{"repo":"zaproxy/action-baseline","free":true,"listed":false,"github":"https://github.com/zaproxy/action-baseline","clone":"git clone https://github.com/zaproxy/action-baseline.git","description":"A GitHub Action for running the ZAP Baseline scan","language":"JavaScript","stars":368,"topics":["security","github-actions","devsecops","actions","dast"],"license":"Apache-2.0","category":"security-tools","readme_excerpt":"Action Baseline A GitHub Action for running the ZAP Baseline scan to find vulnerabilities in your web application. The ZAP baseline action scans a target URL for vulnerabilities and maintains an issue in GitHub repository for the identified alerts. Read the following blog post for additional information. Inputs target Required The URL of the web application to be scanned. This can be either a publicly available web application or a locally accessible URL. docker name Optional The name of the docker file to be executed. By default the action runs the stable version of ZAP. But you can configure the parameter to use the weekly builds. rules file name Optional You can also specify a relative path to the rules file to ignore any alerts from the ZAP scan. Make sure to create the rules file inside the relevant repository. The following shows a sample rules file configuration. Make sure to checkout the repository (actions/checkout@v2) to provide the ZAP rules to the scan action. cmd options Optional Additional command lines options for the baseline script allow issue writing Optional By default the baseline action will file the report to the GitHub issue using the issue title input. Set this to false if you don't want the issue to be created or updated. issue title Optional The title for the GitHub issue to be created token Optional ZAP action uses the default action token provided by GitHub to create and update the issue for the baseline scan. You do not have to create a dedicated ","default_branch":null,"files":null,"tree":[],"storefront":"/r/zaproxy","claimed":false,"request_supported":{"post":"https://gitbuyer.com/r/zaproxy/action-baseline/request-supported","requests":0},"note":"indexed from public GitHub; nothing is for sale on this page. Clone it from GitHub. Paid listings live at /search."}