Security Regression Testing with ZapAPI and NodeGoat


Details
Kim Carter of BinaryMist (http://binarymist.io/) will provide a whirlwind tour of a Proof of Concept covered in his new book "Holistic Info-Sec for Web Developers (https://leanpub.com/holistic-infosec-for-web-developers/read#process-agile-development-and-practices-security-regression-testing)", that he has since implemented for a large international client.
This hands-on session will show you how to leverage the abilities of the OWASP Zap API to discover many vulnerabilities in your web application as you are creating it, rather than at the end of the project.
This is essentially like having a full time penetration tester on your development team, continuously security regression testing your product as a CI or nightly build as it's being developed. For a very minimal set-up cost.
github source (https://github.com/binarymist/NodeGoat/wiki/Security-Regression-Testing-with-Zap-API)

Security Regression Testing with ZapAPI and NodeGoat