Skip to content
Merged
Show file tree
Hide file tree
Changes from 1 commit
Commits
Show all changes
31 commits
Select commit Hold shift + click to select a range
1379283
Move zapConfig into a yaml multi-line section
J12934 Jun 25, 2021
c7ef2e0
Rename scan example files so that they appear on the docs page
J12934 Jun 25, 2021
5a80e9c
Refactored the complete documentation to generate more target specifi…
rfelber Jun 26, 2021
daec523
Updating Helm Docs
Jun 26, 2021
48f5684
Fixed old demo path
rfelber Jun 26, 2021
70e6591
Updating Helm Docs
Jun 26, 2021
a37b572
Bugfixing
rfelber Jun 27, 2021
b017ae6
Updating Helm Docs
Jun 27, 2021
b26d2df
Added operator docs
rfelber Jun 28, 2021
f2cc9b6
Updating Helm Docs
Jun 28, 2021
0ea4f5a
Merge branch 'main' into documentation/documentation-improvements
rfelber Jun 28, 2021
75c0d2a
Fixing the supportet docker image version to prevent errors
rfelber Jun 28, 2021
5fc78ec
Updating Helm Docs
Jun 28, 2021
b55538b
Refactoring the name to be more descriptive
rfelber Jun 28, 2021
15c413a
Added DockerHub Description Update
rfelber Jun 28, 2021
b75be91
Fixing wrong username
rfelber Jun 28, 2021
4851c2a
Fixing wrong path to description readme
rfelber Jun 28, 2021
4d767a9
Trying to fix credentials issue due to https://github.com/peter-evans…
rfelber Jun 28, 2021
9203302
Trying to fix DockerHub Access
rfelber Jun 28, 2021
d7bd539
Fix Version number of Third Party Scanner
rfelber Jun 28, 2021
8dfceaa
Fixing the version number of all Custom Scanner
rfelber Jun 28, 2021
f3baaee
Updating Helm Docs
Jun 28, 2021
f4c973e
Merge branch 'main' into documentation/documentation-improvements
rfelber Jun 28, 2021
26d75c3
Updated CI Pipeline to update all involved
rfelber Jun 28, 2021
452b9c0
Fixed zap readme because it was to long for dockerhub
rfelber Jun 28, 2021
d2a7c9a
Updating Helm Docs
Jun 28, 2021
953173f
Updated Supported Versions
rfelber Jun 28, 2021
b9e4aa9
Added some notes with steps to ensure
rfelber Jun 28, 2021
80c1a1c
Removed missleading licence hint
rfelber Jul 2, 2021
f4bd374
Updating Helm Docs
Jul 2, 2021
077086a
Merge branch 'main' into documentation/documentation-improvements
rfelber Jul 2, 2021
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
Prev Previous commit
Next Next commit
Fixed old demo path
Signed-off-by: Robert Seedorff <Robert.Seedorff@iteratec.com>
  • Loading branch information
rfelber committed Jun 28, 2021
commit 48f568475aced57af2b8ab9027dee948ae7b714e
3 changes: 2 additions & 1 deletion .helm-docs/README.md.gotmpl
Original file line number Diff line number Diff line change
Expand Up @@ -3,9 +3,10 @@ SPDX-FileCopyrightText: 2020 iteratec GmbH

SPDX-License-Identifier: Apache-2.0
*/ -}}
{{ template "extra.hintSection" . }}
{{ template "extra.docsSection" . }}

{{ template "extra.hintSection" . }}

{{ template "extra.badgesSection" . }}

{{ template "extra.chartAboutSection" . }}
Expand Down
2 changes: 1 addition & 1 deletion demo-targets/.helm-docs.gotmpl
Original file line number Diff line number Diff line change
Expand Up @@ -26,7 +26,7 @@ usecase: "Vulnerable WebApp based on html serverside rendering"

### Source Code

* <https://github.com/secureCodeBox/secureCodeBox/tree/master/demo-apps/bodgeit>
* <https://github.com/secureCodeBox/secureCodeBox/tree/master/demo-targets/bodgeit>
* <https://github.com/psiinon/bodgeit>

{{- end }}
Expand Down
2 changes: 1 addition & 1 deletion demo-targets/bodgeit/.helm-docs.gotmpl
Original file line number Diff line number Diff line change
Expand Up @@ -30,7 +30,7 @@ BodgeIt Store is a serverside rendering based html website without any heavy jav

### Source Code

* <https://github.com/secureCodeBox/secureCodeBox/tree/master/demo-apps/bodgeit>
* <https://github.com/secureCodeBox/secureCodeBox/tree/master/demo-targets/bodgeit>
* <https://github.com/psiinon/bodgeit>

{{- end }}
Expand Down
2 changes: 1 addition & 1 deletion demo-targets/bodgeit/README.md
Original file line number Diff line number Diff line change
Expand Up @@ -40,7 +40,7 @@ BodgeIt Store is a serverside rendering based html website without any heavy jav

### Source Code

* <https://github.com/secureCodeBox/secureCodeBox/tree/master/demo-apps/bodgeit>
* <https://github.com/secureCodeBox/secureCodeBox/tree/master/demo-targets/bodgeit>
* <https://github.com/psiinon/bodgeit>

## Deployment
Expand Down
2 changes: 1 addition & 1 deletion demo-targets/bodgeit/docs/README.ArtifactHub.md
Original file line number Diff line number Diff line change
Expand Up @@ -48,7 +48,7 @@ BodgeIt Store is a serverside rendering based html website without any heavy jav

### Source Code

* <https://github.com/secureCodeBox/secureCodeBox/tree/master/demo-apps/bodgeit>
* <https://github.com/secureCodeBox/secureCodeBox/tree/master/demo-targets/bodgeit>
* <https://github.com/psiinon/bodgeit>

## Deployment
Expand Down
2 changes: 1 addition & 1 deletion demo-targets/bodgeit/docs/README.DockerHub-Target.md
Original file line number Diff line number Diff line change
Expand Up @@ -59,7 +59,7 @@ BodgeIt Store is a serverside rendering based html website without any heavy jav

### Source Code

* <https://github.com/secureCodeBox/secureCodeBox/tree/master/demo-apps/bodgeit>
* <https://github.com/secureCodeBox/secureCodeBox/tree/master/demo-targets/bodgeit>
* <https://github.com/psiinon/bodgeit>

## Community
Expand Down
4 changes: 1 addition & 3 deletions demo-targets/dummy-ssh/.helm-docs.gotmpl
Original file line number Diff line number Diff line change
Expand Up @@ -32,11 +32,9 @@ There are also vulnerable credentials which can be identified via bruteforcing:
- Username root,
- Password: THEPASSWORDYOUCREATED

**Homepage:** <https://github.com/psiinon/bodgeit>

### Source Code

* <https://github.com/secureCodeBox/secureCodeBox/tree/master/demo-apps/dummy-ssh>
* <https://github.com/secureCodeBox/secureCodeBox/tree/master/demo-targets/dummy-ssh>

{{- end }}

Expand Down
2 changes: 1 addition & 1 deletion demo-targets/dummy-ssh/README.md
Original file line number Diff line number Diff line change
Expand Up @@ -46,7 +46,7 @@ There are also vulnerable credentials which can be identified via bruteforcing:

### Source Code

* <https://github.com/secureCodeBox/secureCodeBox/tree/master/demo-apps/dummy-ssh>
* <https://github.com/secureCodeBox/secureCodeBox/tree/master/demo-targets/dummy-ssh>

## Deployment
The dummy-ssh `scanType` can be deployed via helm:
Expand Down
2 changes: 1 addition & 1 deletion demo-targets/dummy-ssh/docs/README.ArtifactHub.md
Original file line number Diff line number Diff line change
Expand Up @@ -54,7 +54,7 @@ There are also vulnerable credentials which can be identified via bruteforcing:

### Source Code

* <https://github.com/secureCodeBox/secureCodeBox/tree/master/demo-apps/dummy-ssh>
* <https://github.com/secureCodeBox/secureCodeBox/tree/master/demo-targets/dummy-ssh>

## Deployment
The dummy-ssh `scanType` can be deployed via helm:
Expand Down
2 changes: 1 addition & 1 deletion demo-targets/dummy-ssh/docs/README.DockerHub-Target.md
Original file line number Diff line number Diff line change
Expand Up @@ -65,7 +65,7 @@ There are also vulnerable credentials which can be identified via bruteforcing:

### Source Code

* <https://github.com/secureCodeBox/secureCodeBox/tree/master/demo-apps/dummy-ssh>
* <https://github.com/secureCodeBox/secureCodeBox/tree/master/demo-targets/dummy-ssh>

## Community

Expand Down
2 changes: 1 addition & 1 deletion demo-targets/http-webhook/.helm-docs.gotmpl
Original file line number Diff line number Diff line change
Expand Up @@ -28,7 +28,7 @@ A Dummy webserver to echo HTTP requests in log.
### Source Code

* <https://github.com/mendhak/docker-http-https-echo>
* <https://github.com/secureCodeBox/secureCodeBox/tree/master/demo-apps/http-webhook>
* <https://github.com/secureCodeBox/secureCodeBox/tree/master/demo-targets/http-webhook>

{{- end }}

Expand Down
2 changes: 1 addition & 1 deletion demo-targets/http-webhook/README.md
Original file line number Diff line number Diff line change
Expand Up @@ -38,7 +38,7 @@ A Dummy webserver to echo HTTP requests in log.
### Source Code

* <https://github.com/mendhak/docker-http-https-echo>
* <https://github.com/secureCodeBox/secureCodeBox/tree/master/demo-apps/http-webhook>
* <https://github.com/secureCodeBox/secureCodeBox/tree/master/demo-targets/http-webhook>

## Deployment
The http-webhook `scanType` can be deployed via helm:
Expand Down
2 changes: 1 addition & 1 deletion demo-targets/http-webhook/docs/README.ArtifactHub.md
Original file line number Diff line number Diff line change
Expand Up @@ -46,7 +46,7 @@ A Dummy webserver to echo HTTP requests in log.
### Source Code

* <https://github.com/mendhak/docker-http-https-echo>
* <https://github.com/secureCodeBox/secureCodeBox/tree/master/demo-apps/http-webhook>
* <https://github.com/secureCodeBox/secureCodeBox/tree/master/demo-targets/http-webhook>

## Deployment
The http-webhook `scanType` can be deployed via helm:
Expand Down
2 changes: 1 addition & 1 deletion demo-targets/http-webhook/docs/README.DockerHub-Target.md
Original file line number Diff line number Diff line change
Expand Up @@ -57,7 +57,7 @@ A Dummy webserver to echo HTTP requests in log.
### Source Code

* <https://github.com/mendhak/docker-http-https-echo>
* <https://github.com/secureCodeBox/secureCodeBox/tree/master/demo-apps/http-webhook>
* <https://github.com/secureCodeBox/secureCodeBox/tree/master/demo-targets/http-webhook>

## Community

Expand Down
2 changes: 1 addition & 1 deletion demo-targets/juice-shop/.helm-docs.gotmpl
Original file line number Diff line number Diff line change
Expand Up @@ -30,7 +30,7 @@ OWASP Juice Shop: Probably the most modern and sophisticated insecure web applic

### Source Code

* <https://github.com/secureCodeBox/secureCodeBox/tree/master/demo-apps/juice-shop>
* <https://github.com/secureCodeBox/secureCodeBox/tree/master/demo-targets/juice-shop>
* <https://github.com/bkimminich/juice-shop>

{{- end }}
Expand Down
2 changes: 1 addition & 1 deletion demo-targets/juice-shop/README.md
Original file line number Diff line number Diff line change
Expand Up @@ -40,7 +40,7 @@ OWASP Juice Shop: Probably the most modern and sophisticated insecure web applic

### Source Code

* <https://github.com/secureCodeBox/secureCodeBox/tree/master/demo-apps/juice-shop>
* <https://github.com/secureCodeBox/secureCodeBox/tree/master/demo-targets/juice-shop>
* <https://github.com/bkimminich/juice-shop>

## Deployment
Expand Down
2 changes: 1 addition & 1 deletion demo-targets/juice-shop/docs/README.ArtifactHub.md
Original file line number Diff line number Diff line change
Expand Up @@ -48,7 +48,7 @@ OWASP Juice Shop: Probably the most modern and sophisticated insecure web applic

