Skip to content

Cannot scan sites with self-signed SSL certs #150

Description

@tolvos

Was giving this tool a little bit of a flex to see how it compares to our Lighthouse workflow, but found that it could not run against our testing environment, since the testing environment uses HTTPS with a self-signed SSL cert.

For context, we set up our testing environment dynamically in GitHub actions, and host it with docker/DDEV. When that environment is up, we can do Lighthouse, Playwright, and Selenium tests against that environment in GitHub CI to a similar degree that a developer could using their own computer.

When the local environment is set up, URLs that follow this pattern are available: https://test.ddev.site/my-test-page. When running this action against that example, we see an error like this:

Starting 'find' action
Preparing to scan https://test.ddev.site/my-test-page
node:internal/modules/run_main:107
    triggerUncaughtException(
    ^
page.goto: net::ERR_CERT_AUTHORITY_INVALID at https://test.ddev.site/my-test-page
Call log:
  - navigating to "https://test.ddev.site/my-test-page", waiting until "load"
    at findForUrl (/home/runner/work/_actions/github/accessibility-scanner/current/.github/actions/find/dist/findForUrl.js:12:16)
    at async Module.default (/home/runner/work/_actions/github/accessibility-scanner/current/.github/actions/find/dist/index.js:14:32)
    at async file:///home/runner/work/_actions/github/accessibility-scanner/current/.github/actions/find/bootstrap.js:59:5
    at async file:///home/runner/work/_actions/github/accessibility-scanner/current/.github/actions/find/bootstrap.js:31:1 {
  name: 'Error'
}
Node.js v24.12.0

That error is thrown, and the rest of the job is completely skipped.

Maybe this action needs a new parameter so that the Playwright environment can use the ignoreHTTPSErrors option?

Activity

  1. helen commented on Mar 3, 2026

    @helen
    Member

    We've been having some conversations about how much we want to be prescriptive / easy to use vs. exposing some kind of ability to pass anything you want to Playwright, great data point so I'm sorry this isn't working right now but we also really appreciate you taking the time to open the issue! Will look into it.

  2. tolvos commented on Mar 3, 2026

    @tolvos
    Author

    Makes perfect sense to me, thanks for your response! I can imagine other developers will probably run into similar issues as this. If ease of use and having folks do the least amount of configuration is one of your goals, having this particular case be a soft failure rather than an error might be ideal, at least in my eyes.

    Letting a developer know that the URL(s) they're evaluating don't have a valid SSL cert could be helpful, but I guess it technically isn't really part of most folk's standard accessibility checks. Or at least that's my limited understanding, while it's incredibly important, I don't think it's part of the WCAG or Axe-core? Usually I'd expect a security tool like ZAP to report on invalid certs.

  3. mvanhorn commented on Jun 7, 2026

    @mvanhorn
    Contributor

    Opened #224 adding an opt-in ignore_https_errors input that sets Playwright's ignoreHTTPSErrors so the scanner can run against staging hosts with self-signed/invalid certs. Default off; 8 tests pass.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions