From 8d3da3f57c09bf2e0f7954af3d17c52818cac250 Mon Sep 17 00:00:00 2001 From: Andrew <56427313+AndrewEhlo@users.noreply.github.com> Date: Fri, 31 May 2024 11:28:15 +0500 Subject: [PATCH] VCST-1107: Use latest zaproxy/action-baseline (#2799) fix: Used latest version of GH action zaproxy/action-baseline, removed docker_name option as by default the action runs the stable version of ZAP. --- .github/workflows/platfotm-owasp.yml | 7 +++---- 1 file changed, 3 insertions(+), 4 deletions(-) diff --git a/.github/workflows/platfotm-owasp.yml b/.github/workflows/platfotm-owasp.yml index 254704bbee5..5cac049aec2 100644 --- a/.github/workflows/platfotm-owasp.yml +++ b/.github/workflows/platfotm-owasp.yml @@ -22,9 +22,9 @@ jobs: uses: VirtoCommerce/vc-github-actions/setup-vcbuild@master - name: Docker Login - uses: azure/docker-login@v1 + uses: docker/login-action@v3 with: - login-server: ghcr.io + registry: ghcr.io username: $GITHUB_ACTOR password: ${{ secrets.GITHUB_TOKEN }} @@ -38,9 +38,8 @@ jobs: validateSwagger: 'false' - name: OWASP ZAP Full Scan - uses: zaproxy/action-baseline@v0.4.0 + uses: zaproxy/action-baseline@v0.12.0 with: token: ${{ secrets.GITHUB_TOKEN }} - docker_name: 'owasp/zap2docker-stable' target: 'http://localhost:8090' cmd_options: '-a -d'