Release 2.15.0

This is a bug fix and enhancement release.
These release notes do not include all of the changes included in add-ons updated since 2.14.0.

This release was made possible thanks to our biggest supporter, the Crash Override.

Some of the more significant enhancements include:

Scripts as First Class Scan Rules

Active and passive scan script rules can now be treated as "first class" scan rules. This means that they can be individually referenced in an active scan policy, in the passive scan rules options, and in Automation Framework plans. In addition directories of scripts can now be added with all of the scripts enabled - this will make it much more straightfoward to manage script rules in automation.

Menu Items Restructured

The desktop context sensitive menu items have been reordered, and grouped in a more logical way. This should make it much easier to find the menu item you want, when you want it.

Set Logging Levels

A new -loglevel Command Line option allows you to set the log level, overriding the values specified in the log4j2.properties file in the home directory.

New API calls also allow you to set and view the current logging levels:

Automation Framework GitHub Action

There is a new ZAP GitHub action - the ZAP Automation Framework Scan. The Automation Framework provides a great balance between ease of use and flexibility + functionality. If you want to perform any non-trivial automation with ZAP then the Automation Framework is probably your best bet.

New Docker Hub Organisation

We have a new DockerHub organisation for the ZAP Docker images: https://hub.docker.com/u/zaproxy We are still using the softwaresecurityproject org for 2.15.0 but we will probably not use it for the following releases. We do recommend that you switch from `softwaresecurityproject` to zaproxy sooner rather than later.

Dependency Updates

As usual the release includes dependency updates.

The following libraries were updated:

Add-Ons

Updated Add-Ons

All of the add-ons included by default have been updated since the last full release.

Enhancements

Bug fixes

See Also

    Introductionthe introduction to ZAP
    Releasesthe full set of releases
    Creditsthe people and groups who have made this release possible