Skip to content

VBC-034: http-not-https ​

error

Category: security
Analysis: Regex (line by line)
File types: .js, .ts, .tsx, .py, .html, .astro
Scope: string and template literals only
Excluded paths: **/test/**, **/tests/**, **/__tests__/**, **/testdata/**, **/fixtures/**, **/test_*.py, **/*_test.py, **/test.py, **/conftest.py, **/*_test.go, **/*_bench.go, **/*.test.*, **/*.spec.*, **/bench/**, **/benchmark*, **/*corpus*, **/*payload*
Tags: security

What it reports ​

Insecure http:// link detected at line {line}. Use https:// instead.

Flagged ​

js
const api = 'http://api.example.com/v1';
js
const api = 'http://203.0.113.9/v1';
js
const probe = 'http://172.32.0.1/v1';
js
fetch(`http://${target}/api`)
js
const docs = 'http://docs.example.net/schemata/x';

Not flagged ​

js
const api = 'https://api.example.com/v1';
js
const dev = 'http://localhost:3000';
js
const dev2 = 'http://127.0.0.1:8000';
js
refuse http://169.254.169.254 (cloud metadata) before connecting
js
"A single http:// subresource downgrades the page"
js
"the {label} must use http:// or https://"
js
const parsed = new URL(req.url, `http://${req.headers.host}`);
js
const svg = 'http://www.w3.org/2000/svg';
js
const llm = 'http://192.168.1.50:1234/v1';
js
const db = "http://10.0.0.5/health";
js
const host = 'http://host.docker.internal:4318/v1/traces';
js
print(f"Serving at http://{host}:{port}")
js
console.log(`listening on http://${host}:${port}`)
js
'xmlns': 'http://www.sitemaps.org/schemas/sitemap/0.9'
js
'itunes': 'http://www.itunes.com/dtds/podcast-1.0.dtd'

Pattern ​

regex
(?<!new URL\([^)]{0,200})http://(?!localhost|127\.|0\.0\.0\.0|169\.254\.|\[::1\]|test\b|example\.(?:com|org)|www\.w3\.org|schemas?\.|json-schema\.org|purl\.org|ns\.adobe|www\.apache\.org|10\.|192\.168\.|172\.(?:1[6-9]|2[0-9]|3[01])\.|[\w.-]+\.(?:local|internal|localhost|lan)\b|(?:\$?\{[^}\n]{0,80}\}|\$\w+|%s|%\(\w+\)s):[\d{$]|[^\s'"`)]{0,120}/(?:schemas?|dtds?|xmlns?)\b)(?=[\w\[$\{])

Released under the MIT License.