### Source Code

* <https://github.com/secureCodeBox/secureCodeBox/tree/master/demo-apps/juice-shop>
* <https://github.com/secureCodeBox/secureCodeBox/tree/master/demo-targets/juice-shop>
* <https://github.com/bkimminich/juice-shop>

## Deployment
Expand Down
2 changes: 1 addition & 1 deletion demo-targets/juice-shop/docs/README.DockerHub-Target.md
Original file line number Diff line number Diff line change
Expand Up @@ -59,7 +59,7 @@ OWASP Juice Shop: Probably the most modern and sophisticated insecure web applic

### Source Code

* <https://github.com/secureCodeBox/secureCodeBox/tree/master/demo-apps/juice-shop>
* <https://github.com/secureCodeBox/secureCodeBox/tree/master/demo-targets/juice-shop>
* <https://github.com/bkimminich/juice-shop>

## Community
Expand Down
2 changes: 1 addition & 1 deletion demo-targets/old-wordpress/.helm-docs.gotmpl
Original file line number Diff line number Diff line change
Expand Up @@ -28,7 +28,7 @@ Insecure & Outdated WordPress Instance: Never expose it to the internet!

### Source Code

* <https://github.com/secureCodeBox/secureCodeBox/tree/master/demo-apps/old-wordpress>
* <https://github.com/secureCodeBox/secureCodeBox/tree/master/demo-targets/old-wordpress>

{{- end }}

Expand Down
2 changes: 1 addition & 1 deletion demo-targets/old-wordpress/README.md
Original file line number Diff line number Diff line change
Expand Up @@ -38,7 +38,7 @@ Insecure & Outdated WordPress Instance: Never expose it to the internet!

### Source Code

* <https://github.com/secureCodeBox/secureCodeBox/tree/master/demo-apps/old-wordpress>
* <https://github.com/secureCodeBox/secureCodeBox/tree/master/demo-targets/old-wordpress>

## Deployment
The old-wordpress `scanType` can be deployed via helm:
Expand Down
2 changes: 1 addition & 1 deletion demo-targets/old-wordpress/docs/README.ArtifactHub.md
Original file line number Diff line number Diff line change
Expand Up @@ -46,7 +46,7 @@ Insecure & Outdated WordPress Instance: Never expose it to the internet!

### Source Code

* <https://github.com/secureCodeBox/secureCodeBox/tree/master/demo-apps/old-wordpress>
* <https://github.com/secureCodeBox/secureCodeBox/tree/master/demo-targets/old-wordpress>

## Deployment
The old-wordpress `scanType` can be deployed via helm:
Expand Down
2 changes: 1 addition & 1 deletion demo-targets/old-wordpress/docs/README.DockerHub-Target.md
Original file line number Diff line number Diff line change
Expand Up @@ -57,7 +57,7 @@ Insecure & Outdated WordPress Instance: Never expose it to the internet!

### Source Code

* <https://github.com/secureCodeBox/secureCodeBox/tree/master/demo-apps/old-wordpress>
* <https://github.com/secureCodeBox/secureCodeBox/tree/master/demo-targets/old-wordpress>

## Community

Expand Down
2 changes: 1 addition & 1 deletion demo-targets/swagger-petstore/.helm-docs.gotmpl
Original file line number Diff line number Diff line change
Expand Up @@ -28,7 +28,7 @@ This is the sample petstore application with a restful API.

### Source Code

* <https://github.com/secureCodeBox/secureCodeBox/tree/master/demo-apps/swagger-petstore>
* <https://github.com/secureCodeBox/secureCodeBox/tree/master/demo-targets/swagger-petstore>
* <https://github.com/swagger-api/swagger-petstore>

{{- end }}
Expand Down
2 changes: 1 addition & 1 deletion demo-targets/swagger-petstore/README.md
Original file line number Diff line number Diff line change
Expand Up @@ -38,7 +38,7 @@ This is the sample petstore application with a restful API.

