grafeas / grafeas/grafeas

Add CWE to Vulnerability kind

Open
#164 8 comments 0 reactions 0 assignees View on GitHub
kind/proposal
Dominant language
Go
Stars
1.6k
Forks
307
PR merge metrics
No merged PRs in 30d

Description

The[ OWASP Top 10 ](https://www.owasp.org/index.php/Category:OWASP_Top_Ten_Project )is one of the most comprehensive documents for the `appsec` vulnerabilities. There is currently little or not support for its integration in security testing tools and secure software development pipelines, despite the benefits this could bring. I raised a discussion about this in these security stack- exchange posts ([1](https://security.stackexchange.com/questions/183668/using-owasp-top-10-for-assigning-vulnerability-severity-in-a-security-assessment/183707?noredirect=1#comment370079_183707) & [2](https://security.stackexchange.com/questions/183668/using-owasp-top-10-for-assigning-vulnerability-severity-in-a-security-assessment/183707?noredirect=1#comment370079_183707)), where I clearly defined some ways through which this could be leveraged. Since grafeas is coming with a security automation objective, the information in the top 10 could be integrated somehow. This would in no small measure assist in assessing the applications that are deployed in containers.

Contributor guide

Open the contributing guide

Research direction

Start by locating the Vulnerability kind definition and reviewing how its existing fields are represented. Reconcile the title's request for CWE with the body’s discussion of OWASP Top 10, then determine the required scope and acceptance criteria before changing the API.

Written by the indexing model from the issue text.

Assessment

Tech stack
go
Domain
api, security
Issue type
Feature
Difficulty
5/5
Estimated time
Over a week
Activity status
Stale
Clarity
Needs clarification
Newbie friendliness
25/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.