{"repo":"zaproxy/action-full-scan","free":true,"listed":false,"github":"https://github.com/zaproxy/action-full-scan","clone":"git clone https://github.com/zaproxy/action-full-scan.git","description":"A GitHub Action for running the ZAP Full scan","language":"JavaScript","stars":384,"topics":["security","devsecops","github-actions","actions","dast"],"license":"Apache-2.0","category":"security-tools","readme_excerpt":"ZAP Action Full Scan A GitHub Action for running the ZAP Full Scan to perform Dynamic Application Security Testing (DAST). The ZAP full scan action runs the ZAP spider against the specified target (by default with no time limit) followed by an optional ajax spider scan and then a full active scan before reporting the results. The alerts will be maintained as a GitHub issue in the corresponding repository. WARNING this action will perform attacks on the target website. You should only scan targets that you have permission to test. You should also check with your hosting company and any other services such as CDNs that may be affected before running this action. ZAP will also submit forms which could result in a large number of messages via, for example, 'Contact us' or 'comment' forms. Inputs target Required The URL of the web application to be scanned. This can be either a publicly available web application or a locally accessible URL. docker name Optional The name of the docker file to be executed. By default the action runs the stable version of ZAP. But you can configure the parameter to use the weekly builds. rules file name Optional You can also specify a relative path to the rules file to ignore any alerts from the ZAP scan. Make sure to create the rules file inside the relevant repository. The following shows a sample rules file configuration. Make sure to checkout the repository (actions/checkout@v2) to provide the ZAP rules to the scan action. cmd options Optional Ad","default_branch":null,"files":null,"tree":[],"storefront":"/r/zaproxy","claimed":false,"request_supported":{"post":"https://gitbuyer.com/r/zaproxy/action-full-scan/request-supported","requests":0},"note":"indexed from public GitHub; nothing is for sale on this page. Clone it from GitHub. Paid listings live at /search."}