|
X-Frame-Options false negative |
Closed (fixed) |
Normal |
Bug report |
3.1.3 |
Code |
|
5 months 1 week |
|
False positives header tests due to case sensitivity |
Closed (fixed) |
Major |
Bug report |
3.1.x-dev |
Code |
|
3 months 4 weeks |
|
Make warnings or errors pop on Details page |
Closed (fixed) |
Normal |
Feature request |
3.1.x-dev |
User interface |
|
5 months 2 weeks |
|
Add account creation check |
Closed (fixed) |
Normal |
Feature request |
3.1.x-dev |
Code |
smustgrave |
5 months 2 weeks |
|
Check for CSP on private and public SVG files |
Needs work |
Normal |
Feature request |
3.1.x-dev |
Code |
|
1 year 4 months |
|
Place most critical checks at the top |
Closed (won't fix) |
Normal |
Feature request |
3.1.x-dev |
User interface |
|
3 months 4 weeks |
|
MissingMandatoryParametersException when viewing upload extensions help page |
Closed (fixed) |
Normal |
Bug report |
3.1.x-dev |
Code |
|
5 months 3 weeks |
|
Checking test details before running test throws an exception |
Closed (fixed) |
Normal |
Bug report |
3.1.x-dev |
Code |
smustgrave |
5 months 1 week |
|
Convert to Attributes |
Closed (fixed) |
Normal |
Task |
3.1.x-dev |
Code |
|
4 months 2 weeks |
|
SecRev can not be run with Drush on sites with non-english default language |
Closed (fixed) |
Major |
Bug report |
3.1.x-dev |
Code |
|
5 months 2 weeks |
|
Add test coverage for VendorDirectory and UploadExtensions |
Closed (fixed) |
Normal |
Task |
3.1.x-dev |
Code |
|
5 months 2 weeks |
|
Add better test coverage per check |
Closed (fixed) |
Normal |
Plan |
3.1.x-dev |
Code |
|
1 year 5 months |
|
Add test coverage for FilePermissions |
Closed (fixed) |
Normal |
Task |
3.1.x-dev |
Code |
smustgrave |
5 months 2 weeks |
|
Add test coverage for Headers, InputFormats, and LastCronRun |
Closed (fixed) |
Normal |
Task |
3.1.x-dev |
Code |
mdranove |
5 months 2 weeks |
|
Whitelist views/displays in View access check |
Closed (fixed) |
Normal |
Feature request |
3.1.x-dev |
Code |
smustgrave |
4 years 11 months |
|
Some Details links give Page not found |
Closed (duplicate) |
Normal |
Bug report |
3.1.x-dev |
Code |
|
4 months 3 days |
|
There should be a new test for ownership of files and directories |
Active |
Normal |
Feature request |
3.0.x-dev |
Code |
c-logemann |
10 years 7 months |
|
Checks using sub requests with guzzle get wrong results on 403 situations |
Needs work |
Normal |
Bug report |
3.1.x-dev |
Code |
|
1 year 10 months |
|
CLI/Drush cannot do file checks directly |
Active |
Normal |
Bug report |
3.1.x-dev |
Code |
|
1 year 10 months |
|
DB Log error - ArgumentCountError: Too few arguments to function Drupal\security_review\SecurityReview::__construct(), 4 passed |
Closed (cannot reproduce) |
Normal |
Bug report |
3.1.1 |
Code |
|
5 months 1 week |
|
AJAX HTTP Error During Security Review Analysis and Multiple Errors on Settings Page |
Closed (cannot reproduce) |
Normal |
Bug report |
3.1.x-dev |
Code |
|
1 year 3 months |
|
Error using drush "skip" option values where id and title are different |
Closed (fixed) |
Normal |
Bug report |
3.1.x-dev |
Code |
|
9 months 6 days |
|
Add test coverage for TrustedHosts and TemporaryFiles |
Closed (fixed) |
Normal |
Task |
3.1.x-dev |
Code |
smustgrave |
5 months 1 week |
|
Improve wording for Untrusted roles warning, or update the check |
Closed (fixed) |
Normal |
Task |
3.1.x-dev |
Miscellaneous |
|
5 months 2 weeks |
|
Add test coverage for ViewsAccess |
Closed (fixed) |
Normal |
Task |
3.1.x-dev |
Code |
|
5 months 2 weeks |
|
.htaccess file is writable, using the current Securing file permissions and ownership doc page |
