We’re moving to a CI/CD pipeline and our annual manual pentest just isn’t cutting it anymore. I’ve been looking at APIsec for continuous API security testing — anyone have hands-on experience with it? How does it fit into a GitHub Actions workflow?
3
It’s designed to run on every PR and catch BOLA and other auth issues that SAST tools miss. The key thing is it’s testing, not runtime monitoring, so you’re finding the vulns before they hit production.