Skip to content

add action for vulnerability testing #1635

@tomkralidis

Description

@tomkralidis

Penetration testing on a pygeoapi instance would be a valuable testing mechanism in a DevSecOps context.

Zed Attack Proxy (ZAP) could be a viable option, given it provides this functionality as GitHub Actions:

We should also consider the OWASP API Security Top 10.

The result would be a GitHub Action (.github/workflows/security.yml) that would run some/all of the above.

Metadata

Metadata

Assignees

Labels

Type

No type

Projects

No projects

Milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions