18F / concourse-compliance-testing

Concourse CI assets for Compliance Toolkit
https://compliance-viewer.18f.gov/
Other
17 stars 7 forks source link

Added new project for periodic owasp scans for staging.login.gov #132

Closed mzia closed 7 years ago

mzia commented 7 years ago

We want to periodically scan https://staging.login.gov but it has basic auth enabled. To bypass basic auth OWASP ZAP server public IP will have to be whitelisted within the login.gov's staging environment.

CC: @jgrevich @mogul

afeld commented 7 years ago

OWASP server public IP

Hmm. @18F/cloud-gov-ops Any chance there's a fixed IP range for the Concourse workers?

mzia commented 7 years ago

@afeld, basic auth has been removed. Please see if OWASP ZAP can hit the above URL. Also, should we include the production URL as well (secure.login.gov)?

afeld commented 7 years ago

should we include the production URL as well (secure.login.gov)?

If staging is production-like, there's no need.

afeld commented 7 years ago

Enabled!