Skip to content
Open
Show file tree
Hide file tree
Changes from all commits
Commits
Show all changes
66 commits
Select commit Hold shift + click to select a range
99428bf
Update MASVS progress (#636)
cpholguera Mar 10, 2022
f3c318c
update progress (#639)
cpholguera Apr 26, 2022
1b3fec3
Feature/issue643 improve spanish translation (#645)
Sulfkain Jun 17, 2022
cb110ec
Add Tusted By section (#648)
cpholguera Jun 22, 2022
a53659a
update progress (#650)
cpholguera Jun 24, 2022
3a8b9e6
Add MSTG Advocates (#651)
cpholguera Jul 4, 2022
c8f6b33
update masvs progress (#657)
cpholguera Aug 17, 2022
3cccbcb
Update Twitter handle to @OWASP_MAS (#659)
cpholguera Aug 27, 2022
486c8e6
Update to MAS and MASTG (#660)
cpholguera Aug 27, 2022
0b4590d
Improve Spanish Translation (#658)
antoniojturel Aug 29, 2022
ee84394
Fix V8 Control Objective Statement (#646)
cpholguera Aug 29, 2022
9124583
Removed (Review) from russian translation
sushi2k Aug 31, 2022
f0fa0b9
Merge pull request #661 from OWASP/fix-review-for-Russian-Translation
sushi2k Aug 31, 2022
d0f22f0
Rename MSTG to MASTG & link to New Website (#662)
cpholguera Sep 1, 2022
99c6939
fix mas links (#664)
cpholguera Sep 1, 2022
3d71e06
update progress (#665)
cpholguera Sep 7, 2022
541daf4
Fix MASVS Website Links (#667)
cpholguera Sep 16, 2022
62def04
fix strings and make bold (#668)
cpholguera Sep 28, 2022
c40aab7
fix link (#669)
cpholguera Oct 2, 2022
ccb184f
Fix Read MASVS Link (#671)
cpholguera Oct 5, 2022
fc612d3
Update Donators (#680)
cpholguera Jan 23, 2023
049d8bd
update for all languages and remove local pic (#681)
cpholguera Jan 23, 2023
253b5d2
point to raw image (#682)
cpholguera Jan 23, 2023
b420f4a
add SDK and preload applicability (#678)
cpholguera Jan 24, 2023
eb7121c
Fix pandocker build for all languages (#674)
cpholguera Jan 27, 2023
f6e2202
Greek Translation (#642)
panosylr Jan 27, 2023
0be0b7b
Turkish translation (#561)
haktanemik Jan 27, 2023
be36c99
Add latest translations to actions and fix authors (#684)
cpholguera Jan 31, 2023
1d5904d
Add tr and gr to README (#687)
cpholguera Jan 31, 2023
00014dd
Fix Farsi Generation (#689)
cpholguera Feb 2, 2023
451bc6c
Add MASVS v2 news (#695)
cpholguera Feb 23, 2023
11279b7
Upgrading to v2.0.0 (#697)
cpholguera Mar 31, 2023
f689bc5
minor fixes (#699)
cpholguera Apr 1, 2023
f72d075
Pre-release fixes (#700)
cpholguera Apr 1, 2023
7306b61
Update docgenerator.yml (#701)
cpholguera Apr 1, 2023
f0b1d91
Fix OWASP_MASVS.yaml name (#702)
cpholguera Apr 1, 2023
f2e668b
fix artifact upload (#703)
cpholguera Apr 1, 2023
1a400eb
add input dir to yaml gen (#705)
cpholguera Apr 1, 2023
15246d9
add input dir to populate (#706)
cpholguera Apr 1, 2023
10cf60c
add controls dir to masvs gen (#707)
cpholguera Apr 1, 2023
52a7e87
fix links to controls (#708)
cpholguera Apr 1, 2023
9d33d87
fix table spacing and width (#709)
cpholguera Apr 1, 2023
7d9c4ed
Added POC script that generates CycloneDX standards doc of MASVS (#715)
stevespringett Jul 6, 2023
2a97099
run python3 (#716)
cpholguera Jul 6, 2023
e971590
Update to CycloneDX v1.6 standards support (#717)
stevespringett Sep 8, 2023
e22ed66
Add MASVS-PRIVACY (#720)
cpholguera Jan 18, 2024
8e133d0
fix README Actions badges (#721)
cpholguera Jan 18, 2024
014a102
Updated donators.png image file (#722)
cpholguera Jan 18, 2024
ef4f364
Add SARIF Taxonomy Support (#727)
cpholguera May 15, 2024
e06adc4
Update pandoc_makedocs.sh (#728)
sushi2k Jun 14, 2024
7bfc627
Update MASVS Cover Color to "MASVS Green" (#730)
cpholguera Jun 29, 2024
da544ec
Update README.md (#731)
cpholguera Jun 29, 2024
4e4e152
minor edit (#732)
cpholguera Jun 29, 2024
07f8664
fix script (#733)
cpholguera Jun 29, 2024
2398230
fix(license): Github identification & add SPDX (#725)
otkd Jun 29, 2024
1aae2cb
ci: update github actions (#724)
Jun 29, 2024
7b05d0f
Update README.md to remove Intro from links (#734)
cpholguera Jul 13, 2024
8cd2cca
Bump actions/download-artifact from v2 to v4 in /.github/workflows (#…
dependabot[bot] Sep 4, 2024
30a85aa
Update README.md (#747)
cpholguera May 28, 2025
decfa19
fix repo names everywhere (#751)
cpholguera Jul 14, 2025
b59484e
Update README to align with other repos (#753)
cpholguera Jul 18, 2025
53cb59a
Add Index to MASVS rather than MASTG (#754)
TheDauntless Jul 19, 2025
2a3731b
Enhance MASVS-RESILIENCE with RASP and platform lock-in clarification…
cpholguera Sep 11, 2025
c0db792
Update MAS Testing Profiles link and description (#760)
cpholguera Sep 26, 2025
a3b7b31
Agregar nueva línea al final del archivo README.md
secrethomefamily-sudo Sep 1, 2026
e1b72ea
Pending changes exported from your codespace
secrethomefamily-sudo Sep 15, 2026
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
The table of contents is too big for display.
Diff view
Diff view
  •  
  •  
  •  
8 changes: 4 additions & 4 deletions .github/workflows/codeql-analysis.yml
Original file line number Diff line number Diff line change
Expand Up @@ -38,11 +38,11 @@ jobs:

steps:
- name: Checkout repository
uses: actions/checkout@v2
uses: actions/checkout@v4

# Initializes the CodeQL tools for scanning.
- name: Initialize CodeQL
uses: github/codeql-action/init@v1
uses: github/codeql-action/init@v2
with:
languages: ${{ matrix.language }}
# If you wish to specify custom queries, you can do so here or in a config file.
Expand All @@ -53,7 +53,7 @@ jobs:
# Autobuild attempts to build any compiled languages (C/C++, C#, or Java).
# If this step fails, then you should remove it and run the build manually (see below)
- name: Autobuild
uses: github/codeql-action/autobuild@v1
uses: github/codeql-action/autobuild@v2

# ℹ️ Command-line programs to run using the OS shell.
# 📚 https://git.io/JvXDl
Expand All @@ -67,4 +67,4 @@ jobs:
# make release

- name: Perform CodeQL Analysis
uses: github/codeql-action/analyze@v1
uses: github/codeql-action/analyze@v2
11 changes: 0 additions & 11 deletions .github/workflows/config/.markdownlint.json

This file was deleted.

18 changes: 0 additions & 18 deletions .github/workflows/config/mlc_config.json

This file was deleted.

21 changes: 21 additions & 0 deletions .github/workflows/config/url-checker-config.json
Original file line number Diff line number Diff line change
@@ -0,0 +1,21 @@
{
"ignorePatterns": [
{
"pattern": "changelog"
}
],
"httpHeaders": [
{
"urls": [
"https://",
"http://"
],
"headers": {
"User-Agent": "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:64.0) Gecko/20100101 Firefox/64.0"
}
}
],
"retryOn429": true,
"fallbackRetryDelay": "30s",
"see": "https://github.com/tcort/markdown-link-check#config-file-format"
}
45 changes: 0 additions & 45 deletions .github/workflows/doc-gen-reusable.yml

This file was deleted.

188 changes: 37 additions & 151 deletions .github/workflows/docgenerator.yml
Original file line number Diff line number Diff line change
@@ -1,170 +1,57 @@
name: Documents Build
name: MASVS Build

on: [push, workflow_dispatch]

jobs:
Generate-MASVS-Documents:
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@v4
with:
fetch-depth: 1

##
## Use `pandocker-tag: TAG=stable-full` for langs that require the special fonts (Russian, Chinese, etc.)
##

en:
uses: OWASP/owasp-masvs/.github/workflows/doc-gen-reusable.yml@master
with:
folder: Document
language: English
lang: en

de:
uses: OWASP/owasp-masvs/.github/workflows/doc-gen-reusable.yml@master
with:
folder: Document-de
language: German
lang: de

es:
uses: OWASP/owasp-masvs/.github/workflows/doc-gen-reusable.yml@master
with:
folder: Document-es
language: Spanish
lang: es

fr:
uses: OWASP/owasp-masvs/.github/workflows/doc-gen-reusable.yml@master
with:
folder: Document-fr
language: French
lang: fr

ptbr:
uses: OWASP/owasp-masvs/.github/workflows/doc-gen-reusable.yml@master
with:
folder: Document-ptbr
language: Brazilian Portuguese
lang: ptbr

ptpt:
uses: OWASP/owasp-masvs/.github/workflows/doc-gen-reusable.yml@master
with:
folder: Document-ptpt
language: Portugal Portuguese
lang: ptpt

hi:
uses: OWASP/owasp-masvs/.github/workflows/doc-gen-reusable.yml@master
with:
folder: Document-hi
language: Hindi
lang: hi
pandocker-tag: TAG=stable-full

ja:
uses: OWASP/owasp-masvs/.github/workflows/doc-gen-reusable.yml@master
with:
folder: Document-ja
language: Japanese
lang: ja
pandocker-tag: TAG=stable-full

ko:
uses: OWASP/owasp-masvs/.github/workflows/doc-gen-reusable.yml@master
with:
folder: Document-ko
language: Korean
lang: ko
pandocker-tag: TAG=stable-full
- name: Set MASVS_VERSION to env
run: echo "MASVS_VERSION=$(curl -s https://api.github.com/repos/OWASP/masvs/tags | jq '.[0].name' | sed 's/\"//g')" >> $GITHUB_ENV

ru:
uses: OWASP/owasp-masvs/.github/workflows/doc-gen-reusable.yml@master
with:
folder: Document-ru
language: Russian
lang: ru
pandocker-tag: TAG=stable-full
- name: Set DEV MASVS_VERSION if it's not a tag
if: ${{ !startsWith(github.ref, 'refs/tags/') }}
run: echo "MASVS_VERSION=${{env.MASVS_VERSION}}-$(git rev-parse --short HEAD)" >> $GITHUB_ENV

fa:
uses: OWASP/owasp-masvs/.github/workflows/doc-gen-reusable.yml@master
with:
folder: Document-fa
language: Persian
lang: fa
pandocker-tag: TAG=stable-full
pandocker-template: LATEX_TEMPLATE=default # there's a bug for fa in the eisvogel template, we have to use default
- name: Get Latest MASTG Release Tag
run: echo "MASTG_VERSION=$(curl -s https://api.github.com/repos/OWASP/mastg/releases/latest | jq '.tag_name' | sed 's/\"//g')" >> $GITHUB_ENV

zhcn:
uses: OWASP/owasp-masvs/.github/workflows/doc-gen-reusable.yml@master
with:
folder: Document-zhcn
language: Simplified Chinese
lang: zhcn
pandocker-tag: TAG=stable-full

zhtw:
uses: OWASP/owasp-masvs/.github/workflows/doc-gen-reusable.yml@master
with:
folder: Document-zhtw
language: Traditional Chinese
lang: zhtw
pandocker-tag: TAG=stable-full

export:
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@v2
with:
fetch-depth: 1
- name: Generate MASVS yaml
run: python3 ./tools/generate_masvs_yaml.py -v ${{ env.MASVS_VERSION }}

# tag name with the latest tag
# and the abbreviated hash of the most recent commit
- name: Set VERSION to env
run: echo "VERSION=$(curl -s https://api.github.com/repos/OWASP/owasp-masvs/tags | jq '.[0].name' | sed 's/\"//g')" >> $GITHUB_ENV
- name: Populate MASVS Categories Markdown Files
run: python3 ./tools/populate_masvs_categories_md.py

- name: Set DEV VERSION if it's not a tag
if: ${{ !startsWith(github.ref, 'refs/tags/') }}
run: echo "VERSION=${{env.VERSION}}-$(git rev-parse --short HEAD)" >> $GITHUB_ENV
- name: Generate PDF and ePub
run: ./tools/docker/pandoc_makedocs.sh Document ${{ env.MASVS_VERSION }} ${{ env.MASTG_VERSION }}

