Skip to content

feat(github): Add ZAP action#70

Merged
misonijnik merged 1 commit intomainfrom
misonijnik/zap-action
Mar 26, 2026
Merged

feat(github): Add ZAP action#70
misonijnik merged 1 commit intomainfrom
misonijnik/zap-action

Conversation

@misonijnik
Copy link
Copy Markdown
Member

@misonijnik misonijnik commented Mar 26, 2026

Add a new composite GitHub Action (github/zap) that chains OpenTaint SAST with ZAP DAST to automatically confirm taint-analysis findings via dynamic testing.

What it does

The action runs OpenTaint static analysis to find potential vulnerabilities, then uses those findings to drive targeted ZAP active scans — only testing endpoints and CWE categories that OpenTaint flagged. The final output is a SARIF file containing only dynamically confirmed vulnerabilities, uploaded to GitHub Code Security.

Two scan modes

  • full — Scans the current branch. Suitable for push to main.
  • differential — Compares PR branch against base branch, scanning only new findings. Suitable for pull_request triggers.

Co-authored-by: Grigoriy Klopov <139513740+Gr-i-niy@users.noreply.github.com>
@misonijnik misonijnik force-pushed the misonijnik/zap-action branch from 25f95ba to 3191c10 Compare March 26, 2026 09:52
@misonijnik misonijnik merged commit 96a64e5 into main Mar 26, 2026
5 checks passed
@misonijnik misonijnik deleted the misonijnik/zap-action branch March 26, 2026 10:05
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant