Rename the ASVS framework to OWASP ASVS 5.0.0 everywhere it states the current version - #185
Open
emmanuelgjr wants to merge 1 commit into
Open
emmanuelgjr wants to merge 1 commit into
emmanuelgjr wants to merge 1 commit into
Conversation
…e current version #123 translated all three ASVS mapping files to 5.0.0 identifiers, but the framework kept the name "OWASP ASVS 4.0.3" in titles, README tables, the registry, the generator/grammar/report keys, and so in every export and the webapp. 5.0.0 is the latest versioned release; ASVS's `latest` tag is its Bleeding Edge build. - 26 counted replacements across 17 hand-written files (script asserts each count): ASVS file titles, intro links and references; "14 chapters" -> 17 (V1–V17 in 5.0.0); README + de/es/ja; RATIONALE; llms.txt; ai-standards-crosswalk page; LLM_AITG reference; keys in generate.js, control-ids.js, compliance-report.js; owasp-asvs.json and framework-sources.json names. - incidents.json: six control_failures from #183 (INC-138/139/140/ 145/146/147) cite 5.0.0 ids under the old name (V1.2.4 SQLi, V1.3.2 eval, V1.3.6 SSRF, V1.5 deserialization, checked against 0x10-V1-Encoding-and-Sanitization.md at v5.0.0_release); label fixed. - Regenerated entries, backlinks and webapp bundles: line-for-line label swaps, stats.json unchanged. - Kept at 4.0.3 on purpose: CHANGELOG history, the translation report, the 24 retained-row markers, and docs/classifier-predictions.js (an April classifier snapshot whose ids are 4.0.3 chapters). - CHANGELOG: "Changed" entry, since export consumers filtering by framework name must update the string. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
This branch has not been deployed
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Maintainer request: "update everything to the latest ASVS".
Latest ASVS = 5.0.0 (
v5.0.0_release, 2025-05-30). ASVS's newerlatesttag (2026-09-03) is its Bleeding Edge development build, not a versioned release. Mapping against it would go stale with no version number to show it.#123 already translated all three ASVS mapping files to 5.0.0 identifiers. What was left was the framework's name: "OWASP ASVS 4.0.3" was still the key in the generator, the id grammar and the compliance report, so it showed up in every export, the registry, the webapp, the README and the file titles.
Changes
*_ASVS.mdfiles: title, intro link, references, and "14 chapters" → 17. 5.0.0 runs V1–V17, checked against the release tree.README.mdand itsde/es/jatranslations,RATIONALE.md,docs/llms.txt, theai-standards-crosswalkpage, and a reference inLLM_AITG.md.generate.js,control-ids.jsandcompliance-report.js.owasp-asvs.jsonandframework-sources.json.incidents.json: sixcontrol_failuresfrom incidents: add INC-138..INC-147 — ten GenAI tooling CVEs (LMDeploy, vLLM, SQLBot, Contentful MCP) #183 were already on 5.0.0 ids under the old name. INC-145/146V1.2.4(SQL injection), INC-140V1.3.2(eval), INC-147V1.3.6(SSRF), INC-138/139V1.5(Safe Deserialization). All checked against0x10-V1-Encoding-and-Sanitization.mdatv5.0.0_release. In 4.0.3, V1 is Architecture, so the rename corrects these rather than relabelling them.stats.jsonis unchanged: no mapping, count or id moved.Changedentry, because anyone filtering exports by framework name has to update the string.Kept at 4.0.3, on purpose
docs/classifier-predictions.js(33 ASVS predictions)V5.3Output Encoding). Relabelling would be false. The webapp joins predictions onentry::framework, so these 4.0.3 suggestions stop appearing next to the 5.0.0 mappings, which is correct. Regenerating needs the Python classifier.docs/ASVS_4_TO_5_TRANSLATION.md, theSCHEMA_V2_MIGRATION.mdexample, the datedCOMPETITIVE_ANALYSIS.mdrow, avalidate.jscommentAlso visible: the gitignored compliance report is now written as
owasp-asvs-5-0-0-gap-assessment.md.C2: the label changes on the webapp (bundles and the standards page) are text, not structure, made on this request.
Verified on this head
main) / 328 passedstats:checkcurrentgenerate.jsrun produces no drift🤖 Generated with Claude Code