Hi Board and Leaders,
I'm pleased to announce that I received the final penetration testing retest report over the weekend. There are two minor issues remaining to be fixed (a bump in one of the libraries and a minor CSP tweak once the app is on the
owasp.org domain), but otherwise, the site has a clean bill of health from a security standpoint.
The progress now becomes how do we launch the site? I'm going to restore the database prior to the penetration testing so that any changes made there will be reverted and to clean up any stray testing artefacts.
After that, the main thing remaining is for OWASP leaders to log in to the website and take control of their pages. To avoid overwriting the folks who have already done the right thing and updated their pages on the new site, we won't be re-scraping the old website and replacing all their hard work. As a result, for some chapters and projects, the information might be blank. As part of our previous migration from the Wiki to the current website, we need OWASP Leaders to take the lead in ensuring their pages are up to date.
If you don't have a new website login yet, please submit a Jira ticket at
https://contact.owasp.org, and we'll get you sorted.
I've created a new ticket type here for this:
The system currently sends emails that Google sometimes flags as spam. Please check your spam folder if you're expecting a password reset email.
thanks,
Andrew van der Stock
Distinguished Lifetime Member
Executive Director, OWASP