Report Date: 2026-03-29 10:17:19 UTC
Scan Target:
https://results-exam-test.apps.silver.devops.gov.bc.ca
Report Type: Executive Summary
This automated vulnerability assessment report provides a comprehensive overview of the security posture, code quality, and operational status of the NR Results Exam application. The report consolidates findings from multiple security scanning tools and quality metrics.
đĸ LOW RISK
Security posture is acceptable
Risk Score: 0/100 (Lower is better)
| Metric | Count | Status |
|---|---|---|
| Total Vulnerabilities | 0 | â None |
| Critical | 0 | â None |
| High | 0 | â None |
| Medium | 0 | â None |
| Low/Informational | 0 | âšī¸ Informational |
Scan Status: â
Completed Successfully
Scan Type: Full Penetration Test
Target:
https://results-exam-test.apps.silver.devops.gov.bc.ca
Scan Tool: OWASP ZAP (Zed Attack Proxy)
| Severity | Count | CVSS Range | Remediation Timeline |
|---|---|---|---|
| đ´ Critical | 0 | 9.0 - 10.0 | Immediate (0-7 days) |
| đ High | 0 | 7.0 - 8.9 | Urgent (7-30 days) |
| đĄ Medium | 0 | 4.0 - 6.9 | Important (30-90 days) |
| đĩ Low | 0 | 0.1 - 3.9 | As resources allow |
| âšī¸ Informational | 0 | N/A | Best practices |
| Total | 0 | All Severities | See details below |
Note: Detailed vulnerability descriptions, affected components, and remediation guidance are available in the GitHub Security Tab.
Scan Status: â
Completed Successfully
Scan Type: Template-based Vulnerability Detection
Target:
https://results-exam-test.apps.silver.devops.gov.bc.ca
Scan Tool: ProjectDiscovery Nuclei
| Severity | Count | CVSS Range | Remediation Timeline |
|---|---|---|---|
| đ´ Critical | 0 | 9.0 - 10.0 | Immediate (0-7 days) |
| đ High | 0 | 7.0 - 8.9 | Urgent (7-30 days) |
| đĄ Medium | 0 | 4.0 - 6.9 | Important (30-90 days) |
| đĩ Low | 0 | 0.1 - 3.9 | As resources allow |
| Total | 0 | All Severities | See details below |
Note: Detailed vulnerability information, affected endpoints, and CVE references are available in the GitHub Security Tab.
Dependabot Alerts: 0 open alerts
| Metric | Count | Status |
|---|---|---|
| Total Alerts | 0 | â None |
| Open | 0 | â All Resolved |
| Fixed | 0 | â Resolved |
| Dismissed | 0 | âšī¸ Dismissed |
| Unassigned | 0 | â All Assigned |
| Severity | Count |
|---|---|
| đ´ Critical (Error) | 0 |
| đ High (Warning) | 0 |
| đĄ Medium (Note) | 0 |
Note: Detailed scan results are available in the GitHub Security Tab.
Access detailed information in related tools:
Detailed vulnerability information is intentionally omitted from this public report to avoid exposing sensitive security data.
Note: For complete vulnerability details, remediation guidance, and affected components, see the GitHub Security Tab.
| Component | Coverage | Threshold | Status |
|---|---|---|---|
| Backend | 87.5% | 70% | â Pass |
| Frontend | 82.8% | 70% | â Pass |
Overall Status: â Both components exceed 70% threshold
| Component | Outdated Packages | Status |
|---|---|---|
| Backend | 0 | â Current |
| Frontend | 0 | â Current |
Note: Renovate automerge handles most dependency updates automatically. Manual review may be required for major version updates.
â No Critical Vulnerabilities: No critical vulnerabilities requiring immediate action.
â No High-Risk Vulnerabilities: No high-risk vulnerabilities requiring urgent attention.
â Medium-Risk Status: Medium-risk vulnerabilities are within acceptable limits.
Vulnerabilities are scored using the Common Vulnerability Scoring System (CVSS): - Critical (9.0-10.0): Exploitable vulnerabilities that could lead to complete system compromise - High (7.0-8.9): Serious vulnerabilities that could lead to significant data exposure or system compromise - Medium (4.0-6.9): Moderate risk vulnerabilities that could lead to limited data exposure - Low (0.1-3.9): Minor vulnerabilities with limited impact - Informational (0.0): Best practice recommendations and informational findings
This report was generated automatically by GitHub
Actions.
For detailed technical information, see the GitHub Security
Tab.