How to login and scan with ZAP, integrated into Jenkins pipeline - using zap docker?
57 views
Skip to first unread message
truclb
unread,
Jul 21, 2024, 11:51:57 PM7/21/24
Reply to author
Sign in to reply to author
Forward
Sign in to forward
Delete
You do not have permission to delete messages in this group
Copy link
Report message
Show original message
Either email addresses are anonymous for this group or you need the view member email addresses permission to view the original message
to ZAP User Group
I have a web application, and I want to integrate OWASP ZAP (Zed Attack Proxy) into the CI/CD Jenkins pipeline for automated security testing after deploying it to production. However, I find it challenging to handle authentication if I want to scan all URL links. I wonder if it is possible to do this. Has anyone tried doing it before?
truclb
unread,
Jul 22, 2024, 4:08:11 AM7/22/24
Reply to author
Sign in to reply to author
Forward
Sign in to forward
Delete
You do not have permission to delete messages in this group
Copy link
Report message
Show original message
Either email addresses are anonymous for this group or you need the view member email addresses permission to view the original message
to ZAP User Group
Actually, it's possible—I used ZAP for DAST in DevSecOps. It mimics human behavior to try to exploit vulnerabilities and then generates a report. ZAP is an amazing tool. I followed this video to solve my problem.
Vào lúc 10:51:57 UTC+7 ngày Thứ Hai, 22 tháng 7, 2024, truclb đã viết:
Simon Bennetts
unread,
Jul 25, 2024, 7:44:19 AM7/25/24
Reply to author
Sign in to reply to author
Forward
Sign in to forward
Delete
You do not have permission to delete messages in this group
Copy link
Report message
Show original message
Either email addresses are anonymous for this group or you need the view member email addresses permission to view the original message
to ZAP User Group
FYI there are now more options available for authentication.