Replace ZAP with auth-enabled fork
A few months ago, we have forked zapproxy to enable authentication before running the zap spider. It seems a new project is doing exactly the same: https://github.com/ICTU/zap-baseline. Since we don't have enough resources to maintain our fork, I suggest switching to that version instead. This customized version also enables active scans, so it might be exactly what we need.