Groups
Groups
Sign in
Groups
Groups
ZAP User Group
Conversations
About
Send feedback
Help
ZAP docker Automation Framework
92 views
Skip to first unread message
William Hagman
unread,
Feb 24, 2025, 4:34:40 AM
Feb 24
Reply to author
Sign in to reply to author
Forward
Sign in to forward
Delete
You do not have permission to delete messages in this group
Copy link
Report message
Show original message
Either email addresses are anonymous for this group or you need the view member email addresses permission to view the original message
to ZAP User Group
Hi, is the new clientSpider included in the Docker automation framework?
https://www.zaproxy.org/docs/docker/about/#automation-framework
Simon Bennetts
unread,
Feb 25, 2025, 12:50:36 PM
Feb 25
Reply to author
Sign in to reply to author
Forward
Sign in to forward
Delete
You do not have permission to delete messages in this group
Copy link
Report message
Show original message
Either email addresses are anonymous for this group or you need the view member email addresses permission to view the original message
to ZAP User Group
Hiya,
The Automation Framework is not specific to Docker, it will run outside of docker as well :)
And yes, the Client Spider is supported:
https://www.zaproxy.org/docs/automate/automation-framework/
https://www.zaproxy.org/docs/desktop/addons/client-side-integration/automation/
Cheers,
Simon
William Hagman
unread,
Mar 5, 2025, 5:24:16 AM
Mar 5
Reply to author
Sign in to reply to author
Forward
Sign in to forward
Delete
You do not have permission to delete messages in this group
Copy link
Report message
Show original message
Either email addresses are anonymous for this group or you need the view member email addresses permission to view the original message
to ZAP User Group
Hi,
This is how i currently run the zap scan:
docker run --rm \
-v $(pwd):/zap/wrk/:rw \
-t image ${{ inputs.scan-type }}.py \
-I -j -d \
-m 20 \
-T 60 \
-t ${{ inputs.url }} \
-r zap-report.html \
--hook=/zap/wrk/auth_hook.py
Based on this documentation i can't see the option for using the Client Spider:
https://www.zaproxy.org/docs/docker/baseline-scan/
Br,
William
Simon Bennetts
unread,
Mar 5, 2025, 12:47:37 PM
Mar 5
Reply to author
Sign in to reply to author
Forward
Sign in to forward
Delete
You do not have permission to delete messages in this group
Copy link
Report message
Show original message
Either email addresses are anonymous for this group or you need the view member email addresses permission to view the original message
to ZAP User Group
Thats the documentation for the baseline scan, which is one of the packaged scans.
They are documented here
https://www.zaproxy.org/docs/docker/
None of the packaged scans support the client spider.
The Automation Framework is documented here:
https://www.zaproxy.org/docs/automate/automation-framework/
As you'll see, it does support the client spider:
https://www.zaproxy.org/docs/desktop/addons/client-side-integration/automation/
Cheers,
Simon
Reply all
Reply to author
Forward
0 new messages