{"_id":"@bramkortooms/sectester-scan","_rev":"7-0b1c3a1c5d99eeec07658c58aebecb54","name":"@bramkortooms/sectester-scan","dist-tags":{"test":"0.43.2-test","test2":"0.43.2-test2","latest":"0.43.2-test4"},"versions":{"0.43.2-test.20250622131555":{"name":"@bramkortooms/sectester-scan","version":"0.43.2-test.20250622131555","keywords":["security","testing","e2e","test","typescript","appsec","pentesting","qa","brightsec","scan","dast"],"author":{"name":"Artem Derevnjuk","email":"artem.derevnjuk@brightsec.com"},"license":"MIT","_id":"@bramkortooms/sectester-scan@0.43.2-test.20250622131555","maintainers":[{"name":"bramkortooms","email":"bramkortooms@gmail.com"}],"homepage":"https://github.com/NeuraLegion/sectester-js#readme","bugs":{"url":"https://github.com/NeuraLegion/sectester-js/issues"},"dist":{"shasum":"203affe2bc638eaa1257236275fab03861589b3f","tarball":"https://registry.npmjs.org/@bramkortooms/sectester-scan/-/sectester-scan-0.43.2-test.20250622131555.tgz","fileCount":150,"integrity":"sha512-+WtCFsmNTdFGz0F2By9VEoXTHyWYTpH69Gi9twD1EY+f15iiKYFlIiovZP2/Nm3rKzkE6IpkRu947CZ5zrAfpA==","signatures":[{"sig":"MEUCIEqPk1rtA+lf+B1hxEqH6pFILJve1qcs2gjRIOZ7UEIMAiEAgF3IVm/EfKWzTVEaLqNTky6BDEQPm1+VstPxyIuJaxQ=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":106085},"engines":{"npm":">=10","node":">=18"},"gitHead":"dbd44aba1c298c57e7bc03d4a554235f222c06d3","_npmUser":{"name":"bramkortooms","actor":{"name":"bramkortooms","type":"user","email":"bramkortooms@gmail.com"},"email":"bramkortooms@gmail.com"},"repository":{"url":"git+https://github.com/NeuraLegion/sectester-js.git","type":"git"},"_npmVersion":"10.9.0","description":"The package defines a simple public API to manage scans and their expectations.","directories":{},"_nodeVersion":"22.12.0","dependencies":{"tslib":"~2.6.3","ci-info":"^4.0.0","tsyringe":"^4.8.0","@har-sdk/core":"~1.4.5","reflect-metadata":"^0.2.2"},"_hasShrinkwrap":false,"peerDependencies":{"@sectester/core":">=0.16.0 <1.0.0"},"_npmOperationalInternal":{"tmp":"tmp/sectester-scan_0.43.2-test.20250622131555_1750587357800_0.6633911795601362","host":"s3://npm-registry-packages-npm-production"}},"0.43.2-test.20250622134229":{"name":"@bramkortooms/sectester-scan","version":"0.43.2-test.20250622134229","keywords":["security","testing","e2e","test","typescript","appsec","pentesting","qa","brightsec","scan","dast"],"author":{"name":"Artem Derevnjuk","email":"artem.derevnjuk@brightsec.com"},"license":"MIT","_id":"@bramkortooms/sectester-scan@0.43.2-test.20250622134229","maintainers":[{"name":"bramkortooms","email":"bramkortooms@gmail.com"}],"homepage":"https://github.com/NeuraLegion/sectester-js#readme","bugs":{"url":"https://github.com/NeuraLegion/sectester-js/issues"},"dist":{"shasum":"ba68ae7d1c4f1864de63ace51f3f2445a721ac91","tarball":"https://registry.npmjs.org/@bramkortooms/sectester-scan/-/sectester-scan-0.43.2-test.20250622134229.tgz","fileCount":150,"integrity":"sha512-oDNxVH9SIMuT5zYUvG4/3N3H5YdTGFBO55iYtbcOr/Cz4IGSX+iPaHUC1+oxgSHnXbQ3MZM1AXsdJZjbu4r87w==","signatures":[{"sig":"MEUCIBBoZhEcyQY4dLTneyQ4ZGeFG68SYyY9cj57A9g5jsVSAiEAh0cQFW/4fvBwI/vFXNnZtuIw1i2nL6vNM9b3EQpZrgY=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":106085},"engines":{"npm":">=10","node":">=18"},"gitHead":"dbd44aba1c298c57e7bc03d4a554235f222c06d3","_npmUser":{"name":"bramkortooms","actor":{"name":"bramkortooms","type":"user","email":"bramkortooms@gmail.com"},"email":"bramkortooms@gmail.com"},"repository":{"url":"git+https://github.com/NeuraLegion/sectester-js.git","type":"git"},"_npmVersion":"10.9.0","description":"The