sottlmarek / DevSecOps

Ultimate DevSecOps library
MIT License
5.76k stars 1.01k forks source link

Added mention of Arachni in DAST #30

Closed Zapotek closed 2 years ago

Zapotek commented 2 years ago

Arachni is a F/OSS web application security scanner, albeit with a proprietary license. However, I do think it fits the bill.

GH: https://github.com/Arachni/arachni

shkpk commented 2 years ago

Arachni is heading towards obsolescence, try out its next-gen successor Ecsypno SCNR!

Zapotek commented 2 years ago

Yes but it'll be a year or so or more, I'm just guessing here, it's up to the users. And that doesn't stop anyone from using it anyways. :)

sottlmarek commented 2 years ago

Hello @Zapotek I intentionally excluded Arachni as it is already out of support software. I am trying to keep only the high rated and maintained projects here. I like the tool, sadly it can be insecure by itself as lack of patching.

Zapotek commented 2 years ago

@sottlmarek TLDR; I had announced that some time ago but I revived the project.

I see where you're coming from but actually maintenance has continued and will continue until migration to SCNR completes, but like I said, that would depend on the users.

Regardless, do what you think best of course.

sottlmarek commented 2 years ago

Will reopen this PR after the activity or migration of Arachni will be completed /renewed. Still great tool !