Summary
Set up nightly ZAP (OWASP Zed Attack Proxy) DAST scans against the staging environment. Use the ZAP baseline + full-scan in headless mode against deployed staging. Reports posted to a security board with severity-grouped findings; high/critical findings auto-open issues. This is forward-referenced from doc 11 (test plumbing) but the policy lives in 13.
Design reference
- docs/13-security-baseline.md §7.6, §16.4 (continuous security testing)
Acceptance criteria
Dependencies
none
Complexity
M
Summary
Set up nightly ZAP (OWASP Zed Attack Proxy) DAST scans against the staging environment. Use the ZAP baseline + full-scan in headless mode against deployed staging. Reports posted to a security board with severity-grouped findings; high/critical findings auto-open issues. This is forward-referenced from doc 11 (test plumbing) but the policy lives in 13.
Design reference
Acceptance criteria
zaproxy/action-full-scanagainst staging URL.zap/rules.tsv) to tune severity per ruletype:securityandpriority:P1zap-ignoreallowlist with justification + expiryDependencies
none
Complexity
M