Sign inSign up

vwtdigital/cloudbuilder-dast

By vwtdigital

•Updated over 5 years ago

Image
1

1.2K

vwtdigital/cloudbuilder-dast repository overview

⁠Cloudbuilder-DAST

This container allows you to run dynamic application security tests. Uses Sec-helpers package⁠ from DAST Sec-helpers⁠

⁠Prerequisites

  1. A deployed and running https service

⁠Usage

Two arguments are required to run this container:

  1. a domain name, without http:// or https:// (e.g. domain.tld)
  2. type of service, frontend or api

Typically this container would run as a custom build step in a Cloud Build pipeline after deploying it to Google App Engine.

- name: 'vwtdigital/cloudbuilder-dast'
  args: ['api.example.com', 'api']
docker run -ti cloudbuilder-dast api.example.com api

You can also replace the domain name with a file containing the domain name. The domain should be visible with the following Regex search: .*url: \"(.*)/\\*\".*:

- url: "{domain}.{tld}/*"
⁠Special usage TLS version test:

If the domain name that is passed ends with appspot.*, it will force a pass for the TLS version test. Other domain name configurations will result in normal exit code behaviour.

Tag summary

Content type

Image

Digest

Size

1.1 GB

Last updated

over 5 years ago

docker pull vwtdigital/cloudbuilder-dast