#66 · Enhanced Support for OpenAPI Specs with cURL Examples
We’re excited to announce that our DAST scanner now supports OpenAPI specifications with cURL traffic examples, including those built using extensions like Redocly. This enhancement leverages real-world examples to boost scan quality and simplify your security testing process.
What's new¶
OpenAPI specifications can include cURL traffic examples to demonstrate specific API requests and responses. With this update, our DAST scanner can now parse OpenAPI specs with embedded cURL examples and use them to initiate scans.
We’ve also added support for Redocly, a tool that simplifies creating OpenAPI specs enriched with cURL examples, ensuring seamless integration into your workflows.
How It Works¶
- Prepare Your OpenAPI Spec:
Use tools like Redocly to build your OpenAPI specification, embedding cURL examples to document API behavior and parameters.
-
Upload the Spec to the DAST Scanner:
-
Go to Security Scan and click New Application
- Select REST API
- Upload your OpenAPI spec with cURL examples
3.Run the Scan:
The scanner will parse the OpenAPI spec, leverage the cURL examples for precise API interactions, and begin testing for vulnerabilities!