This container allows you to run dynamic application security tests. Uses Sec-helpers package from DAST Sec-helpers
Two arguments are required to run this container:
frontend or apiTypically this container would run as a custom build step in a Cloud Build pipeline after deploying it to Google App Engine.
- name: 'vwtdigital/cloudbuilder-dast'
args: ['api.example.com', 'api']
docker run -ti cloudbuilder-dast api.example.com api
You can also replace the domain name with a file containing the domain name. The domain should be visible with the following Regex search: .*url: \"(.*)/\\*\".*:
- url: "{domain}.{tld}/*"
If the domain name that is passed ends with appspot.*, it will force a pass for the TLS version test. Other domain name configurations will result in normal exit code behaviour.
Content type
Image
Digest
Size
1.1 GB
Last updated
over 5 years ago
docker pull vwtdigital/cloudbuilder-dast