<?xml version="1.0" encoding="utf-8" standalone="yes"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
  <channel>
    <title>Automation on ZAP</title>
    <link>/successtags/automation/</link>
    <description>Recent content in Automation on ZAP</description>
    <generator>Hugo</generator>
    <language>en-us</language>
    <lastBuildDate>Wed, 06 Dec 2023 00:00:00 +0000</lastBuildDate>
    <atom:link href="/successtags/automation/index.xml" rel="self" type="application/rss+xml" />
    <item>
      <title>Mozilla</title>
      <link>/success/mozilla/</link>
      <pubDate>Wed, 14 Apr 2021 00:00:00 +0000</pubDate>
      <guid>/success/mozilla/</guid>
      <description>&lt;p&gt;ZAP is integral to how Mozilla secures the services powering core Firefox features including Accounts, Addons, and Sync for millions of individuals around the world. We support the  open source development of ZAP, because it helps us ensure the security and privacy of our users keeping the Internet a global, public resource open and accessible to all.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Lombiq</title>
      <link>/success/lombiq/</link>
      <pubDate>Wed, 06 Dec 2023 00:00:00 +0000</pubDate>
      <guid>/success/lombiq/</guid>
      <description>&lt;p&gt;ZAP now automatically scans our ASP.NET Core apps for each code change, and we couldn&amp;rsquo;t be happier with it.&lt;/p&gt;&#xA;&lt;p&gt;We at &lt;a href=&#34;https://lombiq.com/&#34;&gt;Lombiq&lt;/a&gt; provide development, training, hosting, and consulting services for open source .NET-based technologies like the ASP.NET Core web CMS and framework &lt;a href=&#34;https://orchardcore.net/&#34;&gt;Orchard Core&lt;/a&gt;. Our clients include Live Nation Clubs and Theaters, the Smithsonian Institution, and Microsoft itself.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Codific</title>
      <link>/success/codific/</link>
      <pubDate>Wed, 05 Jan 2022 00:00:00 +0000</pubDate>
      <guid>/success/codific/</guid>
      <description>&lt;p&gt;Codific is a developer of secure collaboration tools in Ed Tech, MedTech and HR Tech. Our team of software engineers leverages privacy by design and security by design principles to maximize the security of the applications and the privacy of its users.&lt;/p&gt;&#xA;&lt;p&gt;Codific leverages a security assurance programme for all product development lifecycle. There are many Application Security programmes out there with &lt;a href=&#34;https://codific.com/software-security-with-sammy/&#34;&gt;OWASP SAMM&lt;/a&gt; being by far the simplest of them. SAMM consists of 15 security practices with Secure Deployment and Security Testing amongst them. Both security practices in their higher maturity levels require the use of a dynamic application security testing (DAST) integrated in the CI/CD pipeline. After a time-boxed research into a number of DAST tools we have selected ZAP as our weapon of choice.&lt;/p&gt;</description>
    </item>
    <item>
      <title>we45 and AppSecEngineer</title>
      <link>/success/we45/</link>
      <pubDate>Wed, 11 Aug 2021 00:00:00 +0000</pubDate>
      <guid>/success/we45/</guid>
      <description>&lt;p&gt;We at we45 and our training venture, AppSecEngineer use and train on ZAP extensively. We strongly believe ZAP to be the most programmable DAST tool in its class, regardless of commercial or OSS alternatives.&lt;/p&gt;&#xA;&lt;p&gt;One of the things we do with our clients is to implement continuous DAST scanning as part of their DevSecOps initiatives. Many of our clients run a bevy of automated scans on a periodic basis, triggered through CI tooling with ZAP as the tool. For some of those that have End-to-End Test Automation Scripts with Selenium, Cypress, etc, we set up ZAP to be able to run authenticated, completely automated scanning, which is something we find unique in the DAST space&lt;/p&gt;</description>
    </item>
    <item>
      <title>Orange Business Services</title>
      <link>/success/orange/</link>
      <pubDate>Wed, 21 Jul 2021 00:00:00 +0000</pubDate>
      <guid>/success/orange/</guid>
      <description>&lt;p&gt;At OBS, we strive continually to bring our customers peace of mind with strengthened and reinforced application security.&lt;/p&gt;&#xA;&lt;p&gt;As part of automating our web application and API security, we chose to deploy ZAP as one of our Dynamic Application Security Testing (DAST) technologies. This DevSecOps approach helps our developers and engineering teams to detect vulnerabilities, including the OWASP Top Ten &lt;a href=&#34;https://owasp.org/www-project-top-ten/&#34;&gt;Web&lt;/a&gt; and &lt;a href=&#34;https://owasp.org/www-project-api-security/&#34;&gt;API&lt;/a&gt;, in CI/CD pipelines before releasing our solutions.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Banzai Cloud</title>
      <link>/success/banzaicloud/</link>
      <pubDate>Wed, 14 Apr 2021 00:00:00 +0000</pubDate>
      <guid>/success/banzaicloud/</guid>
      <description>&lt;p&gt;At Banzai Cloud we use our dast-operator which leverages ZAP to run baseline scans against the services we deploy on the K8S cluster. This operator deploys ZAP to the K8S cluster and initiates automated security testing for web applications and APIs based on OpenAPI definitions. Besides the operator responsible for starting the scan against a service, it can prevent opening a vulnerable service to outside. The prevention mechanism is based on the built-in admission controller which is watching the ingress resources. The admission controller checks the backend services of the ingress and makes a decision depending on the result of the ZAP scans.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Motorola Solutions</title>
      <link>/success/motorola/</link>
      <pubDate>Wed, 14 Apr 2021 00:00:00 +0000</pubDate>
      <guid>/success/motorola/</guid>
      <description>&lt;p&gt;Motorola Solutions follows S-SDLC (secure software development lifecycle) best practices for&#xA;our product development. Similarly, these best practices can be found in another OWASP&#xA;project, the &lt;a href=&#34;https://owaspsamm.org/&#34;&gt;Software Assurance Maturity Model&lt;/a&gt;. We build our software development approach&#xA;on the OWASP SAMM, to ensure delivery of secure products, from architecture design to the&#xA;deployment in our own or customer’s infrastructure.&lt;/p&gt;</description>
    </item>
  </channel>
</rss>
