Skip to content

Feature/lab5#1274

Open
raylduk8 wants to merge 3 commits into
inno-devops-labs:mainfrom
raylduk8:feature/lab5
Open

Feature/lab5#1274
raylduk8 wants to merge 3 commits into
inno-devops-labs:mainfrom
raylduk8:feature/lab5

Conversation

@raylduk8

Copy link
Copy Markdown

Goal

Run DAST (ZAP, both unauthenticated and authenticated) against the running Juice Shop, then run SAST (Semgrep) against its source code.

Changes

  • submissions/lab5.md

Testing

Compare authenticated vs unauthenticated ZAP scans

bash labs/lab5/scripts/[compare_zap.sh](https://vk.com/away.php?to=https%3A%2F%2Fcompare_zap.sh&utf=1) \

  labs/lab5/results/baseline-report.json \

  labs/lab5/results/auth-report.json

SAST with Semgrep severity breakdown

jq '[.results[].extra.severity] | group_by(.) | map({severity: .[0], count: length})' \

  labs/lab5/results/semgrep.json

SAST with Semgrep top 10 rule id by frequency

jq '[.results[].check_id] | group_by(.) | map({rule: .[0], count: length}) |

    sort_by(-.count) | .[:10]' \

  labs/lab5/results/semgrep.json
  • Task 1 — ZAP baseline + auth + 10-20× ratio analysis
  • Task 2 — Semgrep top-10 + triage shortcut
  • Bonus — Correlation table with 1+ confirmed cross-tool finding

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant