Uploaded image for project: 'Multiple Architecture Enablement'
  1. Multiple Architecture Enablement
  2. MULTIARCH-4985

Run DAST on MTO webhook and pod placement controller

XMLWordPrintable

    • Icon: Story Story
    • Resolution: Done
    • Icon: Critical Critical
    • None
    • None
    • None
    • False
    • None
    • False
    • NEW
    • NEW
    • Multi-Arch Sprint 259

       DAST is a testing method to uncover potential security flaws by performing automated security testing against a running target; for example, a web application or an API. DAST can also identify runtime and environment-related issues, such as misconfiguration, which is difficult to detect in source code.

      Presently, DAST only applies to web applications or web-facing components of software  including web APIs. This will include OpenShift/Kubernetes components.

      Acceptance criteria

      • A dynamic application security testing (DAST) scan is performed by integrating RapiDAST in the product QE regression test suite and executed on a regular basis against the HTTP endpoints of the product or service.
      • A Jira issue is created in the Jira project for the component scanned for all findings in the DAST scans results.
      • Person assignment and a target end date or due date are specified
      • All Security issues found through DAST must be addressed and fixed according to Vulnerability SLA and Weakness RRT.

      For further information on 

      • Roles and responsibilities
      • Place in the software lifecycle
      • References

      visit RH-SDL Section 2: Secure Development Activities Confluence 

      Runbook: DAST (Dynamic Application Security Testing)

        1. oobtkube.mto.json
          0.2 kB
        2. trivy-report.txt
          11 kB
        3. zap-report.json
          9 kB

              lwan-wanglin Lin Wang
              rhn-support-adistefa Alessandro Di Stefano
              Votes:
              0 Vote for this issue
              Watchers:
              2 Start watching this issue

                Created:
                Updated:
                Resolved: