Skip to content

Refactor permissions in DAST ZAP workflow to streamline configuration

ea23dec
Select commit
Loading
Failed to load commit list.
Merged

Add DAST ZAP full scan workflow configuration #24

Refactor permissions in DAST ZAP workflow to streamline configuration
ea23dec
Select commit
Loading
Failed to load commit list.
GitHub Advanced Security / CodeQL succeeded Apr 21, 2025 in 3s

1 new alert including 1 medium severity security vulnerability

New alerts in code changed by this pull request

Security Alerts:

  • 1 medium

See annotations below for details.

View all branch alerts.

Annotations

Check warning on line 47 in .github/workflows/DAST-ZAP-Zed-Attach-Proxy-Checkmarx.yml

See this annotation in the file changed.

Code scanning / CodeQL

Unpinned tag for a non-immutable Action in workflow Medium

Unpinned 3rd party Action 'DAST - Zed Attack Proxy (ZAP) Full Scan' step
Uses Step: zap
uses 'zaproxy/action-full-scan' with ref 'v0.12.0', not a pinned commit hash