Heroku
tcp/443
GraphQL introspection is enabled.
This could leak to data leak if not properly configured.
Severity: medium
Fingerprint: c2db3a1c40d490db1a0bbaa31a0bbaa31a0bbaa31a0bbaa31a0bbaa31a0bbaa3
GraphQL introspection enabled at /graphql
Severity: medium
Fingerprint: c2db3a1c40d490db1a0bbaa385bc6649e3921ceb83e385a2a26aac8f0772418f
GraphQL introspection enabled at /graphql Types: 1373 (by kind: ENUM: 145, INPUT_OBJECT: 613, OBJECT: 596, SCALAR: 9, UNION: 10) Operations: - Query: Query | fields: appVersion, appliedPricings, asset, assetInventories, assetInventorySummary - Mutation: Mutation | fields: accountingAsync, acknowledgeNote, addAssetToDeliveryOrder, addCodeToAsset, addFeeToOrderGroup Directives: deprecated, include, skip (total: 3)
Severity: medium
Fingerprint: c2db3a1c40d490db1a0bbaa33a5883de4770194e85746cbf1c0b16728ed15ee2
GraphQL introspection enabled at /graphql Types: 1368 (by kind: ENUM: 144, INPUT_OBJECT: 611, OBJECT: 594, SCALAR: 9, UNION: 10) Operations: - Query: Query | fields: appVersion, appliedPricings, asset, assetInventories, assetInventorySummary - Mutation: Mutation | fields: accountingAsync, acknowledgeNote, addAssetToDeliveryOrder, addCodeToAsset, addFeeToOrderGroup Directives: deprecated, include, skip (total: 3)
Open service 13.248.132.87:443 · sprague.fleetpanda.com
2026-01-10 02:27
HTTP/1.1 302 Found
Cache-Control: no-cache
Content-Type: text/html; charset=utf-8
Location: https://sprague.fleetpanda.com/users/login
Nel: {"report_to":"heroku-nel","response_headers":["Via"],"max_age":3600,"success_fraction":0.01,"failure_fraction":0.1}
Report-To: {"group":"heroku-nel","endpoints":[{"url":"https://nel.heroku.com/reports?s=IpDgUsgoaJ%2Fth5fv8OE93%2BZqCboRSPA2CaxzJLOObXQ%3D\u0026sid=c46efe9b-d3d2-4a0c-8c76-bfafa16c5add\u0026ts=1768012038"}],"max_age":3600}
Reporting-Endpoints: heroku-nel="https://nel.heroku.com/reports?s=IpDgUsgoaJ%2Fth5fv8OE93%2BZqCboRSPA2CaxzJLOObXQ%3D&sid=c46efe9b-d3d2-4a0c-8c76-bfafa16c5add&ts=1768012038"
Server: Heroku
Set-Cookie: _fleetpanda_session=A0gCFWAQ31jiqU4%2BtsIrpBqepIsvn6Md0ZqasodDfarPEKkIGw2j3FEgEiKNuZTmPg5InottGiLnWxO9okOOlRU9eHkVCcBtKnAD%2Br7R%2FMgV%2F174kPX3kPV10oCCjcLGzn8QYEZw9VKNMZvNoPApjUVSxcPWAzRFZWgLE3kPod6iY9a45tMMPNEGgdxjBmkWRjDUh9wrfP1Pxv%2Fi8DgaDs%2BWSvNn--gg1MP%2BklppF8j%2FbX--X3Crr1JFneF5WJ1XjsdlIA%3D%3D; domain=.sprague.fleetpanda.com; path=/; secure; HttpOnly; SameSite=Lax
Strict-Transport-Security: max-age=63072000; includeSubDomains
Vary: Origin
Via: 1.1 heroku-router
X-Request-Id: 50c6d33f-341f-5810-14b5-2364f980add1
X-Runtime: 0.006939
Date: Sat, 10 Jan 2026 02:27:18 GMT
Content-Length: 108
Connection: close
<html><body>You are being <a href="https://sprague.fleetpanda.com/users/login">redirected</a>.</body></html>
Open service 13.248.132.87:443 · sprague.fleetpanda.com
2026-01-02 23:17
HTTP/1.1 302 Found
Cache-Control: no-cache
Content-Type: text/html; charset=utf-8
