spring-projects / spring-projects/spring-security
SEC-2345: Run OWASP Zap against Spring Security
Open
Nobody has claimed this yet.
type: jira
type: task
- Dominant language
- Java
- Stars
- 9.6k
- Forks
- 6.3k
- Avg merge
- 2d 11h
- Merged PRs (30d)
- 52
Description
Rob Winch (Migrated from SEC-2345) said:
https://www.owasp.org/index.php/OWASP_Zed_Attack_Proxy_Project
Contributor guide
First steps
- Read the whole issue, then the project's contributing guide.
- Comment on the issue to say you are picking it up — it saves two people doing the same work.
- Fork the repository and make your change on a branch.
- Open a pull request that references the issue number.
Research direction
No files, tests, or entry points are identified. Start with the linked OWASP ZAP project and the Spring Security repository, then confirm with maintainers which application or configuration should be scanned and what report or changes would count as done.
Written by the indexing model from the issue text.
Assessment
- Tech stack
- java, spring
- Domain
- security
- Issue type
- Feature
- Difficulty
- 4/5
- Estimated time
- 3-5 days
- Activity status
- Stale
- Clarity
- Needs clarification
- Newbie friendliness
- 20/100