Skip to content

Commit

Permalink
Browse files Browse the repository at this point in the history
  • Loading branch information
github-actions[bot] committed Sep 15, 2024
1 parent 8f03404 commit 40db252
Show file tree
Hide file tree
Showing 11 changed files with 2,074 additions and 1,656 deletions.
Original file line number Diff line number Diff line change
Expand Up @@ -3,15 +3,15 @@
"width": 1920,
"height": 1080,
"url": "https://www.demarches.interieur.gouv.fr",
"size": 2793.133,
"size": 2747.376,
"nodes": 604,
"requests": 83,
"grade": "D",
"score": 45.0,
"ges": 2.1,
"water": 3.15,
"ecoindex_version": "5.4.2",
"date": "2024-09-01 01:12:26.927238",
"date": "2024-09-15 01:10:21.105044",
"page_type": null
}
]
Original file line number Diff line number Diff line change
@@ -1 +1 @@
{"url":"https://www.demarches.interieur.gouv.fr","algorithm_version":3,"end_time":"Sun, 01 Sep 2024 01:15:24 GMT","grade":"B+","hidden":false,"likelihood_indicator":"MEDIUM","response_headers":{"Transfer-Encoding":"chunked","access-control-allow-credentials":"true","access-control-allow-headers":"Origin, X-Requested-With, Content-Type, Accept, Authorization, x-csrf-token","access-control-allow-methods":"GET, POST, PUT, DELETE, OPTIONS","access-control-allow-origin":"https://lannuaire.service-public.fr","age":"5204","cache-control":"max-age=0, s-maxage=28800, public","content-encoding":"gzip","content-language":"fr","content-security-policy":"frame-ancestors 'self' https://www.service-public.fr https://entreprendre.service-public.fr","content-type":"text/html;charset=UTF-8","cross-origin-embedder-policy":"unsafe-none","cross-origin-opener-policy":"same-origin-allow-popups","cross-origin-resource-policy":"cross-origin","date":"Sun, 01 Sep 2024 01:15:22 GMT","expires":"Sat, 31 Aug 2024 23:48:38 GMT","permissions-policy":"accelerometer=(), ambient-light-sensor=(), autoplay=(), battery=(), camera=(), cross-origin-isolated=(), display-capture=(), document-domain=(), encrypted-media=(), execution-while-not-rendered=(), execution-while-out-of-viewport=(), fullscreen=*, geolocation=(), gyroscope=(), keyboard-map=(), magnetometer=(), microphone=(), midi=(), navigation-override=(), payment=(), picture-in-picture=(), publickey-credentials-get=(), screen-wake-lock=(), sync-xhr=*, usb=(), xr-spatial-tracking=()","referrer-policy":"strict-origin-when-cross-origin","set-cookie":"SP_SESSION=ZTc5OGEyNWItZTc2NC00YzVhLTk3YjUtMjVkNGJhMWE4MjZm; Domain=service-public.fr; Path=/; Secure; HttpOnly; SameSite=Lax, TS012e9d3d=012a7f58e07776fb75764665db882f4c9ed65d7e7a6781cf56919f9cd8e69aa7b794ddcc7b1e9270564af7459bb99335083e62249c; Path=/; Domain=.www.service-public.fr; Secure; HTTPOnly, TS01425d24=012a7f58e011a56d24a36d0619f64ba9fdb544cfde6781cf56919f9cd8e69aa7b794ddcc7ba805ec7d995ff2028ec79dfcbb1c30a003d077e26abdb863eefb950aa730186a; path=/; domain=service-public.fr; HTTPonly; Secure","strict-transport-security":"max-age=63072000; includeSubDomains; preload","x-content-type-options":"nosniff","x-frame-options":"SAMEORIGIN","x-xss-protection":"1; mode=block"},"scan_id":55134560,"score":80,"start_time":"Sun, 01 Sep 2024 01:15:19 GMT","state":"FINISHED","status_code":200,"tests_failed":1,"tests_passed":9,"tests_quantity":10,"details":{"content-security-policy":{"expectation":"csp-implemented-with-no-unsafe","name":"content-security-policy","output":{"data":{"frame-ancestors":["'self'","https://entreprendre.service-public.fr","https://www.service-public.fr"]},"http":true,"meta":false,"numPolicies":1,"policy":{"antiClickjacking":true,"defaultNone":false,"insecureBaseUri":true,"insecureFormAction":true,"insecureSchemeActive":false,"insecureSchemePassive":false,"strictDynamic":false,"unsafeEval":false,"unsafeInline":true,"unsafeInlineStyle":true,"unsafeObjects":true}},"pass":false,"result":"csp-implemented-with-unsafe-inline","score_description":"Content