Files

680 B

OWASP ZAP Methodology

ZAP performs web application tests from ephemeral GitLab Kubernetes-executor pods. Targets come from the web_applications group in root assets.yml; authentication values come from environment-scoped GitLab variables.

The OWASP ASVS source material used to develop the finding-to-control mapping is retained under reference/OWASP_ASVS.

run.sh executes ZAP baseline scanning and a focused TLS preflight, because ZAP does not enumerate all protocol and cipher weaknesses. scripts/normalize.py maps both evidence sources to OWASP ASVS 5 controls using asvs-mapping.json.

Run with:

./methodologies/zap/run.sh https://target.example