# SecTester v1.1.0 has been released!

**URL:** https://forum.crystal-lang.org/t/sectester-v1-1-0-has-been-released/4349
**Category:** News
**Created:** [February 9, 2022, 1:43pm UTC](https://forum.crystal-lang.org/t/sectester-v1-1-0-has-been-released/4349 "2022-02-09T13:43:16Z")
**Posts on this page:** 1
**Page:** 1

<div class="post-metadata">

### Author: ![bararchy](https://yyz2.discourse-cdn.com/flex036/user_avatar/forum.crystal-lang.org/bararchy/32/33_2.png) [@bararchy](https://forum.crystal-lang.org/u/bararchy)
#### Post date: [February 9, 2022, 1:43pm UTC](https://forum.crystal-lang.org/t/sectester-v1-1-0-has-been-released/4349/1 "2022-02-09T13:43:16Z")

</div>

The [SecTester](https://github.com/NeuraLegion/sec_tester) shard has been released with v1.1.0 being the latest!

The shard allows you to run security tests as part of the `Specs` flow, integrating a comprehensive security scanner directly into the development process.

## What do we got?

### New formatting of issues

 ![image](https://canada1.discourse-cdn.com/flex036/uploads/crystal_lang/original/2X/d/d11548e8d13ee2610750856392f77643d4dc3c6e.png)

### New options for spec control

```crystal
require "sec_tester"

it "tests my app for XSS" do
  server = HTTP::Server.new do |context|
    name = URI.decode_www_form(context.request.query_params["name"]?.to_s)

    context.response.content_type = "text/html"
    context.response << <<-EOF
      <html>
        <body>
          <h1>Hello, world!</h1>
          <p>#{name}</p>
        </body>
      </html>
      EOF
  end

  addr = server.bind_unused_port
  spawn do
    server.listen
  end

  tester = SecTester::Test.new
  tester.run_check(
    scan_name: "UnitTestingScan - XSS",
    test_name: "xss",
    target: SecTester::Target.new("http://#{addr}/?name=jhon")
  )
ensure
  server.try &.close
  tester.try &.cleanup
end

```

### Example of usage in the CI

```yaml
steps:
  - name: Install npm and Repeater
    run: |
      apt update
      apt-get install -y libnode-dev node-gyp libssl-dev
      apt-get install -y nodejs npm
      npm install -g @neuralegion/nexploit-cli --unsafe-perm=true
  - name: Run tests
    env:
      NEXPLOIT_TOKEN: ${{ secrets.NEXPLOIT_TOKEN }}
    run: crystal spec

```
