arazzo-no-script-tags-in-markdown
arazzo-no-script-tags-in-markdown checks every description and title in the document for <script> tags.
Descriptions get rendered. In docs, in portals, in tools. A script tag in a description is an injection waiting for somewhere to land.
Why did this violation appear?
A description or title contains a <script tag (in any letter case).
Bad example
arazzo: 1.0.1
info:
title: Read a <script>alert(1)</script> pet
version: '1.0'
Good example
arazzo: 1.0.1
info:
title: Read a pet
version: '1.0'
How do I fix this violation?
Remove the script tag. If you’re documenting markup, put it in a code block and escape it.
