REST API Static Security Testing

REST API Static Security Testing

Vendor: 42Crunch | Key: com.xliic.ci.bamboo-plugin

bamboo server datacenter

Discover all OpenAPI files (YAML or JSON, v2 or v3) in your repository, and have 42Crunch perform static analysis with 200+ various security best practices checks. For each issue, see detailed report for exploit scenario and remediation steps.

View on Marketplace
Versions (7) - Last 1 Year, Server/Data Center Only
Version Build Release Date Compatibility Hosting Status Actions Description
5.1.0 500100001 2025-07-07 Bamboo Data Center 9.6.4 - 11.0.8 datacenter Downloaded Download
Release Notes:
  • It is possible to configure the plugin so that the team permissions in “collections” mode are always applied, even if the team permissions have been previously changed in the Web UI
5.0.0 500000000 2025-06-03 Bamboo Server 9.6.4 - 11.0.2 server Downloaded Download
Release Notes:
  • Adds support for OpenAPI 3.1
  • Adds support for new “Collections” configuration mode in 42c-conf.yaml
3.0.1 300000100 2024-10-18 Bamboo Server 9.6.4 - 10.0.3 server Downloaded Download
Release Notes:
  • Updated dependency on atlassian-spring-scanner-annotation
3.0.0 300000000 2024-10-11 Bamboo Server 9.6.4 - 10.0.3 server Downloaded Download
Release Notes:
  • Add support for Bamboo Data Center
  • Update dependencies used in the plugin
2.12.0 200012000 2024-02-13 Bamboo Server 7.0.6 - 8.2.2 server Downloaded Download
Release Notes:
  • Improve error messages
  • Include Transaction ID in the errors and debug trace
2.11.0 200011000 2023-05-12 Bamboo Server 7.0.6 - 8.2.2 server Downloaded Download
Release Notes:

JSON report now includes additional items:

  • List of deleted APIs
  • Information about collection used for discovered APIs
2.10.0 200010000 2023-03-02 Bamboo Server 7.0.6 - 8.2.2 server Downloaded Download
Release Notes:
  • New tags can be created by the plugin if the tags category permits user to do it
  • Add number of flags to make plugin ignore failures or network errors or to make it to check just the SQG failures