Security Policy (CSP) implemented unsafely. This includes 'unsafe-inline' or data: inside script-src, overly broad sources such as https: inside object-src or script-src, or not restricting the sources for object-src or script-src.","score_modifier":-20},"cookies":{"expectation":"cookies-secure-with-httponly-sessions","name":"cookies","output":{"data":{"SP_SESSION":{"domain":".service-public.fr","expires":null,"httponly":true,"max-age":null,"path":"/","port":null,"samesite":"Lax","secure":true},"TS012e9d3d":{"domain":".www.service-public.fr","expires":null,"httponly":true,"max-age":null,"path":"/","port":null,"samesite":false,"secure":true},"TS01425d24":{"domain":".service-public.fr","expires":null,"httponly":true,"max-age":null,"path":"/","port":null,"samesite":false,"secure":true}},"sameSite":false},"pass":true,"result":"cookies-secure-with-httponly-sessions","score_description":"All cookies use the Secure flag and all session cookies use the HttpOnly flag","score_modifier":0},"cross-origin-resource-sharing":{"expectation":"cross-origin-resource-sharing-not-implemented","name":"cross-origin-resource-sharing","output":{"data":{"acao":"https://lannuaire.service-public.fr","clientaccesspolicy":null,"crossdomain":null}},"pass":true,"result":"cross-origin-resource-sharing-implemented-with-restricted-access","score_description":"Content is visible via cross-origin resource sharing (CORS) files or headers, but is restricted to specific domains","score_modifier":0},"redirection":{"expectation":"redirection-to-https","name":"redirection","output":{"destination":"https://www.service-public.fr/","redirects":true,"route":["http://www.demarches.interieur.gouv.fr/","https://www.demarches.interieur.gouv.fr/","https://www.service-public.fr/"],"status_code":200},"pass":true,"result":"redirection-to-https","score_description":"Initial redirection is to HTTPS on same host, final destination is HTTPS","score_modifier":0},"referrer-policy":{"expectation":"referrer-policy-private","name":"referrer-policy","output":{"data":"strict-origin-when-cross-origin","http":true,"meta":false},"pass":true,"result":"referrer-policy-private","score_description":"Referrer-Policy header set to \"no-referrer\", \"same-origin\", \"strict-origin\" or \"strict-origin-when-cross-origin\"","score_modifier":5},"strict-transport-security":{"expectation":"hsts-implemented-max-age-at-least-six-months","name":"strict-transport-security","output":{"data":"max-age=63072000; includeSubDomains; preload","includeSubDomains":true,"max-age":63072000,"preload":true,"preloaded":false},"pass":true,"result":"hsts-implemented-max-age-at-least-six-months","score_description":"HTTP Strict Transport Security (HSTS) header set to a minimum of six months (15768000)","score_modifier":0},"subresource-integrity":{"expectation":"sri-implemented-and-external-scripts-loaded-securely","name":"subresource-integrity","output":{"data":{}},"pass":true,"result":"sri-implemented-and-all-scripts-loaded-securely","score_description":"Subresource Integrity (SRI) is implemented and all scripts are loaded from a similar origin","score_modifier":5},"x-content-type-options":{"expectation":"x-content-type-options-nosniff","name":"x-content-type-options","output":{"data":"nosniff"},"pass":true,"result":"x-content-type-options-nosniff","score_description":"X-Content-Type-Options header set to \"nosniff\"","score_modifier":0},"x-frame-options":{"expectation":"x-frame-options-sameorigin-or-deny","name":"x-frame-options","output":{"data":"SAMEORIGIN"},"pass":true,"result":"x-frame-options-implemented-via-csp","score_description":"X-Frame-Options (XFO) implemented via the CSP frame-ancestors directive","score_modifier":5},"x-xss-protection":{"expectation":"x-xss-protection-disabled","name":"x-xss-protection","output":{"data":"1; mode=block"},"pass":true,"result":"x-xss-protection-enabled-mode-block","score_description":"Deprecated X-XSS-Protection header set to \"1; mode=block\"","score_modifier":0}}}
