Approach for updating upstream DAST Scanner

Problem to solve

As users run the DAST scanner they run into various bugs, problems or limitations. Since DAST relies on an open source tool, ZAP, which is maintained outside of GitLab, we are left trying to evaluate the best way to solve the problem. We have not yet defined a strategy on how to approach these problems and when we should use each approach. We should develop some guidance as to when we implement one of the solutions below.

  1. Open an upstream MR for the project.
  2. Monkey patch the project.
  3. Leave the issue unresolved or provide a workaround
Edited Nov 19, 2019 by Seth Berger
Assignee Loading
Time tracking Loading