<?xml version="1.0" encoding="utf-8" standalone="yes"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
  <channel>
    <title>Scan Policies on ZAP</title>
    <link>/docs/desktop/addons/scan-policies/</link>
    <description>Recent content in Scan Policies on ZAP</description>
    <generator>Hugo</generator>
    <language>en-us</language>
    <atom:link href="/docs/desktop/addons/scan-policies/index.xml" rel="self" type="application/rss+xml" />
    <item>
      <title>API Policy</title>
      <link>/docs/desktop/addons/scan-policies/policy-api/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/desktop/addons/scan-policies/policy-api/</guid>
      <description>&lt;h1 id=&#34;api-policy&#34;&gt;API Policy&lt;/h1&gt;&#xA;&lt;p&gt;A policy focusing on issues likely to impact APIs and not UI.&lt;/p&gt;&#xA;&lt;p&gt;For the list of scan rules included see the &lt;a href=&#34;/alerttags/policy_api/&#34;&gt;Alert Tag: POLICY_API&lt;/a&gt; page.&lt;/p&gt;&#xA;&lt;p&gt;Programmatic Name: &lt;code&gt;API&lt;/code&gt;&lt;/p&gt;&#xA;&lt;p&gt;Return to &lt;a href=&#34;/docs/desktop/addons/scan-policies/&#34;&gt;main scan policies page&lt;/a&gt;.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Default Policy</title>
      <link>/docs/desktop/addons/scan-policies/policy-default/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/desktop/addons/scan-policies/policy-default/</guid>
      <description>&lt;h1 id=&#34;default-policy&#34;&gt;Default Policy&lt;/h1&gt;&#xA;&lt;p&gt;A policy which enables all of the installed active scan rules.&lt;/p&gt;&#xA;&lt;p&gt;Programmatic Name: &lt;code&gt;Default Policy&lt;/code&gt;&lt;/p&gt;&#xA;&lt;p&gt;Return to &lt;a href=&#34;/docs/desktop/addons/scan-policies/&#34;&gt;main scan policies page&lt;/a&gt;.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Developer CI/CD Policy</title>
      <link>/docs/desktop/addons/scan-policies/policy-dev-cicd/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/desktop/addons/scan-policies/policy-dev-cicd/</guid>
      <description>&lt;h1 id=&#34;developer-cicd-policy&#34;&gt;Developer CI/CD Policy&lt;/h1&gt;&#xA;&lt;p&gt;This policy is designed to be used by developers in a CI/CD pipeline.&lt;/p&gt;&#xA;&lt;ul&gt;&#xA;&lt;li&gt;Recommended for running in CI/CD&lt;/li&gt;&#xA;&lt;li&gt;No environmental / server related rules&lt;/li&gt;&#xA;&lt;li&gt;No long running rules&lt;/li&gt;&#xA;&lt;li&gt;No rules with high false positives&lt;/li&gt;&#xA;&lt;li&gt;No timing attacks&lt;/li&gt;&#xA;&lt;li&gt;No informational only rules&lt;/li&gt;&#xA;&lt;li&gt;Minimal overlap&lt;/li&gt;&#xA;&lt;/ul&gt;&#xA;&lt;p&gt;For the list of scan rules included see the &lt;a href=&#34;/alerttags/policy_dev_cicd/&#34;&gt;Alert Tag: POLICY_DEV_CICD&lt;/a&gt; page.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Developer Standard Policy</title>
      <link>/docs/desktop/addons/scan-policies/policy-dev-std/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/desktop/addons/scan-policies/policy-dev-std/</guid>
      <description>&lt;h1 id=&#34;developer-standard-policy&#34;&gt;Developer Standard Policy&lt;/h1&gt;&#xA;&lt;p&gt;A developer focused policy meant to perform fairly quickly while providing a greater set of results than the CICD policy, intended for use in a dev environment.&lt;/p&gt;&#xA;&lt;ul&gt;&#xA;&lt;li&gt;A superset of Developer CICD&lt;/li&gt;&#xA;&lt;li&gt;Intended to run in a dev environment&lt;/li&gt;&#xA;&lt;li&gt;No environmental / server related rules&lt;/li&gt;&#xA;&lt;li&gt;No rules with high false positives&lt;/li&gt;&#xA;&lt;li&gt;No timing attacks&lt;/li&gt;&#xA;&lt;li&gt;No informational only rules&lt;/li&gt;&#xA;&lt;li&gt;Can include longer running rules&lt;/li&gt;&#xA;&lt;/ul&gt;&#xA;&lt;p&gt;For the list of scan rules included see the &lt;a href=&#34;/alerttags/policy_dev_std/&#34;&gt;Alert Tag: POLICY_DEV_STD&lt;/a&gt; page.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Developer Full Policy</title>
      <link>/docs/desktop/addons/scan-policies/policy-dev-full/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/desktop/addons/scan-policies/policy-dev-full/</guid>
      <description>&lt;h1 id=&#34;developer-full-policy&#34;&gt;Developer Full Policy&lt;/h1&gt;&#xA;&lt;p&gt;A developer focused policy, including a superset of the &lt;a href=&#34;/docs/desktop/addons/scan-policies/policy-dev-std/&#34;&gt;dev standard&lt;/a&gt; with a greater variety of potential findings and only minimal environmental/server related rules, intended for use in a dev environment.&lt;/p&gt;&#xA;&lt;ul&gt;&#xA;&lt;li&gt;A superset of Developer Standard&lt;/li&gt;&#xA;&lt;li&gt;Intended to run in a dev environment&lt;/li&gt;&#xA;&lt;li&gt;No rules with high false positives&lt;/li&gt;&#xA;&lt;li&gt;No timing attacks&lt;/li&gt;&#xA;&lt;li&gt;Minimal environmental / server related rules&lt;/li&gt;&#xA;&lt;/ul&gt;&#xA;&lt;p&gt;For the list of scan rules included see the &lt;a href=&#34;/alerttags/policy_dev_full/&#34;&gt;Alert Tag: POLICY_DEV_FULL&lt;/a&gt; page.&lt;/p&gt;</description>
    </item>
    <item>
      <title>QA CI/CD Policy</title>
      <link>/docs/desktop/addons/scan-policies/policy-qa-cicd/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/desktop/addons/scan-policies/policy-qa-cicd/</guid>
      <description>&lt;h1 id=&#34;qa-cicd-policy&#34;&gt;QA CI/CD Policy&lt;/h1&gt;&#xA;&lt;p&gt;A quality assurance focused policy meant to perform fairly quickly while providing a greater set of results than developer policies, intended for use in a CI/CD pipeline for a QA/staging environment.&lt;/p&gt;&#xA;&lt;ul&gt;&#xA;&lt;li&gt;Recommended for running in CI/CD&lt;/li&gt;&#xA;&lt;li&gt;Intended to run in a QA / Staging environment which is close to production&lt;/li&gt;&#xA;&lt;li&gt;A superset of Developer CI/CD but with important env / server rules enabled&lt;/li&gt;&#xA;&lt;li&gt;No long running rules&lt;/li&gt;&#xA;&lt;li&gt;No rules with high false positives&lt;/li&gt;&#xA;&lt;li&gt;No timing attacks&lt;/li&gt;&#xA;&lt;li&gt;No informational only rules&lt;/li&gt;&#xA;&lt;li&gt;Minimal overlap&lt;/li&gt;&#xA;&lt;/ul&gt;&#xA;&lt;p&gt;For the list of scan rules included see the &lt;a href=&#34;/alerttags/policy_qa_cicd/&#34;&gt;Alert Tag: POLICY_QA_CICD&lt;/a&gt; page.&lt;/p&gt;</description>
    </item>
    <item>
      <title>QA Standard Policy</title>
      <link>/docs/desktop/addons/scan-policies/policy-qa-std/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/desktop/addons/scan-policies/policy-qa-std/</guid>
      <description>&lt;h1 id=&#34;qa-standard-policy&#34;&gt;QA Standard Policy&lt;/h1&gt;&#xA;&lt;p&gt;A quality assurance focused policy meant to perform fairly quickly while providing a greater set of results than developer policies, intended for use in a QA/staging environment.&lt;/p&gt;&#xA;&lt;ul&gt;&#xA;&lt;li&gt;Intended to run in a QA / Staging environment which is close to production&lt;/li&gt;&#xA;&lt;li&gt;A superset of Developer Standard but with important env / server rules enabled&lt;/li&gt;&#xA;&lt;li&gt;Not env issues that should have been fixed by everyone&lt;/li&gt;&#xA;&lt;/ul&gt;&#xA;&lt;p&gt;For the list of scan rules included see the &lt;a href=&#34;/alerttags/policy_qa_std/&#34;&gt;Alert Tag: POLICY_QA_STD&lt;/a&gt; page.&lt;/p&gt;</description>
    </item>
    <item>
      <title>QA Full Policy</title>
      <link>/docs/desktop/addons/scan-policies/policy-qa-full/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/desktop/addons/scan-policies/policy-qa-full/</guid>
      <description>&lt;h1 id=&#34;qa-full-policy&#34;&gt;QA Full Policy&lt;/h1&gt;&#xA;&lt;p&gt;A quality assurance focused policy, including a superset of the &lt;a href=&#34;/docs/desktop/addons/scan-policies/policy-qa-std/&#34;&gt;QA standard&lt;/a&gt; with a greater variety of potential findings with more environmental/server related rules, intended for use in a QA/Staging environment.&lt;/p&gt;&#xA;&lt;ul&gt;&#xA;&lt;li&gt;Intended to run in a QA / Staging environment which is close to production&lt;/li&gt;&#xA;&lt;li&gt;A superset of Developer Full (and QA Standard) but with more env / server rules enabled&lt;/li&gt;&#xA;&lt;/ul&gt;&#xA;&lt;p&gt;For the list of scan rules included see the &lt;a href=&#34;/alerttags/policy_qa_full/&#34;&gt;Alert Tag: POLICY_QA_FULL&lt;/a&gt; page.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Penetration Tester Policy</title>
      <link>/docs/desktop/addons/scan-policies/policy-pentest/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/desktop/addons/scan-policies/policy-pentest/</guid>
      <description>&lt;h1 id=&#34;penetration-tester-policy&#34;&gt;Penetration Tester Policy&lt;/h1&gt;&#xA;&lt;p&gt;A policy which enables all of the installed active scan rules with the exception of the Example rules.&lt;/p&gt;&#xA;&lt;p&gt;Programmatic Name: &lt;code&gt;Pen Test&lt;/code&gt;&lt;/p&gt;&#xA;&lt;p&gt;Return to &lt;a href=&#34;/docs/desktop/addons/scan-policies/&#34;&gt;main scan policies page&lt;/a&gt;.&lt;/p&gt;</description>
    </item>
  </channel>
</rss>