Closed (fixed) |
Normal |
Task |
3.1.x-dev |
Documentation |
|
6 months 3 weeks |
|
Add test coverage for NamePasswords, PrivateFiles, and QueryErrors |
Closed (fixed) |
Normal |
Task |
3.1.x-dev |
Code |
smustgrave |
5 months 2 weeks |
|
Add test coverage for fields plugin |
Closed (fixed) |
Normal |
Task |
3.1.x-dev |
Code |
smustgrave |
5 months 2 weeks |
|
Create tests for AdminUser, ErrorReporting, ExecutablePhp, FailedLogin |
Closed (fixed) |
Normal |
Task |
3.1.x-dev |
Code |
smustgrave |
5 months 2 weeks |
|
Fix fatal error when pressing Run checklist button |
Closed (fixed) |
Normal |
Bug report |
3.0.x-dev |
Code |
|
1 year 9 months |
|
Headers check should be lowercase |
Closed (works as designed) |
Normal |
Bug report |
3.1.x-dev |
Code |
mdranove |
1 year 4 months |
|
Add "restrict access" to the "access security review list" permission |
Closed (fixed) |
Normal |
Task |
3.1.x-dev |
Code |
smustgrave |
1 year 4 months |
|
Fields::getDetails() can return a TranslatableMarkup object |
Closed (fixed) |
Normal |
Bug report |
3.1.1 |
Code |
|
10 months 3 days |
|
In valid array in Security.php on scan null given in in_array() |
Closed (outdated) |
Normal |
Bug report |
2.0.2 |
Code |
|
12 months 5 hours |
|
TypeError: array_key_exists(): Argument #2 ($array) must be of type array, null given in array_key_exists() (line 203 of modules/contrib/security_review/src/SecurityReview.php). |
Closed (cannot reproduce) |
Normal |
Bug report |
3.0.3 |
Code |
|
1 year 5 months |
|
Move from state API tot dedicated key/value collection |
Active |
Normal |
Task |
3.1.x-dev |
Code |
|
1 year 6 months |
|
False Negative for Writeable .htaccess on NGINX |
Closed (fixed) |
Normal |
Bug report |
8.x-1.x-dev |
Code |
|
11 years 3 months |
|
Add test for adminPermission Plugin + start testbase |
Closed (fixed) |
Normal |
Task |
3.1.x-dev |
Code |
|
1 year 4 months |
|
Long field names which are shortened by Drupal doesn't work. |
Closed (fixed) |
Normal |
Bug report |
2.0.x-dev |
Code |
|
5 years 8 months |
|
file check is problematic "green" when not test with chmod |
Closed (fixed) |
Normal |
Bug report |
3.1.x-dev |
Code |
|
1 year 10 months |
|
TypeError: Drupal\user\UserAuthentication::authenticateAccount(): Argument #1 (closed) ($account) must be of type Drupal\user\UserInterface, bool given |
Closed (fixed) |
Normal |
Bug report |
3.1.x-dev |
Code |
|
1 year 5 months |
|
Once failed but skipped checks shown as warning on status page |
Closed (fixed) |
Normal |
Bug report |
3.1.x-dev |
Code |
|
1 year 6 months |
|
Update 3.0.4 > 3.1.0 |
Closed (works as designed) |
Normal |
Bug report |
3.1.0 |
Miscellaneous |
|
1 year 5 months |
|
Validate schema |
Closed (fixed) |
Normal |
Task |
3.1.x-dev |
Code |
smustgrave |
1 year 6 months |
|
Problem with Mail Login || Deprecation of UserAuthInterface |
Closed (fixed) |
Normal |
Bug report |
3.1.x-dev |
Code |
|
1 year 9 months |
|
Hashes in dangerous tags in content exclude list not working |
Closed (fixed) |
Normal |
Bug report |
3.0.3 |
Code |
|
1 year 7 months |
|
Drush command does not display checks anymore |
Closed (fixed) |
Normal |
Bug report |
3.0.2 |
Code |
|
1 year 9 months |
|
views_access check is broken |
Closed (fixed) |
Normal |
Bug report |
3.0.2 |
Code |
|
1 year 9 months |
|
Private files path is not detected correctly |
Closed (fixed) |
Normal |
Bug report |
3.0.2 |
Code |
|
1 year 9 months |
|
[error] Message: Error executable_php, access was denied to the file. |
Closed (fixed) |
Normal |
Bug report |
3.0.x-dev |
Code |
|
1 year 11 months |