Skip to content

Use Browser-based DAST as scanner name and remove ZAP for FIPS mode

Michael Eddington requested to merge 407822-scanner-name-fips into main

What does this MR do?

Makes two main changes to what scanner information we include in the DAST security report.

  1. Use Browser-based DAST instead of Browserker. Browserker is an internal term that should not be customer facing.
  2. When FIPS mode is detected, don't include ZAP in the scanner name or ID field.

What are the relevant issue numbers?

https://gitlab.com/gitlab-org/gitlab/-/issues/407822+

GitLab Docs MR

Edited by Michael Eddington

Merge request reports