# OWASP ZAP Methodology ZAP performs web application tests from ephemeral GitLab Kubernetes-executor pods. Targets come from the `web_applications` group in root `assets.yml`; authentication values come from environment-scoped GitLab variables. The OWASP ASVS source material used to develop the finding-to-control mapping is retained under `reference/OWASP_ASVS`. `run.sh` executes ZAP baseline scanning and a focused TLS preflight, because ZAP does not enumerate all protocol and cipher weaknesses. `scripts/normalize.py` maps both evidence sources to OWASP ASVS 5 controls using `asvs-mapping.json`. Run with: ```bash ./methodologies/zap/run.sh https://target.example ```