680 B
680 B
OWASP ZAP Methodology
ZAP performs web application tests from ephemeral GitLab Kubernetes-executor pods. Targets come from the web_applications group in root assets.yml; authentication values come from environment-scoped GitLab variables.
The OWASP ASVS source material used to develop the finding-to-control mapping is retained under reference/OWASP_ASVS.
run.sh executes ZAP baseline scanning and a focused TLS preflight, because ZAP
does not enumerate all protocol and cipher weaknesses. scripts/normalize.py
maps both evidence sources to OWASP ASVS 5 controls using asvs-mapping.json.
Run with:
./methodologies/zap/run.sh https://target.example