Software Engineering Radio - the podcast for professional software developers

SE Radio 568: Simon Bennetts on OWASP Dynamic Application Security Testing Tool ZAP

06.14.2023 - By [email protected]Play

Download our free app to listen on your phone

Download on the App StoreGet it on Google Play

Simon Bennetts, a distinguished engineer at Jit, discusses one of the flagship projects of OWASP: the Zed Attack Proxy (ZAP) open source security testing tool. As ZAP’s primary maintainer, Simon traces the tool's origins and shares some anecdotes with SE Radio host Priyanka Raghavan on why there was a need for it. They take a deep dive into ZAP’s features and its ability to integrate with CI/CD, as well as shift security left. Bennetts also considers what it takes to build a successful open source project before spending time on ZAP’s ability to script to provide richer results. Finally, the conversation ends with some questions on ZAP’s future in this AI-powered world of bots.

More episodes from Software Engineering Radio - the podcast for professional software developers