Files

16 lines
680 B
Markdown

# OWASP ZAP Methodology
ZAP performs web application tests from ephemeral GitLab Kubernetes-executor pods. Targets come from the `web_applications` group in root `assets.yml`; authentication values come from environment-scoped GitLab variables.
The OWASP ASVS source material used to develop the finding-to-control mapping is retained under `reference/OWASP_ASVS`.
`run.sh` executes ZAP baseline scanning and a focused TLS preflight, because ZAP
does not enumerate all protocol and cipher weaknesses. `scripts/normalize.py`
maps both evidence sources to OWASP ASVS 5 controls using `asvs-mapping.json`.
Run with:
```bash
./methodologies/zap/run.sh https://target.example
```