SE Radio 568: Simon Bennetts on OWASP Dynamic Application Security Testing Tool ZAP

Published: June 14, 2023, 8:29 p.m.

Simon Bennetts, a distinguished engineer at Jit, discusses one of the flagship projects of OWASP: the Zed Attack Proxy (ZAP) open source security testing tool. As ZAP\u2019s primary maintainer, Simon traces the tool's origins and shares some anecdotes with SE Radio host Priyanka Raghavan on why there was a need for it. They take a deep dive into ZAP\u2019s features and its ability to integrate with CI/CD, as well as shift security left. Bennetts also considers what it takes to build a successful open source project before spending time on ZAP\u2019s ability to script to provide richer results. Finally, the conversation ends with some questions on ZAP\u2019s future in this AI-powered world of bots.