Location: https://sprague.fleetpanda.com/users/login
Nel: {"report_to":"heroku-nel","response_headers":["Via"],"max_age":3600,"success_fraction":0.01,"failure_fraction":0.1}
Report-To: {"group":"heroku-nel","endpoints":[{"url":"https://nel.heroku.com/reports?s=u6l5nVmrB9wo6QydxpAW%2FScsKJiok6J6tSOnFzphbcY%3D\u0026sid=c46efe9b-d3d2-4a0c-8c76-bfafa16c5add\u0026ts=1767395830"}],"max_age":3600}
Reporting-Endpoints: heroku-nel="https://nel.heroku.com/reports?s=u6l5nVmrB9wo6QydxpAW%2FScsKJiok6J6tSOnFzphbcY%3D&sid=c46efe9b-d3d2-4a0c-8c76-bfafa16c5add&ts=1767395830"
Server: Heroku
Set-Cookie: _fleetpanda_session=TqzabqRO45If88rLnt7g6x%2BBCthwJwgbuvke1mnZuBm%2FKtC1rkzaq1EvnS9oNHqY3iKM3H3BCQlUATLi33HdxjXqEseCkpTAESrfIxCW4jGLnEJs9QVIRACXM%2Ft0GmlxzIgAAxyhkiizX6cLwtPLeSP0Pvcq%2BDWLjOr482T4X2nStzYr6BcslgUlCFThRCujuTfLqGkd60%2BpZzfdpxAF97vUWlP%2F--aNEoc%2BzicfqNXlv3--T3zgGs4foxYNleaackOULA%3D%3D; domain=.sprague.fleetpanda.com; path=/; secure; HttpOnly; SameSite=Lax
Strict-Transport-Security: max-age=63072000; includeSubDomains
Vary: Origin
Via: 1.1 heroku-router
X-Request-Id: c01d4e35-94e4-8086-4e00-663a593e363e
X-Runtime: 0.004480
Date: Fri, 02 Jan 2026 23:17:10 GMT
Content-Length: 108
Connection: close
<html><body>You are being <a href="https://sprague.fleetpanda.com/users/login">redirected</a>.</body></html>
Open service 13.248.132.87:443 · sprague.fleetpanda.com
2025-12-22 23:56
HTTP/1.1 302 Found
Cache-Control: no-cache
Content-Type: text/html; charset=utf-8
Location: https://sprague.fleetpanda.com/users/login
Nel: {"report_to":"heroku-nel","response_headers":["Via"],"max_age":3600,"success_fraction":0.01,"failure_fraction":0.1}
Report-To: {"group":"heroku-nel","endpoints":[{"url":"https://nel.heroku.com/reports?s=NwyViRTfMSzkL39IxzZS%2FfBTu1TE7jedMOKxteulG%2BE%3D\u0026sid=c46efe9b-d3d2-4a0c-8c76-bfafa16c5add\u0026ts=1766447766"}],"max_age":3600}
Reporting-Endpoints: heroku-nel="https://nel.heroku.com/reports?s=NwyViRTfMSzkL39IxzZS%2FfBTu1TE7jedMOKxteulG%2BE%3D&sid=c46efe9b-d3d2-4a0c-8c76-bfafa16c5add&ts=1766447766"
Server: Heroku
Set-Cookie: _fleetpanda_session=eknSnAfIfEtkadHDX42DRBEaJH9v9o0jpaJgIIqKa%2FmzCgYF9k2gvStGPnbc5TgqYYpWWsNyQ2amULdMsmgX4BvuGo3E6dbPNEf%2FCrM68X5xbk1f2M4q1LnUatAIt1r9sP%2B7kAQ5%2Fe9%2FSvE9iVk6mlmyJOmVCXO5cXp%2BJr3M2EQHmgvjR%2FJeWZmgCNERIix7M8pq2nraBtUuz7GROsSica2j1tqt--pZLxyh%2Ba8jda0pRd--vk8EYe%2BJ8KA3bBACnqmfnQ%3D%3D; domain=.sprague.fleetpanda.com; path=/; secure; HttpOnly; SameSite=Lax
Strict-Transport-Security: max-age=63072000; includeSubDomains
Vary: Origin
Via: 1.1 heroku-router
X-Request-Id: 83d3d1d0-b65a-f552-4143-051f0290da46
X-Runtime: 0.007604
Date: Mon, 22 Dec 2025 23:56:06 GMT
Content-Length: 108
Connection: close
<html><body>You are being <a href="https://sprague.fleetpanda.com/users/login">redirected</a>.</body></html>
Open service 13.248.132.87:443 · sprague.fleetpanda.com
2025-12-21 07:17
