kasunkv / owasp-zap-vsts-task

Visual Studio Team Services build/release task for running OWASP ZAP automated security tests
MIT License
30 stars 11 forks source link

Coveralls Status Known Vulnerabilities dependencies Status devDependencies Status Best Practices GitHub release license Visual Studio Marketplace Gitter

OWASP Zed Attack Proxy Scan Task

Visual Studio Team Services build/release task for running OWASP ZAP automated security tests. Run active scan against a target with security risk thresholds and ability to generate the scan report.

Using OWASP Zed Attack Proxy Scan Task

Follow the instructions given below to add and configure OWASP Zed Attack Proxy Task in your build/release pipeline.

Prerequisites

Add the OWASP Zed Attack Proxy Scan Task

Install the OWASP Zed Attack Proxy Scan Task in to your Visual Studio Team Services account and search for the task in the available tasks. The task will appear in the Test section of the task list. Add it to your build/release task.

Add OWASP Zed Attack Proxy Task

Required Configuration

OWASP Zed Attack Proxy Scan task has some required configuration options that needed to be provided.

These configurations are found in the ZAP API Configuration section.

Required Configuration Options

Required Options

Spider Scan Options

This configuration section includes the parameters that need to be sent to perform the active scan against the target.

Spider Scan Options

Available Options

Active Scan Options

This configuration section includes the parameters that need to be sent to perform the active scan against the target.

Active Scan Options

Available Options

Configure Verification

This configuration section includes the parameters that need to be sent to perform the active scan against the target.

Configure Verification

Available Options

Configure Reports

This configuration section includes the parameters that need to be sent to perform the active scan against the target.

Configure Reports

Available Options

Contributing to OWASP Zed Attack Proxy Scan Task

Found a Bug?

Fixed a Bug?

Add/Suggest a New Feature, or Change Existing One?

Have Questions?

Current Contributors

A special thanks to all the Contributors of the OWASP Zed Attack Proxy Scan Task Project. Your valuable contributions are most welcome. :)