Skip to content

Rename the ASVS framework to OWASP ASVS 5.0.0 everywhere it states the current version - #185

Open
emmanuelgjr wants to merge 1 commit into
mainfrom
fix/asvs-5.0.0-identity
Open

emmanuelgjr wants to merge 1 commit into
mainfrom
fix/asvs-5.0.0-identity

Conversation

@emmanuelgjr

Copy link
Copy Markdown
Contributor

Maintainer request: "update everything to the latest ASVS".

Latest ASVS = 5.0.0 (v5.0.0_release, 2025-05-30). ASVS's newer latest tag (2026-09-03) is its Bleeding Edge development build, not a versioned release. Mapping against it would go stale with no version number to show it.

#123 already translated all three ASVS mapping files to 5.0.0 identifiers. What was left was the framework's name: "OWASP ASVS 4.0.3" was still the key in the generator, the id grammar and the compliance report, so it showed up in every export, the registry, the webapp, the README and the file titles.

Changes

  • 26 counted replacements across 17 hand-written files. The script asserts each count before writing:
    • The three *_ASVS.md files: title, intro link, references, and "14 chapters" → 17. 5.0.0 runs V1–V17, checked against the release tree.
    • README.md and its de/es/ja translations, RATIONALE.md, docs/llms.txt, the ai-standards-crosswalk page, and a reference in LLM_AITG.md.
    • The keys in generate.js, control-ids.js and compliance-report.js.
    • The names in owasp-asvs.json and framework-sources.json.
  • incidents.json: six control_failures from incidents: add INC-138..INC-147 — ten GenAI tooling CVEs (LMDeploy, vLLM, SQLBot, Contentful MCP) #183 were already on 5.0.0 ids under the old name. INC-145/146 V1.2.4 (SQL injection), INC-140 V1.3.2 (eval), INC-147 V1.3.6 (SSRF), INC-138/139 V1.5 (Safe Deserialization). All checked against 0x10-V1-Encoding-and-Sanitization.md at v5.0.0_release. In 4.0.3, V1 is Architecture, so the rename corrects these rather than relabelling them.
  • Regenerated entries, backlinks and the webapp bundles. Every file is a line-for-line swap, and stats.json is unchanged: no mapping, count or id moved.
  • CHANGELOG: a Changed entry, because anyone filtering exports by framework name has to update the string.

Kept at 4.0.3, on purpose

What Why
The 24 rows whose requirement 5.0.0 deleted No 5.0.0 successor exists. They keep their 4.0.3 id and DRAFT marker naming the official disposition (#123).
docs/classifier-predictions.js (33 ASVS predictions) A dated 2026-04-09 classifier snapshot whose ids are 4.0.3 chapters (e.g. V5.3 Output Encoding). Relabelling would be false. The webapp joins predictions on entry::framework, so these 4.0.3 suggestions stop appearing next to the 5.0.0 mappings, which is correct. Regenerating needs the Python classifier.
CHANGELOG history, docs/ASVS_4_TO_5_TRANSLATION.md, the SCHEMA_V2_MIGRATION.md example, the dated COMPETITIVE_ANALYSIS.md row, a validate.js comment Accurate history.

Also visible: the gitignored compliance report is now written as owasp-asvs-5-0-0-gap-assessment.md.

C2: the label changes on the webapp (bundles and the standards page) are text, not structure, made on this request.

Verified on this head

  • validate: 0 errors / 93 warnings (same as main) / 328 passed
  • stats:check current
  • unit tests 89/89, including the webapp route walk
  • markdownlint-cli2 0.13.0: 0 errors
  • a second generate.js run produces no drift

🤖 Generated with Claude Code

…e current version

#123 translated all three ASVS mapping files to 5.0.0 identifiers, but
the framework kept the name "OWASP ASVS 4.0.3" in titles, README tables,
the registry, the generator/grammar/report keys, and so in every export
and the webapp. 5.0.0 is the latest versioned release; ASVS's `latest`
tag is its Bleeding Edge build.

- 26 counted replacements across 17 hand-written files (script asserts
  each count): ASVS file titles, intro links and references; "14
  chapters" -> 17 (V1–V17 in 5.0.0); README + de/es/ja; RATIONALE;
  llms.txt; ai-standards-crosswalk page; LLM_AITG reference; keys in
  generate.js, control-ids.js, compliance-report.js; owasp-asvs.json and
  framework-sources.json names.
- incidents.json: six control_failures from #183 (INC-138/139/140/
  145/146/147) cite 5.0.0 ids under the old name (V1.2.4 SQLi, V1.3.2
  eval, V1.3.6 SSRF, V1.5 deserialization, checked against
  0x10-V1-Encoding-and-Sanitization.md at v5.0.0_release); label fixed.
- Regenerated entries, backlinks and webapp bundles: line-for-line label
  swaps, stats.json unchanged.
- Kept at 4.0.3 on purpose: CHANGELOG history, the translation report,
  the 24 retained-row markers, and docs/classifier-predictions.js (an
  April classifier snapshot whose ids are 4.0.3 chapters).
- CHANGELOG: "Changed" entry, since export consumers filtering by
  framework name must update the string.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant