diff --git a/.github/workflows/main.yml b/.github/workflows/main.yml new file mode 100644 index 0000000..80a7a70 --- /dev/null +++ b/.github/workflows/main.yml @@ -0,0 +1,41 @@ +# This is a basic workflow to help you get started with Actions + +name: CI + +# Controls when the workflow will run +on: + # Triggers the workflow on push or pull request events but only for the master branch + push: + branches: [ master ] + pull_request: + branches: [ master ] + + # Allows you to run this workflow manually from the Actions tab + workflow_dispatch: + +# A workflow run is made up of one or more jobs that can run sequentially or in parallel +jobs: + # This workflow contains a single job called "build" + build: + # The type of runner that the job will run on + runs-on: ubuntu-latest + + # Steps represent a sequence of tasks that will be executed as part of the job + steps: + - uses: actions/checkout@v2 + - name: Set up JDK 11 + uses: actions/setup-java@v2 + with: + java-version: '11' + distribution: 'adopt' + - name: maven build + run: mvn clean install + - name: maven deploy + run: mvn spring-boot:run & + + # Checks-out your repository under $GITHUB_WORKSPACE, so your job can access it + - name: ZAP Scan + uses: zaproxy/action-full-scan@v0.3.0 + with: + target: 'http://localhost:8080/login' + cmd_options: '-n zapconfig.context' diff --git a/zapconfig.context b/zapconfig.context new file mode 100644 index 0000000..5f91e85 --- /dev/null +++ b/zapconfig.context @@ -0,0 +1,78 @@ + + + + Default Context + + true + http://localhost:8080.* + + Db + Db.CouchDB + Db.Firebird + Db.HypersonicSQL + Db.IBM DB2 + Db.Microsoft Access + Db.Microsoft SQL Server + Db.MongoDB + Db.MySQL + Db.Oracle + Db.PostgreSQL + Db.SAP MaxDB + Db.SQLite + Db.Sybase + Language + Language.ASP + Language.C + Language.JSP/Servlet + Language.Java + Language.JavaScript + Language.PHP + Language.Python + Language.Ruby + Language.XML + OS + OS.Linux + OS.MacOS + OS.Windows + SCM + SCM.Git + SCM.SVN + WS + WS.Apache + WS.IIS + WS.Tomcat + + + org.zaproxy.zap.model.StandardParameterParser + {"kvps":"&","kvs":"=","struct":[]} + + + org.zaproxy.zap.model.StandardParameterParser + {"kvps":"&","kvs":"=","struct":[]} + + + 2 +
+ http://localhost:8080/perform-login + username={%username%}&password={%password%} + http://localhost:8080/perform-login +
+
+ + 14;true;YnJ1Y2U=;2;YnJ1Y2U=~d2F5bmU=~ + + 14 + + 0 + + + 0 + +
+ + AND + -1 + + + +