Security Testing
OWASP ZAP in CI/CD: Automated Security Testing on Every Pull Request
Most security tools are designed to be run manually by security engineers during a dedicated audit phase. OWASP ZAP (Zed Attack Proxy) is different — it's designed to be automated. The ZAP team maintains official Docker images with CI-oriented scan modes, GitHub Actions integrations, and a configuration system