Skip to content

Phase 3: ZAP DAST Integration & Reliability #2

Description

@ToryMic

Phase 3 — ZAP DAST Integration & Reliability

Depends on: Phase 2

Drips Wave alignment

  • Mirrors Wave #1034 health check automation for scanner dependency readiness
  • Graceful degradation when ZAP unavailable (similar to dependency-unavailable error contracts)

Deliverables

  • ZAP spider/AJAX spider timeout hardening in zap_client.py
  • Passive scan wait optimisation with progress callbacks
  • Active scan policy profiles: quick / standard / deep
  • /ready includes ZAP connectivity check when SCANNER_MODE=zap
  • Structured DEPENDENCY_UNAVAILABLE error when ZAP down
  • Integration tests with mocked ZAP API

Acceptance criteria

  • Full lab scan (./start-lab.sh full) completes without timeout on DVWA
  • Fallback to builtin logged clearly when ZAP unreachable
  • Contract test for dependency-unavailable envelope
  • docker compose ps documented in runbook

References

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    phase-3ZAP DAST integrationstellar-waveDrips Stellar Wave 6 alignment

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions