StackHawk announces native dynamic application and API security testing for GitHub
StackHawk’s DAST solution spots vulnerabilities within developers' GitHub projects
StackHawk has announced a dynamic application and API security testing (DAST) solution for GitHub, an industry-first.
The application security testing firm has integrated its proprietary DAST software with GitHub code scanning.
Code Scanning, one of GitHub's Advanced Security features, helps developers pinpoint security vulnerabilities and coding errors. The addition of StackHawk’s DAST solution to CodeScanning will enable engineering teams to test running applications, services, and APIs “for the same vulnerabilities an attacker would exploit, with results available directly in GitHub.”
Vulnerabilities may include SQL injection, cross-site scripting (XSS), cross-site request forgery (CSRF), and more. Built on zed attack proxy (ZAP), StackHawk also offers fixes for securing findings.
"GitHub is the central tool for developers and engineering teams," says Joni Klippert, founder and CEO of StackHawk.
"We built StackHawk to bring application and API security testing into the hands of developers. Our integration with GitHub Advanced Security simply furthers this mission, making it easier for teams to efficiently deliver secure applications."
StackHawk can be used alongside GitHub’s native security tools, including CodeQL for semantic code analysis and Dependabot for software composition analysis (SCA), among other third-party SAST and SCA offerings.
Sign up today and you will receive a free copy of our Future Focus 2026 report - the leading resource for IT decision-maker insight on priorities and investment areas in AI, security and more.
RELATED RESOURCE
DevOps: A view from the enterprise
What's driving DevOps, the impact of value stream management, and more
“DAST has long been a leading method of testing for potential vulnerabilities. By executing security tests against the running application and services, this form of testing surfaces exploitable vulnerabilities in the same way an attacker or security researcher would uncover them. With the advent of DevOps, however, DAST tools have not kept pace with the speed of modern software delivery. StackHawk has revolutionized DAST, bringing this proven security testing approach to CI/CD automation and developer workflows,” added StackHawk.
-
AI is shrinking attack windows, and it’s forcing a complete rethink of cyber resilience – here’s how organizations can prepareNews Commvault has urged companies to improve their business continuity and resilience plans in the face of flaws spotted by AI
-
Anthropic targets vulnerability detection gains with Claude Security public beta — here's what users can expectNews The Claude Mythos developer is aiming for a more limited approach to cyber tooling for public consumption
-
Researchers warn millions of RDP and VNC servers are wide open to exploitationNews Researchers at Forescout spotted millions of RDP and VNC servers exposed online
-
Brace yourselves for a vulnerability explosion, Forescout warnsNews AI advances are helping identify software flaws at record pace and scale, but that's not the good news some would think
-
Ubuntu vulnerability exposes enterprises to root escalation, complete system compromiseNews The high-severity Ubuntu vulnerability allows an unprivileged local attacker to escalate privileges through the interaction of two standard system components
-
Security agencies issue warning over critical Cisco Catalyst SD-WAN vulnerabilityNews Threat actors have been exploiting the vulnerability to achieve root access since 2023
-
Millions of developers could be impacted by flaws in Visual Studio Code extensions – here's what you need to know and how to protect yourselfNews The VS Code vulnerabilities highlight broader IDE security risks, said OX Security
-
CVEs are set to top 50,000 this year, marking a record high – here’s how CISOs and security teams can prepare for a looming onslaughtNews While the CVE figures might be daunting, they won't all be relevant to your organization