### Source Code

* <https://github.com/secureCodeBox/secureCodeBox/tree/master/demo-apps/swagger-petstore>
* <https://github.com/secureCodeBox/secureCodeBox/tree/master/demo-targets/swagger-petstore>
* <https://github.com/swagger-api/swagger-petstore>

## Deployment
Expand Down
2 changes: 1 addition & 1 deletion demo-targets/swagger-petstore/docs/README.ArtifactHub.md
Original file line number Diff line number Diff line change
Expand Up @@ -46,7 +46,7 @@ This is the sample petstore application with a restful API.

### Source Code

* <https://github.com/secureCodeBox/secureCodeBox/tree/master/demo-apps/swagger-petstore>
* <https://github.com/secureCodeBox/secureCodeBox/tree/master/demo-targets/swagger-petstore>
* <https://github.com/swagger-api/swagger-petstore>

## Deployment
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -57,7 +57,7 @@ This is the sample petstore application with a restful API.

### Source Code

* <https://github.com/secureCodeBox/secureCodeBox/tree/master/demo-apps/swagger-petstore>
* <https://github.com/secureCodeBox/secureCodeBox/tree/master/demo-targets/swagger-petstore>
* <https://github.com/swagger-api/swagger-petstore>

## Community
Expand Down
2 changes: 1 addition & 1 deletion demo-targets/unsafe-https/.helm-docs.gotmpl
Original file line number Diff line number Diff line change
Expand Up @@ -30,7 +30,7 @@ which contains both private and public key and is not authorized by a third part

### Source Code

* <https://github.com/secureCodeBox/secureCodeBox/tree/master/demo-apps/unsafe-https>
* <https://github.com/secureCodeBox/secureCodeBox/tree/master/demo-targets/unsafe-https>

{{- end }}

Expand Down
2 changes: 1 addition & 1 deletion demo-targets/unsafe-https/README.md
Original file line number Diff line number Diff line change
Expand Up @@ -40,7 +40,7 @@ which contains both private and public key and is not authorized by a third part

### Source Code

* <https://github.com/secureCodeBox/secureCodeBox/tree/master/demo-apps/unsafe-https>
* <https://github.com/secureCodeBox/secureCodeBox/tree/master/demo-targets/unsafe-https>

## Deployment
The unsafe-https `scanType` can be deployed via helm:
Expand Down
2 changes: 1 addition & 1 deletion demo-targets/unsafe-https/docs/README.ArtifactHub.md
Original file line number Diff line number Diff line change
Expand Up @@ -48,7 +48,7 @@ which contains both private and public key and is not authorized by a third part

### Source Code

* <https://github.com/secureCodeBox/secureCodeBox/tree/master/demo-apps/unsafe-https>
* <https://github.com/secureCodeBox/secureCodeBox/tree/master/demo-targets/unsafe-https>

## Deployment
The unsafe-https `scanType` can be deployed via helm:
Expand Down
2 changes: 1 addition & 1 deletion demo-targets/unsafe-https/docs/README.DockerHub-Target.md
Original file line number Diff line number Diff line change
Expand Up @@ -59,7 +59,7 @@ which contains both private and public key and is not authorized by a third part

### Source Code

* <https://github.com/secureCodeBox/secureCodeBox/tree/master/demo-apps/unsafe-https>
* <https://github.com/secureCodeBox/secureCodeBox/tree/master/demo-targets/unsafe-https>

## Community

Expand Down
4 changes: 2 additions & 2 deletions hooks/persistence-defectdojo/.helm-docs.gotmpl
Original file line number Diff line number Diff line change
Expand Up @@ -100,7 +100,7 @@ spec:
scanType: "zap-full-scan"
parameters:
- "-t"
- "http://juice-shop.demo-apps.svc:3000"
- "http://juice-shop.demo-targets.svc:3000"
```

### Complete Example Scan
Expand Down Expand Up @@ -132,7 +132,7 @@ spec:
scanType: "zap-full-scan"
parameters:
- "-t"
- "http://juice-shop.demo-apps.svc:3000"
- "http://juice-shop.demo-targets.svc:3000"
```
{{- end }}

Expand Down
4 changes: 2 additions & 2 deletions hooks/persistence-defectdojo/README.md
Original file line number Diff line number Diff line change
Expand Up @@ -118,7 +118,7 @@ spec:
scanType: "zap-full-scan"
parameters:
- "-t"
- "http://juice-shop.demo-apps.svc:3000"
- "http://juice-shop.demo-targets.svc:3000"
```

### Complete Example Scan
Expand Down Expand Up @@ -150,7 +150,7 @@ spec:
scanType: "zap-full-scan"
parameters:
- "-t"
- "http://juice-shop.demo-apps.svc:3000"
- "http://juice-shop.demo-targets.svc:3000"
```

