<?xml version="1.0" encoding="utf-8" standalone="yes"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
  <channel>
    <title>Sast on ZAP</title>
    <link>/tags/sast/</link>
    <description>Recent content in Sast on ZAP</description>
    <generator>Hugo</generator>
    <language>en-us</language>
    <lastBuildDate>Wed, 01 Apr 2026 00:00:00 +0000</lastBuildDate>
    <atom:link href="/tags/sast/index.xml" rel="self" type="application/rss+xml" />
    <item>
      <title>OWASP PTK Findings as ZAP Alerts (Juice Shop Walkthrough)</title>
      <link>/blog/2026-04-01-owasp-ptk-findings-to-zap-alerts/</link>
      <pubDate>Wed, 01 Apr 2026 00:00:00 +0000</pubDate>
      <guid>/blog/2026-04-01-owasp-ptk-findings-to-zap-alerts/</guid>
      <description>OWASP PTK 9.8.0 and the ZAP OWASP PTK add-on 0.3.0 now let ZAP display OWASP PTK findings directly as ZAP Alerts. This post shows how to install the add-on, choose which PTK rules to run (SAST / IAST / DAST), optionally auto-start scans on browser launch, and then scan OWASP Juice Shop with all results visible in ZAP.</description>
    </item>
    <item>
      <title>Guided ZAP Scans: Faster CI/CD Feedback Using Static Analysis</title>
      <link>/blog/2026-03-27-guided-zap-scans-faster-cicd-feedback-using-sast/</link>
      <pubDate>Fri, 27 Mar 2026 00:00:00 +0000</pubDate>
      <guid>/blog/2026-03-27-guided-zap-scans-faster-cicd-feedback-using-sast/</guid>
      <description>This post describes an approach that uses static analysis findings to guide ZAP&amp;rsquo;s active scans toward the most relevant endpoints. The result is a faster scanning mode suited for CI/CD pipelines, built on top of ZAP&amp;rsquo;s Automation Framework.</description>
    </item>
    <item>
      <title>OWASP PTK Integration with ZAP</title>
      <link>/blog/2026-01-19-owasp-ptk-add-on/</link>
      <pubDate>Mon, 19 Jan 2026 00:00:00 +0000</pubDate>
      <guid>/blog/2026-01-19-owasp-ptk-add-on/</guid>
      <description>OWASP PTK is now pre-installed in the browsers launched by ZAP (Chrome, Edge and Firefox). This post shows how to run PTK’s DAST, IAST, SAST, and SCA inside the same authenticated session you’re testing, plus practical JWT and cookie workflows—while ZAP remains your traffic and context hub.</description>
    </item>
  </channel>
</rss>
