24 lines
832 B
Bash
24 lines
832 B
Bash
#!/usr/bin/env bash
|
|
set -euo pipefail
|
|
|
|
TARGET_URL="${1:?Usage: run.sh https://target}"
|
|
SCRIPT_DIR="$(cd "$(dirname "$0")" && pwd)"
|
|
REPOSITORY_DIR="$(cd "$SCRIPT_DIR/../.." && pwd)"
|
|
ARTIFACT_ROOT="${ARTIFACT_ROOT:-$REPOSITORY_DIR/artifacts}"
|
|
RAW_DIR="$ARTIFACT_ROOT/raw/zaproxy"
|
|
NORMALIZED_DIR="$ARTIFACT_ROOT/normalized"
|
|
|
|
mkdir -p "$RAW_DIR" "$NORMALIZED_DIR"
|
|
|
|
zap-baseline.py -t "$TARGET_URL" -J "$RAW_DIR/zap.json" -I
|
|
python3 "$SCRIPT_DIR/scripts/tls-probe.py" "$TARGET_URL" "$RAW_DIR/tls.json"
|
|
|
|
if [ "${NORMALIZE_ZAP:-true}" = "true" ]; then
|
|
python3 "$SCRIPT_DIR/scripts/normalize.py" \
|
|
"$RAW_DIR/zap.json" \
|
|
"$RAW_DIR/tls.json" \
|
|
"$NORMALIZED_DIR/zaproxy-demo-web.json" \
|
|
--target "$TARGET_URL" \
|
|
--mapping "$SCRIPT_DIR/asvs-mapping.json" \
|
|
--schema "$REPOSITORY_DIR/schemas/test-report.schema.json"
|
|
fi |