OWASP SonarQube Project

From OWASP
Revision as of 16:17, 11 June 2014 by Kait Disney-Leugers (Talk | contribs)

(diff) ← Older revision | Latest revision (diff) | Newer revision → (diff)
Jump to: navigation, search
[edit]

OWASP Project Header.jpg

OWASP SonarQube Project

OWASP SonarQube is...

Introduction

SonarQube is an open platform to manage code quality. The project consist to deliver a set of "standard" profile for security, like OWASP Top10 profile, ASVS profiles, PCI-DSS profile, ....who can be used by team with the support of owasp

Description

Project will be like the OWASP modsecurity CRS project. Deliver a set of profile who can be recognize by the community as a need for securing their application.

Sponsors :

Advens (Experts on application security) ; allowing time to work on the project

SonarSource (Founder and maintener of SonarQube) ; giving time and expertise to the core of SonarQube


Licensing

OWASP SonarQube Project is free to use. It is licensed under the [ttp://www.apache.org/licenses/LICENSE-2.0 Apache 2.0 license], so you can copy, distribute and transmit the work, and you can adapt it, and use it commercially, but all provided that you attribute the work and if you alter, transform, or build upon this work, you may distribute the resulting work only under the same or similar license to this one.


What is SonarQube?

OWASP SonarQube provides:

  • A set of quality profile (as SonarQube), mapped to security standards.
  • Some new plugins/rules for SonarQube.


Presentation

Project Leader

Sebastien Gioria

Freddy Mallet

Related Projects

Ohloh

Quick Download

Email List

Project Email List

News and Events

In Print

Classifications

New projects.png Owasp-builders-small.png
Owasp-defenders-small.png
Cc-button-y-sa-small.png
Project Type Files CODE.jpg

Q1
A1
Q2
A2

Volunteers

SonarQube is developed by a worldwide team of volunteers. The primary contributors to date have been:

  • xxx
  • xxx

Others

  • xxx
  • xxx

As of June 2014, the priorities are:

We will first deliver on Java langage :

  • Deliver for the beginning of Q4 (October) 2014 a set of profile

directly mapping OWASP Top10 2013 with the standard rules of SonarQube.

  • Deliver for the end of the year 2014 a set of profile mapping

PCI-DSS requirements with the standard rules of SonarQube.

  • Deliver for 2015 profiles for mapping OWASP ASVS level (1,2,3,4).
  • Deliver profile based on Cert Secure Coding and ISO 27034 ASC for 2015

We plan but not having any roadmap to setup and deliver to OWASP project the capacity yo scan their project with the profiles and rules.

Involvement in the development and promotion of SonarQube is actively encouraged! You do not have to be a security expert in order to contribute. Some of the ways you can help:

  • xxx
  • xxx


PROJECT INFO
What does this OWASP project offer you?
RELEASE(S) INFO
What releases are available for this project?
what is this project?
Name: OWASP SonarQube Project
Purpose: SonarQube is an open platform to manage code quality. The project consist to deliver a set of "standard" profile for security, like OWASP Top10 profile, ASVS profiles, PCI-DSS profile,

....who can be used by team with the support of owasp

License: Apache 2.0 license
who is working on this project?
Project Leader(s):
  • Sebastien Gioria and Freddy Mallet @
how can you learn more?
Project Pamphlet: Not Yet Created
Project Presentation:
Mailing list: [owasp_sonarqube@lists.owasp.org Mailing List Archives]
Project Roadmap: Not Yet Created
Key Contacts
  • Contact Sebastien Gioria and Freddy Mallet @ to contribute to this project
  • Contact Sebastien Gioria and Freddy Mallet @ to review or sponsor this project
  • Contact the GPC to report a problem or concern about this project or to update information.
current release
Not Yet Published
last reviewed release
Not Yet Reviewed


other releases