package defines a simple public API to manage scans and their expectations.","directories":{},"_nodeVersion":"22.12.0","dependencies":{"tslib":"~2.6.3","ci-info":"^4.0.0","tsyringe":"^4.8.0","@har-sdk/core":"~1.4.5","reflect-metadata":"^0.2.2"},"_hasShrinkwrap":false,"peerDependencies":{"@sectester/core":">=0.16.0 <1.0.0"},"_npmOperationalInternal":{"tmp":"tmp/sectester-scan_0.43.2-test.20250622134229_1750588951773_0.5029138622634717","host":"s3://npm-registry-packages-npm-production"}},"0.43.2-test":{"name":"@bramkortooms/sectester-scan","version":"0.43.2-test","keywords":["security","testing","e2e","test","typescript","appsec","pentesting","qa","brightsec","scan","dast"],"author":{"name":"Artem Derevnjuk","email":"artem.derevnjuk@brightsec.com"},"license":"MIT","_id":"@bramkortooms/sectester-scan@0.43.2-test","maintainers":[{"name":"bramkortooms","email":"bramkortooms@gmail.com"}],"homepage":"https://github.com/NeuraLegion/sectester-js#readme","bugs":{"url":"https://github.com/NeuraLegion/sectester-js/issues"},"dist":{"shasum":"65e061e44e389a28f1f4403f3fdb86fcd4ad0926","tarball":"https://registry.npmjs.org/@bramkortooms/sectester-scan/-/sectester-scan-0.43.2-test.tgz","fileCount":150,"integrity":"sha512-Djyfne7uD0QQVgMxLUG3oe5HyX0h6M2pa1khhOeni4uMmyN/SsXrstDebVxTYSROuoKtqFqOTbSPo0f9W2R4Bg==","signatures":[{"sig":"MEYCIQC5OfeAX37a75opMoBj0mr47y9UJVhRqJ9JYbQEG9RPIwIhAPbBWWmdiBYNW9u7vuZpG5SmblTc1pVznZM/iEIfQ+dJ","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":106151},"main":"./src/index.js","type":"commonjs","types":"./src/index.d.ts","engines":{"npm":">=10","node":">=18"},"gitHead":"dbd44aba1c298c57e7bc03d4a554235f222c06d3","_npmUser":{"name":"bramkortooms","actor":{"name":"bramkortooms","type":"user","email":"bramkortooms@gmail.com"},"email":"bramkortooms@gmail.com"},"repository":{"url":"git+https://github.com/NeuraLegion/sectester-js.git","type":"git"},"_npmVersion":"10.9.0","description":"The package defines a simple public API to manage scans and their expectations.","directories":{},"_nodeVersion":"22.12.0","dependencies":{"tslib":"~2.6.3","ci-info":"^4.0.0","tsyringe":"^4.8.0","@har-sdk/core":"~1.4.5","reflect-metadata":"^0.2.2"},"_hasShrinkwrap":false,"readmeFilename":"README.md","peerDependencies":{"@sectester/core":">=0.16.0 <1.0.0"},"_npmOperationalInternal":{"tmp":"tmp/sectester-scan_0.43.2-test_1750603336898_0.8388847631937759","host":"s3://npm-registry-packages-npm-production"}},"0.43.2-test2":{"name":"@bramkortooms/sectester-scan","version":"0.43.2-test2","keywords":["security","testing","e2e","test","typescript","appsec","pentesting","qa","brightsec","scan","dast"],"author":{"name":"Artem Derevnjuk","email":"artem.derevnjuk@brightsec.com"},"license":"MIT","_id":"@bramkortooms/sectester-scan@0.43.2-test2","maintainers":[{"name":"bramkortooms","email":"bramkortooms@gmail.com"}],"homepage":"https://github.com/NeuraLegion/sectester-js#readme","bugs":{"url":"https://github.com/NeuraLegion/sectester-js/issues"},"dist":{"shasum":"1aeb382fa9c6f18b4c348a4f65ac77d5270be703","tarball":"https://registry.npmjs.org/@bramkortooms/sectester-scan/-/sectester-scan-0.43.2-test2.tgz","fileCount":150,"integrity":"sha512-cKaGVvjna63nbM4AWd/J/b/IMsLgiH/2vd3ZIoE9z4jiBnf0c8L1Tv5V1R7nxtFlII/JSLunsDZRwluscbelxw==","signatures":[{"sig":"MEUCIDKJC3vb7Lk5vBQgaE8HOg88u+moZGvtjtO9ENsmD2PeAiEA2DPwcRCYNd2lnovUopOXa0+tpRR4LR2t8moD0h6Hc/s=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":106152},"main":"./src/index.js","type":"commonjs","types":"./src/index.d.ts","engines":{"npm":">=10","node":">=18"},"gitHead":"dbd44aba1c298c57e7bc03d4a554235f222c06d3","_npmUser":{"name":"bramkortooms","actor":{"name":"bramkortooms","type":"user","email":"bramkortooms@gmail.com"},"email":"bramkortooms@gmail.com"},"repository":{"url":"git+https://github.com/NeuraLegion/sectester-js.git","type":"git"},"_npmVersion":"10.9.0","description":"The