{"url":"https://www.demarches.interieur.gouv.fr","algorithm_version":3,"end_time":"Sun, 15 Sep 2024 01:13:20 GMT","grade":"B+","hidden":false,"likelihood_indicator":"MEDIUM","response_headers":{"Transfer-Encoding":"chunked","access-control-allow-credentials":"true","access-control-allow-headers":"Origin, X-Requested-With, Content-Type, Accept, Authorization, x-csrf-token","access-control-allow-methods":"GET, POST, PUT, DELETE, OPTIONS","access-control-allow-origin":"https://lannuaire.service-public.fr","age":"5442","cache-control":"max-age=0, s-maxage=28800, public","content-encoding":"gzip","content-language":"fr","content-security-policy":"frame-ancestors 'self' https://www.service-public.fr https://entreprendre.service-public.fr","content-type":"text/html;charset=UTF-8","cross-origin-embedder-policy":"unsafe-none","cross-origin-opener-policy":"same-origin-allow-popups","cross-origin-resource-policy":"cross-origin","date":"Sun, 15 Sep 2024 01:13:17 GMT","expires":"Sat, 14 Sep 2024 23:42:35 GMT","permissions-policy":"accelerometer=(), ambient-light-sensor=(), autoplay=(), battery=(), camera=(), cross-origin-isolated=(), display-capture=(), document-domain=(), encrypted-media=(), execution-while-not-rendered=(), execution-while-out-of-viewport=(), fullscreen=*, geolocation=(), gyroscope=(), keyboard-map=(), magnetometer=(), microphone=(), midi=(), navigation-override=(), payment=(), picture-in-picture=(), publickey-credentials-get=(), screen-wake-lock=(), sync-xhr=*, usb=(), xr-spatial-tracking=()","referrer-policy":"strict-origin-when-cross-origin","set-cookie":"SP_SESSION=MjM0MWUzOWEtMTZjNC00MjM4LTg1YzItMWY5ZTdiYTI1YTg0; Domain=service-public.fr; Path=/; Secure; HttpOnly; SameSite=Lax, TS012e9d3d=012a7f58e039be0dd60c9ba2b0254fc508629a8e6b748251391edcc68ef6d36ecd0fa6cc7989c01c137be163dae6dbe1425c58e669; Path=/; Domain=.www.service-public.fr; Secure; HTTPOnly, TS01425d24=012a7f58e0861f4d33d15e93d718601b1888b42173748251391edcc68ef6d36ecd0fa6cc7909d434e12e8f24be23e3232fa26b4afaebf7e06695cb145efdf12577bb30061e; path=/; domain=service-public.fr; HTTPonly; Secure","strict-transport-security":"max-age=63072000; includeSubDomains; preload","x-content-type-options":"nosniff","x-frame-options":"SAMEORIGIN","x-xss-protection":"1; mode=block"},"scan_id":55644571,"score":80,"start_time":"Sun, 15 Sep 2024 01:13:14 GMT","state":"FINISHED","status_code":200,"tests_failed":1,"tests_passed":9,"tests_quantity":10,"details":{"content-security-policy":{"expectation":"csp-implemented-with-no-unsafe","name":"content-security-policy","output":{"data":{"frame-ancestors":["https://www.service-public.fr","https://entreprendre.service-public.fr","'self'"]},"http":true,"meta":false,"numPolicies":1,"policy":{"antiClickjacking":true,"defaultNone":false,"insecureBaseUri":true,"insecureFormAction":true,"insecureSchemeActive":false,"insecureSchemePassive":false,"strictDynamic":false,"unsafeEval":false,"unsafeInline":true,"unsafeInlineStyle":true,"unsafeObjects":true}},"pass":false,"result":"csp-implemented-with-unsafe-inline","score_description":"Content Security Policy (CSP) implemented unsafely. This includes 'unsafe-inline' or data: inside script-src, overly broad sources such as https: inside object-src or script-src, or not restricting the sources for object-src or