{"repo":"zaproxy/action-api-scan","free":true,"listed":false,"github":"https://github.com/zaproxy/action-api-scan","clone":"git clone https://github.com/zaproxy/action-api-scan.git","description":"A GitHub Action for running the ZAP API scan","language":"JavaScript","stars":75,"topics":["security","github-actions","devsecops","action","dast"],"license":"Apache-2.0","category":"security-tools","readme_excerpt":"Action API Scan A GitHub Action for running the ZAP API scan to perform Dynamic Application Security Testing (DAST). WARNING this action will perform attacks on the target API. You should only scan targets that you have permission to test. You should also check with your hosting company and any other services such as CDNs that may be affected before running this action. Inputs target Required target API definition, OpenAPI or SOAP, local file or URL, e.g. https://www.example.com/openapi.json or target endpoint URL, GraphQL, e.g. https://www.example.com/graphql format Optional The format of the defintion, openapi , soap , or graphql . Default is openapi . docker name Optional The name of the Docker image to be executed. By default the action runs the stable version of ZAP. But you can configure the parameter to use the weekly builds. rules file name Optional You can also specify a relative path to the rules file to ignore any alerts from the ZAP scan. Make sure to create the rules file inside the relevant repository. The following shows a sample rules file configuration. Make sure to checkout the repository (actions/checkout@v2) to provide the ZAP rules to the scan action. cmd options Optional Additional command lines options for the scan script allow issue writing Optional By default the action will file the report to the GitHub issue using the issue title input. Set this to false if you don't want the issue to be created or updated. issue title Optional The title for the Git","default_branch":null,"files":null,"tree":[],"storefront":"/r/zaproxy","claimed":false,"request_supported":{"post":"https://gitbuyer.com/r/zaproxy/action-api-scan/request-supported","requests":0},"note":"indexed from public GitHub; nothing is for sale on this page. Clone it from GitHub. Paid listings live at /search."}