package defines a simple public API to manage scans and their expectations.","directories":{},"_nodeVersion":"22.12.0","dependencies":{"tslib":"~2.6.3","ci-info":"^4.0.0","tsyringe":"^4.8.0","@har-sdk/core":"~1.4.5","reflect-metadata":"^0.2.2"},"_hasShrinkwrap":false,"readmeFilename":"README.md","peerDependencies":{"@sectester/core":">=0.16.0 <1.0.0"},"_npmOperationalInternal":{"tmp":"tmp/sectester-scan_0.43.2-test2_1750604117668_0.9365397131550335","host":"s3://npm-registry-packages-npm-production"}},"0.43.2-test.20250622185029":{"name":"@bramkortooms/sectester-scan","version":"0.43.2-test.20250622185029","keywords":["security","testing","e2e","test","typescript","appsec","pentesting","qa","brightsec","scan","dast"],"author":{"name":"Artem Derevnjuk","email":"artem.derevnjuk@brightsec.com"},"license":"MIT","_id":"@bramkortooms/sectester-scan@0.43.2-test.20250622185029","maintainers":[{"name":"bramkortooms","email":"bramkortooms@gmail.com"}],"homepage":"https://github.com/NeuraLegion/sectester-js#readme","bugs":{"url":"https://github.com/NeuraLegion/sectester-js/issues"},"dist":{"shasum":"e993a0afcefe00037907179b0df1e8163fe6c997","tarball":"https://registry.npmjs.org/@bramkortooms/sectester-scan/-/sectester-scan-0.43.2-test.20250622185029.tgz","fileCount":150,"integrity":"sha512-AJZHcmYHxQU/pE5xb1JbQ3RF34/vUW7udAVIJdN+zxoqKzmAOZ55fGMrCoT3Gske+aJkx0630xIg3qzXXw/GiQ==","signatures":[{"sig":"MEYCIQCXqE2O6yn0gllXZRYHfAcD1D7EmL65vygjjXU/FvP6RgIhAK19RwQ1p/cfUXXQd5HOP0VHNfT+MMlOrJfJu0dtv2rR","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":106166},"main":"./src/index.js","type":"commonjs","types":"./src/index.d.ts","engines":{"npm":">=10","node":">=18"},"gitHead":"dbd44aba1c298c57e7bc03d4a554235f222c06d3","_npmUser":{"name":"bramkortooms","actor":{"name":"bramkortooms","type":"user","email":"bramkortooms@gmail.com"},"email":"bramkortooms@gmail.com"},"repository":{"url":"git+https://github.com/NeuraLegion/sectester-js.git","type":"git"},"_npmVersion":"10.9.0","description":"The package defines a simple public API to manage scans and their expectations.","directories":{},"_nodeVersion":"22.12.0","dependencies":{"tslib":"~2.6.3","ci-info":"^4.0.0","tsyringe":"^4.8.0","@har-sdk/core":"~1.4.5","reflect-metadata":"^0.2.2"},"_hasShrinkwrap":false,"peerDependencies":{"@sectester/core":">=0.16.0 <1.0.0"},"_npmOperationalInternal":{"tmp":"tmp/sectester-scan_0.43.2-test.20250622185029_1750607438021_0.32180217843221826","host":"s3://npm-registry-packages-npm-production"}},"0.43.2-test3":{"name":"@bramkortooms/sectester-scan","version":"0.43.2-test3","keywords":["security","testing","e2e","test","typescript","appsec","pentesting","qa","brightsec","scan","dast"],"author":{"name":"Artem