bcgov / cas-registration

A web app for Registration in OBPS under the Clean Growth branch
Apache License 2.0
1 stars 1 forks source link

Set up BCIERS apps for OWASP Zap scan #2195

Open marcellmueller opened 2 months ago

marcellmueller commented 2 months ago

Blocked by #2283 as scanning so many more containers will exacerbate the rate limiting errors

Describe the task

We should set up our BCIERS apps so they can be scanned for common vulnerabilities using https://www.zaproxy.org/ Zap scan. We already have it running in CI for Registration 1.

Now that we have the BCIERS apps running in CI for e2e this will be a lot simpler and the work on this could be reused to run all apps concurrently for e2e tests if we had cross-app workflows to test.

Acceptance Criteria

Additional context

patrickisaac commented 1 month ago

Good topic for next DevOps meeting