- name: Install pyyaml
run: pip3 install pyyaml
- name: Generate CycloneDX JSON
run: python3 ./tools/generate_masvs_cyclonedx.py

- name: Generate CSV
run: cd tools && python3 export.py --format csv --lang en > OWASP_MASVS-${{env.VERSION}}.csv
- name: Generate JSON
run: cd tools && python3 export.py --format json --lang en > OWASP_MASVS-${{env.VERSION}}.json
- name: Generate XML
run: cd tools && python3 export.py --format xml --lang en > OWASP_MASVS-${{env.VERSION}}.xml
- name: Generate MASVS YAML
run: cd tools && python3 export.py --format yaml --lang en > OWASP_MASVS-${{env.VERSION}}.yaml
- name: Generate SARIF
run: python3 ./tools/generate_masvs_sarif.py

- name: Upload CSV
uses: actions/upload-artifact@v2
with:
name: OWASP_MASVS-${{env.VERSION}}.csv
path: tools/OWASP_MASVS-${{env.VERSION}}.csv
- name: Upload JSON
uses: actions/upload-artifact@v2
with:
name: OWASP_MASVS-${{env.VERSION}}.json
path: tools/OWASP_MASVS-${{env.VERSION}}.json
- name: Upload XML
uses: actions/upload-artifact@v2
with:
name: OWASP_MASVS-${{env.VERSION}}.xml
path: tools/OWASP_MASVS-${{env.VERSION}}.xml
- name: Upload YAML
uses: actions/upload-artifact@v2
- name: Upload Artifacts
uses: actions/upload-artifact@v4
with:
name: OWASP_MASVS-${{env.VERSION}}.yaml
path: tools/OWASP_MASVS-${{env.VERSION}}.yaml
name: OWASP_MASVS
path: OWASP_MASVS*

release:
runs-on: ubuntu-latest
needs: [en, de, fa, es, fr, hi, ja, ko, ptbr, ptpt, ru, zhcn, zhtw, export]
needs: [Generate-MASVS-Documents]
if: startsWith(github.ref, 'refs/tags/') && (github.actor == 'cpholguera' || github.actor == 'sushi2k')
steps:
- uses: actions/download-artifact@v2
- uses: actions/download-artifact@v4
- name: Move all files to the root folder
run: mv OWASP_MASVS*/* .

- name: Move all translations (pdf, epub and docx) to root
run: mv OWASP_MASVS-*-*/* .
- name: Release
uses: softprops/action-gh-release@v1
with:
Expand All @@ -173,11 +60,10 @@ jobs:
generate_release_notes: true
discussion_category_name: Announcements
files: |
OWASP_MASVS-*.pdf
OWASP_MASVS-*.epub
OWASP_MASVS-*.docx
OWASP_MASVS-*.csv/OWASP_MASVS-*.csv
OWASP_MASVS-*.json/OWASP_MASVS-*.json
OWASP_MASVS-*.xml/OWASP_MASVS-*.xml
OWASP_MASVS.pdf
OWASP_MASVS.epub
OWASP_MASVS.yaml
OWASP_MASVS.cdx.json
OWASP_MASVS.sarif
env:
GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }}
Original file line number Diff line number Diff line change
Expand Up @@ -7,12 +7,12 @@ jobs:
runs-on: ubuntu-latest
steps:
- name: Checkout
uses: actions/checkout@v2
uses: actions/checkout@v4
with:
fetch-depth: 1
- name: markdownlint-cli
uses: nosborn/github-action-markdown-cli@v2.0.0
with:
files: './Document*'
config_file: ".github/workflows/config/.markdownlint.json"
config_file: ".markdownlint.jsonc"
ignore_files: "tools, node_modules"
Original file line number Diff line number Diff line change
@@ -1,11 +1,11 @@
name: codespell
name: Spell Checker
on: [pull_request, push]
jobs:
codespell:
spell-check:
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@v2
- uses: actions/checkout@v4
- uses: codespell-project/actions-codespell@master
with:
path: ./Document
ignore_words_list: ba,compliancy,firt,ist,keypair,ligh,ser,synopsys,zuser
ignore_words_list: OWASP,MASVS,MASTG
Loading