This is a bug fix release, along with some minor enhancements.
This release was made possible thanks to Checkmarx who employ 3 of the Core Team to work on ZAP.
These release notes do not include all of the changes included in add-ons updated since 2.16.0.
The enhancements include:
The Script Console no longer includes its own “Script Output” panel. Instead it uses the main Output tab.
The Output tab now supports sub-tabs. The Script Console add-on will add one tab for each script that generates any output, making it much easier to see where output messages come from.
The API now supports plugable Authentication and Session Management methods, which means you can configure modern options like Browser Based Authentication.
Many enhancements have been made to ensure ZAP handles authentication more easily and effectively, including support for TOTP.
ZAP now supports Native Decorations on Windows systems, providing a more unified and visually pleasing experience.
The AJAX Spider no longer counts URLs that are out of scope. This may affect any tests you have in place.
As usual the release includes dependency updates.
The following libraries were updated:
Introduction | the introduction to ZAP | |
Releases | the full set of releases | |
Credits | the people and groups who have made this release possible |