kingthorin kingthorin force-pushed the pii-fps branch 4 times, most recently from e8b6f05 to 2e6ee57 Compare October 15, 2025 21:09
@kingthorin
Copy link
Member Author

Got all those (I think) and the conflict.

@thc202
Copy link
Member

thc202 commented Oct 16, 2025

Thank you!

@psiinon psiinon merged commit 3735f02 into zaproxy:main Oct 16, 2025
10 checks passed
@github-actions github-actions bot locked and limited conversation to collaborators Oct 16, 2025
@kingthorin kingthorin deleted the pii-fps branch October 16, 2025 15:25
Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.

Labels

None yet

Development

Successfully merging this pull request may close these issues.

3 participants