Skip to content

Phase 3: ZAP DAST Integration & Reliability #2

Description

@ToryMic

Phase 3 — ZAP DAST Integration & Reliability

Depends on: Phase 2

Drips Wave alignment

  • Mirrors Wave #1034 health check automation for scanner dependency readiness
  • Graceful degradation when ZAP unavailable (similar to dependency-unavailable error contracts)

Deliverables

  • ZAP spider/AJAX spider timeout hardening in zap_client.py
  • Passive scan wait optimisation with progress callbacks
  • Active scan policy profiles: quick / standard / deep
  • /ready includes ZAP connectivity check when SCANNER_MODE=zap
  • Structured DEPENDENCY_UNAVAILABLE error when ZAP down
  • Integration tests with mocked ZAP API

Acceptance criteria

  • Full lab scan (./start-lab.sh full) completes without timeout on DVWA
  • Fallback to builtin logged clearly when ZAP unreachable
  • Contract test for dependency-unavailable envelope
  • docker compose ps documented in runbook

References

Metadata

Metadata

Assignees

No one assigned

    Labels

    phase-3ZAP DAST integrationstellar-waveDrips Stellar Wave 6 alignment

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions