In this chapter, we looked at how to use ZAP, which is a tool developed by the OWASP community to automate the execution of web application security tests. And we also saw how Postman can provide information on API performance.
In the next chapter, we will continue to talk about security and DevSecOps with the automation of infrastructure testing with Inspec, secret protection with Hashicorp's Vault, and the Secure DevOps Kit for Azure for checking the security compliance of Azure infrastructures.