Derevnjuk","email":"artem.derevnjuk@brightsec.com"},"license":"MIT","_id":"@bramkortooms/sectester-scan@0.43.2-test3","maintainers":[{"name":"bramkortooms","email":"bramkortooms@gmail.com"}],"homepage":"https://github.com/NeuraLegion/sectester-js#readme","bugs":{"url":"https://github.com/NeuraLegion/sectester-js/issues"},"dist":{"shasum":"9a619e1806f195520b5843bd82c063b313897b72","tarball":"https://registry.npmjs.org/@bramkortooms/sectester-scan/-/sectester-scan-0.43.2-test3.tgz","fileCount":150,"integrity":"sha512-BTakX/9aAcNd8D6gi5tk0AygR93jUotneZlF3EeRbqtQuxkAcNgUKe/wPU/TvFbuQfrvaLM5e1wtf9D7jeCFMw==","signatures":[{"sig":"MEQCIGrJVzOyLUkmYemHpg86BQea/Ay1y0sNKHRk+74nXAqNAiAdGXfAMiq6v9JMXaFXq4Hcev7A3bkj4N79sa3yy7LU7w==","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":106152},"main":"./src/index.js","type":"commonjs","types":"./src/index.d.ts","engines":{"npm":">=10","node":">=18"},"gitHead":"dbd44aba1c298c57e7bc03d4a554235f222c06d3","_npmUser":{"name":"bramkortooms","actor":{"name":"bramkortooms","type":"user","email":"bramkortooms@gmail.com"},"email":"bramkortooms@gmail.com"},"repository":{"url":"git+https://github.com/NeuraLegion/sectester-js.git","type":"git"},"_npmVersion":"10.9.0","description":"The package defines a simple public API to manage scans and their expectations.","directories":{},"_nodeVersion":"22.12.0","dependencies":{"tslib":"~2.6.3","ci-info":"^4.0.0","tsyringe":"^4.8.0","@har-sdk/core":"~1.4.5","reflect-metadata":"^0.2.2"},"_hasShrinkwrap":false,"peerDependencies":{"@sectester/core":">=0.16.0 <1.0.0"},"_npmOperationalInternal":{"tmp":"tmp/sectester-scan_0.43.2-test3_1750607697616_0.40119768150016966","host":"s3://npm-registry-packages-npm-production"}},"0.43.2-test4":{"name":"@bramkortooms/sectester-scan","version":"0.43.2-test4","description":"The package defines a simple public API to manage scans and their expectations.","repository":{"type":"git","url":"git+https://github.com/NeuraLegion/sectester-js.git"},"engines":{"node":">=18","npm":">=10"},"author":{"name":"Artem Derevnjuk","email":"artem.derevnjuk@brightsec.com"},"license":"MIT","bugs":{"url":"https://github.com/NeuraLegion/sectester-js/issues"},"keywords":["security","testing","e2e","test","typescript","appsec","pentesting","qa","brightsec","scan","dast"],"dependencies":{"@har-sdk/core":"~1.4.5","ci-info":"^4.0.0","tslib":"~2.6.3","tsyringe":"^4.8.0","reflect-metadata":"^0.2.2"},"peerDependencies":{"@sectester/core":">=0.16.0 <1.0.0"},"types":"./src/index.d.ts","main":"./src/index.js","type":"commonjs","_id":"@bramkortooms/sectester-scan@0.43.2-test4","gitHead":"dbd44aba1c298c57e7bc03d4a554235f222c06d3","homepage":"https://github.com/NeuraLegion/sectester-js#readme","_nodeVersion":"22.12.0","_npmVersion":"10.9.0","dist":{"integrity":"sha512-R9u1k3vmQvBNGAihGVdJMCPSFE7drTyKaf8hdm+nyLdVr+cv/0QRkZD+nxTdiDoKh+jgHi5VFeuf52CD6c/ehg==","shasum":"e7a38bb76cf54d2ccd3d7e5c68faa99e5ebd67d1","tarball":"https://registry.npmjs.org/@bramkortooms/sectester-scan/-/sectester-scan-0.43.2-test4.tgz","fileCount":150,"unpackedSize":106152,"signatures":[{"keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U","sig":"MEUCIQDwT7ujaGU4hZH0hr1JFA3C16e2MAVJJspuaOq7C7HCsQIgZiSNEhTqgDEQco+FCxlX6Ve5EUn8n6mFH/n2GBYltTM="}]},"_npmUser":{"name":"bramkortooms","email":"bramkortooms@gmail.com","actor":{"name":"bramkortooms","email":"bramkortooms@gmail.com","type":"user"}},"directories":{},"maintainers":[{"name":"bramkortooms","email":"bramkortooms@gmail.com"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages-npm-production","tmp":"tmp/sectester-scan_0.43.2-test4_1750607887226_0.7787486111951147"},"_hasShrinkwrap":false}},"time":{"created":"2025-06-22T10:15:57.733Z","modified":"2025-06-22T15:58:07.604Z","0.43.2-test.20250622131555":"2025-06-22T10:15:58.001Z","0.43.2-test.20250622134229":"2025-06-22T10:42:31.955Z","0.43.2-test":"2025-06-22T14:42:17.075Z","0.43.2-test2":"2025-06-22T14:55:17.874Z","0.43.2-test.20250622185029":"2025-06-22T15:50:38.198Z","0.43.2-test3":"2025-06-22T15:54:57.783Z","0.43.2-test4":"2025-06-22T15:58:07.418Z"},"bugs":{"url":"https://github.com/NeuraLegion/sectester-js/issues"},"author":{"name":"Artem Derevnjuk","email":"artem.derevnjuk@brightsec.com"},"license":"MIT","homepage":"https://github.com/NeuraLegion/sectester-js#readme","keywords":["security","testing","e2e","test","typescript","appsec","pentesting","qa","brightsec","scan","dast"],"repository":{"type":"git","url":"git+https://github.com/NeuraLegion/sectester-js.git"},"description":"The package defines a simple public API to manage scans and their expectations.","maintainers":[{"name":"bramkortooms","email":"bramkortooms@gmail.com"}],"readme":"# @sectester/scan\n\n[![Maintainability](https://api.codeclimate.com/v1/badges/a5f72ececc9b0f402802/maintainability)](https://codeclimate.com/github/NeuraLegion/sectester-js/maintainability)\n[![Test Coverage](https://api.codeclimate.com/v1/badges/a5f72ececc9b0f402802/test_coverage)](https://codeclimate.com/github/NeuraLegion/sectester-js/test_coverage)\n![Build Status](https://github.com/NeuraLegion/sectester-js/actions/workflows/coverage.yml/badge.svg?branch=master&event=push)\n![NPM Downloads](https://img.shields.io/npm/dw/@sectester/core)\n\nThe package defines a simple public API to manage scans and their expectations.\n\n## Setup\n\n```bash\nnpm i -s @sectester/scan\n```\n\n## Usage\n\nTo start scanning your application, you have to create a `ScanFactory` as follows:\n\n```ts\nimport { Configuration } from '@sectester/core';\nimport { ScanFactory } from '@sectester/scan';\n\nconst config = new Configuration({\n  hostname: 'app.brightsec.com',\n  projectId: 'your project ID'\n});\n\nconst scanFactory = new ScanFactory(config);\n```\n\nTo create a new scan, you have to define a target first (for details, see [here](#defining-a-target-for-attack)):\n\n```ts\nimport { Target } from '@sectester/scan';\n\nconst target = new Target({\n  url: 'https://example.com'\n});\n```\n\nThe factory exposes the `createScan` method that returns a new [Scan instance](#managing-a-scan):\n\n```ts\nconst scan = await scanFactory.createScan({\n  target,\n  tests: ['insecure_output_handling']\n});\n```\n\nBelow you will find a list of parameters that can be used to configure a `Scan`:\n\n| Option                 | Description                                                                                                                                                                                                                                                |\n| ---------------------- | ---------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |\n| `target`               | The target that will be attacked. For details, see [here](#defining-a-target-for-attack).                                                                                                                                                                  |\n| `tests`                | The list of tests to be performed against the target application. To retrieve the complete list, send a request to the [API](https://app.brightsec.com/api/v1/scans/tests). [Learn more about tests](https://docs.brightsec.com/docs/vulnerability-guide). |\n| `repeaterId`           | Connects the scan to a Repeater agent, which provides secure access to local networks.                                                                                                                                                                     |\n| `smart`                | Minimize scan time by using automatic smart decisions regarding parameter skipping, detection phases, etc. Enabled by default.                                                                                                                             |\n| `skipStaticParams`     | Use an advanced algorithm to automatically determine if a parameter has any effect on the target system's behavior when changed, and skip testing such static parameters. Enabled by default.                                                              |\n| `poolSize`             | Sets the maximum concurrent requests for the scan, to control the load on your server. By default, `50`.                                                                                                                                                   |\n| `requestsRateLimit`    | Controls the rate limit for requests during the scan. By default, `0` (automatic rate limiting). Maximum value is `1000`.                                                                                                                                  |\n| `attackParamLocations` | Defines which part of the request to attack. By default, automatically detected based on the target (includes `body`, `query`, and `fragment` when applicable).                                                                                            |\n| `name`                 | The scan name. The method and pathname by default, e.g. `GET /users/1`.                                                                                                                                                                                    |\n\n### Defining a target for attack\n\nThe target can accept the following options:\n\n#### url\n\n- type: `string`\n\nThe server URL that will be used for the request. Usually the `url` represents a WHATWG URL:\n\n```ts\nimport { Target } from '@sectester/scan';\n\nconst target = new Target({\n  url: 'https://example.com'\n});\n```\n\nIf `url` contains a query string, they will be parsed as search params:\n\n```ts\nimport { Target } from '@sectester/scan';\n\nconst target = new Target({\n  url: 'https://example.com?foo=bar'\n});\n\nconsole.log(target.queryString); // foo=bar\n```\n\nIf you pass a `query` parameter, it will override these which obtained from `url`:\n\n```ts\nimport { Target } from '@sectester/scan';\n\nconst target = new Target({\n  url: 'https://example.com?foo=bar',\n  query: '?bar=foo'\n});\n\nconsole.log(target.queryString); // bar=foo\n```\n\n#### method\n\n- type: `string | HttpMethod`\n\nThe request method to be used when making the request, `GET` by default:\n\n```ts\nimport { Target, HttpMethod } from '@sectester/scan';\n\nconst target = new Target({\n  url: 'https://example.com',\n  method: HttpMethod.DELETE\n});\n```\n\n#### query\n\n- type: `URLSearchParams | string | Record<string, string | readonly string[]>`\n\nThe query parameters to be sent with the request:\n\n```ts\nimport { Target } from '@sectester/scan';\n\nconst target = new Target({\n  url: 'https://example.com',\n  query: {\n    hello: 'world',\n    foo: '123'\n  }\n});\n\nconsole.log(target.queryString); // hello=world&foo=123\n```\n\nIf you need to pass an array, you can do it using a `URLSearchParams` instance:\n\n```ts\nimport { Target } from '@sectester/scan';\n\nconst target = new Target({\n  url: 'https://example.com',\n  query: new URLSearchParams([\n    ['key', 'a'],\n    ['key', 'b']\n  ])\n});\n\nconsole.log(target.queryString); // key=a&key=b\n```\n\n> This will override the query string in url.