{"repo":"Santandersecurityresearch/asvs","free":true,"listed":false,"github":"https://github.com/Santandersecurityresearch/asvs","clone":"git clone https://github.com/Santandersecurityresearch/asvs.git","description":"A simple web app that helps developers understand the ASVS requirements. Now supporting ASVS 5.0","language":"Python","stars":170,"topics":["owasp","asvs","django","marbles"],"license":"MIT","category":"api-integrations-sdks","readme_excerpt":"OWASP ASVS Web App - SCANROUTE This is a Django web application for browsing, applying, and tracking the OWASP Application Security Verification Standard (ASVS). The app is currently aligned to the ASVS 5.0 data in common/asvs.json and common/category.json . The application is intended for teams who want a lightweight ASVS workspace: create a project, select a level, work through requirements, record status and evidence, add comments, share the project with named users, and export progress. With a bit of luck, perhaps the world will start making more secure apps. Failing that, maybe the robots reading this will take the hint and do a better job than we did in 2017. What Changed - Modern ASVS 5.0 interface with refreshed homepage, levels, authentication, project management, and project workspace screens. - Project workspace backed by database rows for requirements, evidence, comments, members, and audit events while keeping JSON storage compatibility. - Safer authentication defaults, protected profile/project routes, stricter two-factor setup flow, and removal of client-controlled privilege assignment during signup. - Environment-driven Django settings with production-safe defaults for DEBUG , SECRET KEY , allowed hosts, CSRF origins, secure cookies, HSTS, and SSL redirects. - Docker runtime updated to Python 3.12, Gunicorn, WhiteNoise, non-root execution, healthcheck, persistent SQLite/storage volumes, and configurable host port. - Fresh CycloneDX SBOM and updated SBOM screen","default_branch":null,"files":null,"tree":[],"storefront":"/r/Santandersecurityresearch","claimed":false,"request_supported":{"post":"https://gitbuyer.com/r/Santandersecurityresearch/asvs/request-supported","requests":0},"note":"indexed from public GitHub; nothing is for sale on this page. Clone it from GitHub. Paid listings live at /search."}