script-src.","score_modifier":-20},"cookies":{"expectation":"cookies-secure-with-httponly-sessions","name":"cookies","output":{"data":{"SP_SESSION":{"domain":".service-public.fr","expires":null,"httponly":true,"max-age":null,"path":"/","port":null,"samesite":"Lax","secure":true},"TS012e9d3d":{"domain":".www.service-public.fr","expires":null,"httponly":true,"max-age":null,"path":"/","port":null,"samesite":false,"secure":true},"TS01425d24":{"domain":".service-public.fr","expires":null,"httponly":true,"max-age":null,"path":"/","port":null,"samesite":false,"secure":true}},"sameSite":false},"pass":true,"result":"cookies-secure-with-httponly-sessions","score_description":"All cookies use the Secure flag and all session cookies use the HttpOnly flag","score_modifier":0},"cross-origin-resource-sharing":{"expectation":"cross-origin-resource-sharing-not-implemented","name":"cross-origin-resource-sharing","output":{"data":{"acao":"https://lannuaire.service-public.fr","clientaccesspolicy":null,"crossdomain":null}},"pass":true,"result":"cross-origin-resource-sharing-implemented-with-restricted-access","score_description":"Content is visible via cross-origin resource sharing (CORS) files or headers, but is restricted to specific domains","score_modifier":0},"redirection":{"expectation":"redirection-to-https","name":"redirection","output":{"destination":"https://www.service-public.fr/","redirects":true,"route":["http://www.demarches.interieur.gouv.fr/","https://www.demarches.interieur.gouv.fr/","https://www.service-public.fr/"],"status_code":200},"pass":true,"result":"redirection-to-https","score_description":"Initial redirection is to HTTPS on same host, final destination is HTTPS","score_modifier":0},"referrer-policy":{"expectation":"referrer-policy-private","name":"referrer-policy","output":{"data":"strict-origin-when-cross-origin","http":true,"meta":false},"pass":true,"result":"referrer-policy-private","score_description":"Referrer-Policy header set to \"no-referrer\", \"same-origin\", \"strict-origin\" or \"strict-origin-when-cross-origin\"","score_modifier":5},"strict-transport-security":{"expectation":"hsts-implemented-max-age-at-least-six-months","name":"strict-transport-security","output":{"data":"max-age=63072000; includeSubDomains; preload","includeSubDomains":true,"max-age":63072000,"preload":true,"preloaded":false},"pass":true,"result":"hsts-implemented-max-age-at-least-six-months","score_description":"HTTP Strict Transport Security (HSTS) header set to a minimum of six months (15768000)","score_modifier":0},"subresource-integrity":{"expectation":"sri-implemented-and-external-scripts-loaded-securely","name":"subresource-integrity","output":{"data":{}},"pass":true,"result":"sri-implemented-and-all-scripts-loaded-securely","score_description":"Subresource Integrity (SRI) is implemented and all scripts are loaded from a similar origin","score_modifier":5},"x-content-type-options":{"expectation":"x-content-type-options-nosniff","name":"x-content-type-options","output":{"data":"nosniff"},"pass":true,"result":"x-content-type-options-nosniff","score_description":"X-Content-Type-Options header set to \"nosniff\"","score_modifier":0},"x-frame-options":{"expectation":"x-frame-options-sameorigin-or-deny","name":"x-frame-options","output":{"data":"SAMEORIGIN"},"pass":true,"result":"x-frame-options-implemented-via-csp","score_description":"X-Frame-Options (XFO) implemented via the CSP frame-ancestors directive","score_modifier":5},"x-xss-protection":{"expectation":"x-xss-protection-disabled","name":"x-xss-protection","output":{"data":"1; mode=block"},"pass":true,"result":"x-xss-protection-enabled-mode-block","score_description":"Deprecated X-XSS-Protection header set to \"1; mode=block\"","score_modifier":0}}}

Large diffs are not rendered by default.

Loading

0 comments on commit 40db252

Please sign in to comment.