Skip to content

sec: OWASP ZAP DAST scan post-deploy#121

Merged
Pyronewbic merged 1 commit into
mainfrom
dev
May 18, 2026
Merged

sec: OWASP ZAP DAST scan post-deploy#121
Pyronewbic merged 1 commit into
mainfrom
dev

Conversation

@Pyronewbic

Copy link
Copy Markdown
Owner

Summary

  • OWASP ZAP API scan runs after deploy + health check
  • Scans all endpoints via OpenAPI spec for injection, XSS, auth bypass
  • Report uploaded as artifact (30 day retention)
  • Non-blocking (fail_action: false)

Test plan

  • CI passes
  • Deploy triggers DAST job after health check

@Pyronewbic Pyronewbic merged commit e46ec41 into main May 18, 2026
16 of 17 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant