diff options
| author | Craig Jennings <c@cjennings.net> | 2026-05-22 14:38:16 -0500 |
|---|---|---|
| committer | Craig Jennings <c@cjennings.net> | 2026-05-22 14:38:16 -0500 |
| commit | 9480b424cb5069ace4979a9efd49a983c5526481 (patch) | |
| tree | 19b0ab2c610e3718ec707bf034eaa50825539073 /pairwise-tests | |
| parent | 5f9b72d8311ff1b197ebdc5cff88255863bba15c (diff) | |
| download | rulesets-9480b424cb5069ace4979a9efd49a983c5526481.tar.gz rulesets-9480b424cb5069ace4979a9efd49a983c5526481.zip | |
docs(commands): update security-check to OWASP 2021 + scanner tooling
Two audit fixes to the OWASP review. It now maps each finding to an OWASP Top 10 2021 category or a WSTG area, adding the four that were missing (Insecure Design, Software and Data Integrity Failures, Security Logging and Monitoring Failures, SSRF) with explicit checks for object and function-level authorization, SSRF URL fetches, update and dependency integrity, and logging gaps. A new optional-scanners step adds gitleaks/trufflehog, semgrep, OSV, and lockfile-diff review, with a network caveat: a scan that can't run reports "not run", never a silent pass.
Diffstat (limited to 'pairwise-tests')
0 files changed, 0 insertions, 0 deletions
