-
Task
-
Resolution: Done
-
Critical
-
None
-
None
-
8
-
False
-
-
False
-
ToDo
-
-
-
0
-
0.000
-
Very Likely
-
0
-
None
-
Unset
-
Unknown
-
None
I had set a meeting for this afternoon to go over this, but this might be one of those meetings that could have been an email, so I will cancel the meeting in favor of this. As part of SDLC compliance DAST needs to be implemented and running on a regular basis (schedule, per build, on y-streams, etc). We use RapiDAST to accomplish this, and we have a quickstart guide along with example setups for jenkins and github actions.
https://issues.redhat.com/browse/OADP-2431
https://spaces.redhat.com/display/PRODSEC/DAST+workflow
https://github.com/RedHatProductSecurity/rapidast?tab=readme-ov-file#workflow
https://spaces.redhat.com/pages/viewpage.action?spaceKey=PRODSEC&title=RapiDAST+QuickStart+Guide
https://github.com/RedHatProductSecurity/rapidast/tree/development/workflow_examples/jenkins