HTTP/1.1 302 Found
Cache-Control: no-cache
Content-Type: text/html; charset=utf-8
Location: https://sprague.fleetpanda.com/users/login
Nel: {"report_to":"heroku-nel","response_headers":["Via"],"max_age":3600,"success_fraction":0.01,"failure_fraction":0.1}
Report-To: {"group":"heroku-nel","endpoints":[{"url":"https://nel.heroku.com/reports?s=RzGvEiXxW8d3AEIe7kj0hi1uSIIvNfPpaf30c8wV9iU%3D\u0026sid=c46efe9b-d3d2-4a0c-8c76-bfafa16c5add\u0026ts=1766301473"}],"max_age":3600}
Reporting-Endpoints: heroku-nel="https://nel.heroku.com/reports?s=RzGvEiXxW8d3AEIe7kj0hi1uSIIvNfPpaf30c8wV9iU%3D&sid=c46efe9b-d3d2-4a0c-8c76-bfafa16c5add&ts=1766301473"
Server: Heroku
Set-Cookie: _fleetpanda_session=K1qFimMk%2FTSBwqIeHTfRWGRUKayixQe5vojPgS0kd9wF0FHfYhaJPUrIjAbDyM5yWHaX6AwM%2Fgfiic4mErteoeuA67wGUgWnzEnn4roQ4CGEuj9xnGGXzNMw%2FiwW3%2FFf9S5J0ImJZpoek2QS5RVxSXdOgTBVgg8eBpM4MiDsGSVgE%2BX1JEJd3GnWGmtQzBxAAVIDopNGHgi8MqsBeEgtfyc%2F%2BA7U--QGFn07l1WW%2F0dact--PWg1cTW4QvtWDlIgMPFVQw%3D%3D; domain=.sprague.fleetpanda.com; path=/; secure; HttpOnly; SameSite=Lax
Strict-Transport-Security: max-age=63072000; includeSubDomains
Vary: Origin
Via: 1.1 heroku-router
X-Request-Id: 41d169ed-ce80-0f83-d1d5-d83cd96bf670
X-Runtime: 0.008207
Date: Sun, 21 Dec 2025 07:17:53 GMT
Content-Length: 108
Connection: close
<html><body>You are being <a href="https://sprague.fleetpanda.com/users/login">redirected</a>.</body></html>
Open service 13.248.132.87:443 · sprague.fleetpanda.com
2025-12-19 10:21
HTTP/1.1 302 Found
Cache-Control: no-cache
Content-Type: text/html; charset=utf-8
Location: https://sprague.fleetpanda.com/users/login
Nel: {"report_to":"heroku-nel","response_headers":["Via"],"max_age":3600,"success_fraction":0.01,"failure_fraction":0.1}
Report-To: {"group":"heroku-nel","endpoints":[{"url":"https://nel.heroku.com/reports?s=3%2BggLohZeVhPnhfk9dahFLrX5AsCVHc%2Bm4AthO8yxnw%3D\u0026sid=c46efe9b-d3d2-4a0c-8c76-bfafa16c5add\u0026ts=1766139678"}],"max_age":3600}
Reporting-Endpoints: heroku-nel="https://nel.heroku.com/reports?s=3%2BggLohZeVhPnhfk9dahFLrX5AsCVHc%2Bm4AthO8yxnw%3D&sid=c46efe9b-d3d2-4a0c-8c76-bfafa16c5add&ts=1766139678"
Server: Heroku
Set-Cookie: _fleetpanda_session=wmcUxf%2By4wSTLd6hxX7RYvh%2B3v%2BkkV0VauYT%2BhWQvuNArOUGQm5v6phsipEQH6z6o%2F6uJco3gXMIRf0298fudvpjYhamYIwyRxVpdSP71D4vycYQiVMbiTcbJS8BTMSaltHR37C638e5X5B%2FZIcpN81jOzhUfUM3LYRGmsJZyIoyYkT8dguaRgf1WczW4y0a3g71G07RS9H6bXC9clJ1CDpJ8WxO--Poy9uXxf%2FVYpTlru--219zJH3AWfkal%2BzhOVn4ug%3D%3D; domain=.sprague.fleetpanda.com; path=/; secure; HttpOnly; SameSite=Lax
Strict-Transport-Security: max-age=63072000; includeSubDomains
Vary: Origin
Via: 1.1 heroku-router
X-Request-Id: 0996c7dc-a9be-91b3-ccab-ee8572552b7a
X-Runtime: 0.007834
Date: Fri, 19 Dec 2025 10:21:18 GMT
Content-Length: 108
Connection: close
<html><body>You are being <a href="https://sprague.fleetpanda.com/users/login">redirected</a>.</body></html>