You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
For my website, I just received the result of pen-test.
They found some versions on JS file as on chartjs. They think it's an issue to show version of librairies we're using.
Do you think it's possible to remove it from the final file?
Here is they screenshoot they sent to us:
Possible Implementation
I tried to remove it from the file, or set like static version = "hidden"; but I get error by some plugins as annotations which can no longer parse it.
I think this would be hard. Is that possible to have a way to say "I know what I'm doing, it's in right version" ?
The text was updated successfully, but these errors were encountered:
I don't think removing the version number will solve anything.
Firstly as you mentioned some libraries depend on it to know if certain features are available. Secondly if you remove the version number you can still check the source code and match it against all the versions. So it takes a step more to find the version used but it will never be a secret.
Feature Proposal
For my website, I just received the result of pen-test.
They found some versions on JS file as on chartjs. They think it's an issue to show version of librairies we're using.
Do you think it's possible to remove it from the final file?
Here is they screenshoot they sent to us:
Possible Implementation
I tried to remove it from the file, or set like
static version = "hidden";
but I get error by some plugins as annotations which can no longer parse it.I think this would be hard. Is that possible to have a way to say "I know what I'm doing, it's in right version" ?
The text was updated successfully, but these errors were encountered: