FAQ

  • GitHub GitHub Repo stars
  • Discord Discord Server
  • ✨ New! Try the OpenAPI Doctor ✨ The OpenAPI Doctor
    Recommended

    arazzo-no-script-tags-in-markdown


    Formats: Severity:

    arazzo-no-script-tags-in-markdown checks every description and title in the document for <script> tags.

    Descriptions get rendered. In docs, in portals, in tools. A script tag in a description is an injection waiting for somewhere to land.

    Why did this violation appear?

    A description or title contains a <script tag (in any letter case).

    Bad example

    arazzo: 1.0.1
    info:
      title: Read a <script>alert(1)</script> pet
      version: '1.0'
    

    Good example

    arazzo: 1.0.1
    info:
      title: Read a pet
      version: '1.0'
    

    How do I fix this violation?

    Remove the script tag. If you’re documenting markup, put it in a code block and escape it.