## Values
Expand Down
4 changes: 2 additions & 2 deletions hooks/persistence-defectdojo/docs/README.ArtifactHub.md
Original file line number Diff line number Diff line change
Expand Up @@ -142,7 +142,7 @@ spec:
scanType: "zap-full-scan"
parameters:
- "-t"
- "http://juice-shop.demo-apps.svc:3000"
- "http://juice-shop.demo-targets.svc:3000"
```

### Complete Example Scan
Expand Down Expand Up @@ -174,7 +174,7 @@ spec:
scanType: "zap-full-scan"
parameters:
- "-t"
- "http://juice-shop.demo-apps.svc:3000"
- "http://juice-shop.demo-targets.svc:3000"
```

## Values
Expand Down
2 changes: 1 addition & 1 deletion scanners/zap-advanced/.helm-docs.gotmpl
Original file line number Diff line number Diff line change
Expand Up @@ -114,7 +114,7 @@ If you want to configure the `api` scan, `spider` or active 'scan` section it is
```

## ZAP Configuration
The following YAMl gives you an overview about all the different configuration options you have to configure the ZAP advanced scan. Please have a look into our `./examples/...` to find some working examples. We provide a list of working examples to scan our `demo-apps` with the `zap-advanced-scan`.
The following YAMl gives you an overview about all the different configuration options you have to configure the ZAP advanced scan. Please have a look into our `./examples/...` to find some working examples. We provide a list of working examples to scan our `demo-targets` with the `zap-advanced-scan`.

:::note

Expand Down
2 changes: 1 addition & 1 deletion scanners/zap-advanced/README.md
Original file line number Diff line number Diff line change
Expand Up @@ -128,7 +128,7 @@ If you want to configure the `api` scan, `spider` or active 'scan` section it is
```

## ZAP Configuration
The following YAMl gives you an overview about all the different configuration options you have to configure the ZAP advanced scan. Please have a look into our `./examples/...` to find some working examples. We provide a list of working examples to scan our `demo-apps` with the `zap-advanced-scan`.
The following YAMl gives you an overview about all the different configuration options you have to configure the ZAP advanced scan. Please have a look into our `./examples/...` to find some working examples. We provide a list of working examples to scan our `demo-targets` with the `zap-advanced-scan`.

:::note

Expand Down
2 changes: 1 addition & 1 deletion scanners/zap-advanced/docs/README.ArtifactHub.md
Original file line number Diff line number Diff line change
Expand Up @@ -134,7 +134,7 @@ If you want to configure the `api` scan, `spider` or active 'scan` section it is
```

## ZAP Configuration
The following YAMl gives you an overview about all the different configuration options you have to configure the ZAP advanced scan. Please have a look into our `./examples/...` to find some working examples. We provide a list of working examples to scan our `demo-apps` with the `zap-advanced-scan`.
The following YAMl gives you an overview about all the different configuration options you have to configure the ZAP advanced scan. Please have a look into our `./examples/...` to find some working examples. We provide a list of working examples to scan our `demo-targets` with the `zap-advanced-scan`.

:::note

Expand Down
2 changes: 1 addition & 1 deletion scanners/zap-advanced/docs/README.DockerHub-Scanner.md
Original file line number Diff line number Diff line change
Expand Up @@ -137,7 +137,7 @@ If you want to configure the `api` scan, `spider` or active 'scan` section it is
```

## ZAP Configuration
The following YAMl gives you an overview about all the different configuration options you have to configure the ZAP advanced scan. Please have a look into our `./examples/...` to find some working examples. We provide a list of working examples to scan our `demo-apps` with the `zap-advanced-scan`.
The following YAMl gives you an overview about all the different configuration options you have to configure the ZAP advanced scan. Please have a look into our `./examples/...` to find some working examples. We provide a list of working examples to scan our `demo-targets` with the `zap-advanced-scan`.

:::note

Expand Down