\n\nIt is possible to define a custom serializer for query parameters:\n\n```ts\nimport { Target } from '@sectester/scan';\nimport { stringify } from 'qs';\n\nconst target = new Target({\n  url: 'https://example.com',\n  query: { a: ['b', 'c', 'd'] },\n  serializeQuery(params: Record<string, string | string[]>): string {\n    return stringify(params);\n  }\n});\n\nconsole.log(target.queryString); // a[0]=b&a[1]=c&a[2]=d\n```\n\n#### headers\n\n- type: `Headers | Record<string, string | string[]>`\n\nThe HTTP headers to be sent:\n\n```ts\nimport { Target } from '@sectester/scan';\n\nconst target = new Target({\n  url: 'https://example.com',\n  headers: {\n    'content-type': 'application/json'\n  }\n});\n```\n\n#### body\n\n- type: `ArrayBuffer | AsyncIterable<Uint8Array> | Blob | FormData | NodeJS.ReadableStream | Iterable<Uint8Array> | NodeJS.ArrayBufferView | URLSearchParams | string | Record<string, unknown>`\n\nThe data to be sent as the request body. Makes sense only for `POST`, `PUT`, `PATCH`, and `DELETE`:\n\n```ts\nimport { Target } from '@sectester/scan';\n\nconst target = new Target({\n  url: 'https://example.com',\n  body: {\n    foo: 'bar'\n  }\n});\n```\n\nYou can use `FormData` objects, as request body as well:\n\n```ts\nimport { Target } from '@sectester/scan';\n\nconst form = new FormData();\nform.append('greeting', 'Hello, world!');\n\nconst target = new Target({\n  url: 'https://example.com',\n  body: form\n});\n```\n\nIt is possible to set a form as body using an instance of `URLSearchParams`:\n\n```ts\nimport { Target } from '@sectester/scan';\n\nconst target = new Target({\n  url: 'https://example.com',\n  body: new URLSearchParams('foo=bar')\n});\n```\n\n#### auth\n\n- type: `string | undefined`\n  The authentication ID to be used for the target. For more information, see [here](https://docs.brightsec.com/docs/add-new-auth-object).\n\n```ts\nimport { Target } from '@sectester/scan';\n\nconst target = new Target({\n  url: 'https://example.com',\n  auth: 'your-auth-id' // Add your authentication ID here\n});\n```\n\n### Managing a scan\n\nThe `Scan` provides a lightweight API to revise and control the status of test execution.\n\nFor instance, to get a list of found issues, you can use the `issues` method:\n\n```ts\nconst issues = await scan.issues();\n```\n\nTo wait for certain conditions you can use the `expect` method:\n\n```ts\nawait scan.expect(Severity.HIGH);\nconst issues = await scan.issues();\n```\n\n> It returns control as soon as a scan is done, timeout is gone, or an expectation is satisfied.\n\nYou can also define a custom expectation passing a function that accepts an instance of `Scan` as follows:\n\n```ts\nawait scan.expect((scan: Scan) => scan.done);\n```\n\nIt might return a `Promise` instance as well:\n\n```ts\nawait scan.expect(async (scan: Scan) => {\n  const issues = await scan.issues();\n\n  return issues.length > 3;\n});\n```\n\nYou can use the `status` method to obtain scan status, to ensure that the scan is done and nothing prevents the user to check for issues, or for other reasons:\n\n```ts\nfor await (const state of scan.status()) {\n  // your code\n}\n```\n\n> This `for...of` will work while a scan is active.\n\nTo stop scan, use the `stop` method:\n\n```ts\nawait scan.stop();\n```\n\nTo dispose a scan, you just need to call the `dispose` method:\n\n```ts\nawait scan.dispose();\n```\n\n## License\n\nCopyright © 2025 [Bright Security](https://brightsec.com/).\n\nThis project is licensed under the MIT License - see the [LICENSE file](LICENSE) for details.\n","readmeFilename":"README.md"}