testable-eu / sast-testability-patterns

Testability Pattern Catalogs for SAST
https://owasp.org/www-project-testability-patterns-for-web-applications/
Apache License 2.0
29 stars 2 forks source link

[Patterns] Review all patterns #7

Open compaluca opened 2 years ago

compaluca commented 2 years ago

Goal

Review, mature, extend our SAST testability patterns

Links

Checklist

Please follow the process hereafter for each pattern that you review.

Phase 1: main json file complete?

Phase 2: pattern instances

For each instance in the pattern

2.1: instance is measurable?

2.2: instance is discoverable?

2.3: instance properties

2.4: instance is remediable? (optional)

Phase 3: test with the framework

Phase 4: retrofit your review in the shared excel file

compaluca commented 1 year ago

PHP - Pattern review assignment - 1st and 2nd rounds

Review at least 15 each.

SAP

TUBS

compaluca commented 1 year ago

JS - Pattern review assignment - 1st and 2nd rounds

Review at least 15 each.

CISPA

ECM

@SoheilKhodayari, @ManuManu97 for discovery rules do not hesitate to ping @pr0me

compaluca commented 1 year ago

JAVA - Pattern review assignment - 1st and 2nd rounds

We do not have reliable SAST measurement results, so for the moment we can proceed in the pattern alphabetical name order.

SAP

SHLT

MSEC