[go: up one dir, main page]

Skip to content

Include OWASP 2021 mapping to sast-rules

Based on discussion &10970 (comment 1636001776)

Creating this issue to include the OWASP 2021 mappings as well to sast-rules as they are current categories mentioned in https://owasp.org/www-project-top-ten/

Various rules under https://semgrep.dev/p/owasp-top-ten is already having 2021 mapping supported, though GitLab produces and releases our own ruleset.

Example rule from Semgrep: https://semgrep.dev/playground/r/csharp.dotnet.security.audit.ldap-injection.ldap-injection?editorMode=advanced Screenshot_2024-01-17_at_5.37.05_PM

Edited by Connor Gilbert