Vulnerability Scan & Management Report
Report Date: Sun, 23 Aug 2026 10:12:06 GMT Scan Target: https://results-exam-test.apps.silver.devops.gov.bc.ca Report Type: Executive Summary & Action Hub📊 Executive Summary
This security and operational report provides an aggregated overview of NR Results Exam. It consolidates vulnerability scanning, compliance metrics, deep health checks, and test coverage into a unified management review.Status Assessment
🟢 LOW RISK Security posture is acceptable. - Current Risk Score:0/100 (Lower is better)
- Remediation Debt Estimate: 0 hours of targeted security effort.
- Business Criticality: Medium
📈 Security Posture & Vulnerabilities
| Scan Origin | Critical | High | Medium | Low/Info | Active Findings | | :--- | :---: | :---: | :---: | :---: | :---: | | ZAP Penetration Test | 0 | 0 | 0 | 0 | 0 | | Nuclei Scanning | 0 | 0 | 0 | 0 | 0 | | GitHub Code Scanning | 0 | 0 | 1 | - | 1 | | Dependabot Alerts | - | - | - | - | 0 || Scan Origin | Critical | High | Medium | Low/Info | Active Findings |
|---|---|---|---|---|---|
| ZAP Penetration Test | 0 | 0 | 0 | 0 | 0 |
| Nuclei Scanning | 0 | 0 | 0 | 0 | 0 |
| GitHub Code Scanning | 0 | 0 | 1 | - | 1 |
| Dependabot Alerts | - | - | - | - | 0 |
0 alerts have been analyzed and accepted as low-risk in tests/.zap/rules.tsv.
>
> Full scanning trace and historical remediations are tracked directly under the [GitHub Repository Security Dashboard](https://github.com/bcgov/nr-results-exam/security).
🚀 DevOps Maturity & Stability Metrics
Measure of deployments, automation stability, and release velocity: - Deployment Frequency (Last 30 Days):0 deployments
- Pipeline Deployment Success Rate: 100%
- Mean Time to Recovery (MTTR): N/A
- Vulnerability Remediation Velocity (Resolution Rate): 94%
- Last Successful Production Deployment: N/A
⚡ Application Performance & Infrastructure Latency
Continuous synthetic monitoring of backend dependencies and response latency: - Overall Deep Health Check:OK
- Health Check Round-trip Latency: 622ms
- CHES (Email Client Services): 14ms
- Object Storage (S3 / MinIO): 36ms
- Cognito Federated Authentication: 219ms
📝 Code Quality & Maintainability
Quality metrics extracted from static analysis and dependency trees: - Backend Test Coverage:87.4% (Threshold: 70%)
- Frontend Test Coverage: 82.9% (Threshold: 70%)
- Backend Outdated Packages: 0 packages
- Frontend Outdated Packages: 0 packages
🛠️ Prioritized Remediation Action Items
1. ✅ No Critical Vulnerabilities: No critical vulnerabilities require immediate action. 2. ✅ No High Vulnerabilities: No high-risk items requiring active maintenance. 3. ✅ No Medium Vulnerabilities: Medium items are in order.Report automatically compiled by the security reporting engine. Full audit archive and history lines: [GitHub Pages Security Dashboard](https://github.com/bcgov/nr-results-exam/reports/)