Skip to content

Scan wavsep#246

Merged
thc202 merged 1 commit intozapbot:masterfrom
psiinon:scan/wavsep
Aug 13, 2025
Merged

Scan wavsep#246
thc202 merged 1 commit intozapbot:masterfrom
psiinon:scan/wavsep

Conversation

@psiinon
Copy link
Collaborator

@psiinon psiinon commented Aug 8, 2025

@psiinon
Copy link
Collaborator Author

psiinon commented Aug 8, 2025

Note that this depends on zaproxy/zap-extensions#6640

Copy link
Collaborator

@kingthorin kingthorin left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Just one thing, otherwise seems fine to me.

Comment on lines +46 to +61
run: |
cd zaproxy-website

# Update the index to be sure git is aware of changes
git update-index -q --refresh
## If there are changes: comment, commit, PR
if ! git diff-index --quiet HEAD --; then

git add site/data/scans/wavsep/*
git commit -s -m "Updated WAVSEP Results"
git push origin

echo ${{ secrets.ZAPBOT_TOKEN }} | gh auth login --with-token
gh pr create --fill

fi
Copy link
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

IMHO it should update existing, like: #240 or the Auth tests job.

Copy link
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

But without failing the build.

Copy link
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I wasn't able to come up with a solution to that yet. In the other PR we had agreed to go ahead without that for now.

Not to deter you @psiinon if you see or find a way to do it without failure then go for it.

Copy link
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Yes, but because the other jobs are either disabled or don't raise PRs as often. This one is yet to be seen.

Copy link
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

As for the solution, we could use an action which gives full control on the behaviour, also allows to remove all the duplication (e.g. https://github.com/zaproxy/zaproxy-website/tree/main/.github/actions/update-website).

Copy link
Collaborator Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Can I suggest we leave that to a future PR? 😁
Right now this is only being done on demand, and I suspect we'll need to go through a few itterations before we want to automate it...

@psiinon
Copy link
Collaborator Author

psiinon commented Aug 13, 2025

Just deleted the "old" wavsep scanning files as well

Signed-off-by: Simon Bennetts <psiinon@gmail.com>
@thc202 thc202 merged commit 1d19f4c into zapbot:master Aug 13, 2025
@psiinon
Copy link
Collaborator Author

psiinon commented Aug 13, 2025

And 2 crontab files, 1 of which referenced the old wavsep files. Neither have been used for years!

@thc202
Copy link
Collaborator

thc202 commented Aug 13, 2025

Thank you!

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants