Skip to content

Update localized resources - #521

Merged
kingthorin merged 1 commit into
zaproxy:mainfrom
zapbot:crowdin-update
Aug 17, 2026
Merged

Update localized resources#521
kingthorin merged 1 commit into
zaproxy:mainfrom
zapbot:crowdin-update

Conversation

@zapbot

@zapbot zapbot commented Aug 17, 2026

Copy link
Copy Markdown
Contributor

Update resources from Crowdin.

Update resources from Crowdin.

Signed-off-by: zapbot <12745184+zapbot@users.noreply.github.com>
@psiinon

psiinon commented Aug 17, 2026

Copy link
Copy Markdown
Member

Logo
Checkmarx One – Scan Summary & Detailsdf79296c-ddb3-4684-8adc-2d7f22597eb4


New Issues (11)

High: 2 · Medium: 3 · Low: 6

Checkmarx found the following issues in this Pull Request

# Severity Issue Source File / Package Checkmarx Insight
1 HIGH Cx2c9af752-2171 Maven-com.fasterxml.jackson.core:jackson-core-2.17.0
detailsRecommended version: 2.18.8
Description: The fix released in jackson-core `2.18.6` and `2.21.1` for [GHSA-72hv-8253-57qq] (Number Length Constraint Bypass in Async Parser, published 2026-0...
Attack Vector: NETWORK
Attack Complexity: LOW
Vulnerable Package
2 HIGH Last User Is 'root' /docker-wrapper: 10
detailsLeaving the last user as root can cause security risks. Change to another user after running the commands that need privileges
3 MEDIUM Hardcoded_Password_in_Connection_String other/api/sdlc-integration/core/scan_module/scan.py: 219
detailsThe application contains hardcoded connection details, "PASS: ", at line 219 of /other/api/sdlc-integration/core/scan_module/scan.py. This conn...
Attack Vector
4 MEDIUM Unchecked_Input_for_Loop_Condition standalone/load_context_from_burp.py: 29
detailsMethod at line 29 of /standalone/load_context_from_burp.py obtains user input from load - the range of this value is not validated, and is ev...
Attack Vector
5 MEDIUM Use_of_Broken_or_Risky_Cryptographic_Algorithm payloadgenerator/associated_fields.py: 34
detailsIn , the application protects sensitive data using a cryptographic algorithm, hexdigest, that is considered weak or even trivially broken, in /payl...
Attack Vector
6 LOW Filtering_Sensitive_Logs other/api/sdlc-integration/core/scan_module/scan.py: 218
detailsThe application logs various user events, and in method  writes sensitive user details to debug, in /other/api/sdlc-integration/core/scan_module/...
Attack Vector
7 LOW Filtering_Sensitive_Logs other/api/sdlc-integration/core/scan_module/scan.py: 243
detailsThe application logs various user events, and in method  writes sensitive user details to debug, in /other/api/sdlc-integration/core/scan_module/...
Attack Vector
8 LOW MAINTAINER Instruction Being Used /docker-wrapper: 3
detailsThe MAINTAINER instruction sets the Author field of the generated images. The LABEL instruction is a much more flexible version of this and you sh...
9 LOW Unpinned Actions Full Length Commit SHA /codeql.yml: 31
detailsPinning an action to a full length commit SHA is currently the only way to use an action as an immutable release. Pinning to a particular SHA help...
10 LOW Unpinned Actions Full Length Commit SHA /codeql.yml: 34
detailsPinning an action to a full length commit SHA is currently the only way to use an action as an immutable release. Pinning to a particular SHA help...
11 LOW Unpinned Actions Full Length Commit SHA /codeql.yml: 35
detailsPinning an action to a full length commit SHA is currently the only way to use an action as an immutable release. Pinning to a particular SHA help...

Use @Checkmarx to interact with Checkmarx PR Assistant.
Examples:
@Checkmarx how are you able to help me?
@Checkmarx rescan this PR

@kingthorin
kingthorin merged commit f9cb362 into zaproxy:main Aug 17, 2026
9 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Development

Successfully merging this pull request may close these issues.

4 participants