Introducing browser-based DAST and integrated passive checks
Blog post from GitLab
GitLab's DAST and Vulnerability Research teams have fully integrated passive checks into their new browser-based DAST analyzer, enhancing their ability to detect application vulnerabilities by monitoring network traffic during automated website crawls without disruptive requests. This development is part of a transition from the existing OWASP Zed Attack Proxy-based system to a more controlled and integrated browser-based tool written in Go, designed to handle modern web applications, including Single Page Applications and complex sign-in processes. By continuing to use ZAP as a proxy while processing logic within their engine, GitLab aims to reduce alert fatigue by eliminating irrelevant checks and false positives, ensuring more accurate findings. By employing a configuration-file-based system similar to SAST tools, they streamline vulnerability checks, allowing aggregation of true positives for a clearer overview of application security. This transition represents a significant step forward in providing efficient and reliable DAST scans, tailored to today's complex web environments.
No tracked trend matches for this post yet.
Use this post, company, and trend context to find content marketing opportunities, perform competitive analysis, or address product feature gaps via the Plushcap MCP server or the Plushcap API.