Restructure to TCASVS v5.0.0 (ASVS 5.0.0 format) + repo rename references#35
Conversation
- Migrate 79 requirements across 6 chapters to ASVS 5.0.0 format (132 total) - Add 73 gap-fill requirements for thick-client threat coverage - Create versioned directory layout (1.0/en/) with 0x-prefix file naming - Add Source column to all requirement tables (TASVS vs New) - Add build tooling: parser, JSON/CSV/CycloneDX export, Makefile - Add CI pipeline (.github/workflows/main.yml) - Add full traceability mapping (mappings/mapping_tasvs_to_tcasvs_v1.0.yml) - Archive original TASVS content (archive/1.0-original-tasvs/) - Include MIGRATION-SUMMARY.md with Mermaid diagram and stats
…o refs for OWASP/TCASVS rename - Migrate content to 5.0/ versioned layout with ASVS 5.0.0 formatted chapters (V1-V6) - Update all in-repo references from old www-project slug to OWASP/TCASVS - project.owasp.yaml repositories name/url updated; website field pending Nest relink
|
@matreurai. A few questions/comments please:
|
…tainerized build - Drop the CWE column from all 6 chapters (132 reqs); tables are now | # | Description | Level | Source |. Update parser, CycloneDX export, 5.0/Makefile, CONTRIBUTING, and issue templates accordingly. - Remove utils/Convert-TASVS-Excel (superseded by JSON/CSV/XML/CycloneDX exports). - Add ASVS-aligned document builder image (docker/Dockerfile + run.sh) with pinned fonts, pandoc, and the LaTeX packages eisvogel needs; root Makefile and CI now build inside it so PDF/DOCX/JSON/CSV/XML/CycloneDX generate cleanly. - main.yml: build inside the image, validate on pull_request (release on push only), upload build artifacts. Add image build/publish workflow. - Fix frontispiece license image path; ignore build/dist; force LF on scripts.
|
Thanks @JeffreyShran for the feedback, all three handled in 2da4bf6.
|
There was a problem hiding this comment.
@matreurai we still need a review and potentially a PR for this file from the internal security architecture team
|
||||||||||
Summary
Restructures the standard from the original TASVS layout to ASVS 5.0.0 format and updates all in-repo references for the
OWASP/TCASVSrepository rename.Changes
5.0/layout with ASVS 5.0.0-formatted chapters (V1–V6)5.0/tools/,Makefile,generate-all.sh) — JSON/CSV/CycloneDX/PDF/DOCX5.0/mappings/mapping_tasvs_to_tcasvs_v5.0.0.yml)www-project-…slug toOWASP/TCASVSarchive/1.0-original-tasvs/Notes
project.owasp.yamlwebsite:field is intentionally left on the current page URLpending the OWASP Nest team relinking the project page to
OWASP/TCASVS.Migration details
See
MIGRATION-SUMMARY.md— 79 original requirements mapped, 132 total, 73 gap-fills, 1 dropped.