Skip to content

Refresh DAST OWASP Top 10 2025 coverage mapping#315

Closed
x0tta6bl4-ai wants to merge 1 commit into
UnitOneAI:mainfrom
x0tta6bl4-ai:improve/dast-top10-2025-coverage-207
Closed

Refresh DAST OWASP Top 10 2025 coverage mapping#315
x0tta6bl4-ai wants to merge 1 commit into
UnitOneAI:mainfrom
x0tta6bl4-ai:improve/dast-top10-2025-coverage-207

Conversation

@x0tta6bl4-ai

Copy link
Copy Markdown

Summary

  • Refreshes dast-config from OWASP Top 10:2021 to OWASP Top 10:2025.
  • Adds framework-version preflight, source/retrieval date, DAST tool/version, scan environment, and legacy-baseline handling.
  • Adds per-category coverage status values so DAST-only evidence is not overclaimed for A03 supply chain, A06 design, A08 integrity, or A09 logging/alerting.
  • Adds A10:2025 exceptional-condition test planning for malformed state, fail-open authn/authz, error paths, retry/timeout, and downstream failure behavior.
  • Adds benign and vulnerable fixtures for current 2025 mapping versus stale 2021 output.

Bounty

Verification

  • git diff --check
  • Markdown fence balance check for touched markdown files
  • Frontmatter delimiter check for skills/devsecops/dast-config/SKILL.md
  • Link checks returned HTTP 200 for OWASP Top 10:2025 introduction, OWASP Top 10 project, WSTG v4.2, and ZAP Automation Framework

Sources

Bounty Terms

  • I have read and agree to the CONTRIBUTING.md bounty terms.

@x0tta6bl4-ai x0tta6bl4-ai force-pushed the improve/dast-top10-2025-coverage-207 branch from 72d5d59 to e5db7d3 Compare June 3, 2026 11:56
@kamalsrini

Copy link
Copy Markdown
Contributor

Thanks for contributing to SecuritySkills, and for your interest in the project 🙏

We're resetting the contribution queue, so we're closing the currently open PRs — this isn't a reflection of your work, and you're welcome to resubmit.

When you do, please include evidence that the skill was actually used: the skill run against a real repository, with the findings it produced. That's how we recognize genuinely useful contributions, and it's where strong work stands out. The PR template lays out exactly what to include: https://github.com/UnitOneAI/SecuritySkills/blob/main/.github/PULL_REQUEST_TEMPLATE.md

@kamalsrini kamalsrini closed this Jun 15, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

[REVIEW] dast-config: refresh OWASP Top 10:2025 coverage mapping

2 participants