Skip to content

[1.01] Fix broken ASVS links, stale 1.0 text, and 1.01 credits - #1155

Merged
jmanico merged 2 commits into
mainfrom
1.01-links-and-stale-text
Sep 18, 2026
Merged

jmanico merged 2 commits into
mainfrom
1.01-links-and-stale-text

Conversation

@jmanico

@jmanico jmanico commented Sep 18, 2026 •

Copy link
Copy Markdown
Member

Patch-level fixes only under RELEASE.md: broken links, editorial text, credits. No requirement text or level changes.

Broken ASVS links

owasp.org moved project pages to /projects/<slug>. The old ASVS URL https://owasp.org/www-project-application-security-verification-standard/ now redirects to a page that returns 404. Repointed five occurrences to https://owasp.org/projects/asvs: three in Using AISVS, one in the Appendix B references, one in the README. The other owasp.org links in the repo still redirect correctly and are left alone.

Appendix B rows behind the 1.01 text

  • C10.2.7 row read "No pass-through of client access tokens to downstream APIs". The requirement now reads:

    Verify that MCP servers only accept tokens explicitly issued for them.

    Row is now "MCP servers accept only tokens explicitly issued for them".

  • C9.2.1 row read "privileged, high-impact, or irreversible actions". Clarify C9.2 reversibility approval wording #1095 removed "high-impact" from the requirement; the row now matches.

Stale version strings in 1.01-dev

  • Preface: "version 1.0" is now "version 1.01".
  • Using AISVS: "Each requirement in AISVS v1.0 is assigned" is now version-agnostic so it cannot drift again.
  • Frontispiece acknowledgments: "AISVS v1.0 is the result" is now v1.01.

Frontispiece credits

Added the authors of merged 1.01 changes under the names their profiles show: Amine Khazraj (#1127, C10.4.10), Iman (#1121, C11.3.5), MRX (#1153, Appendix B). Removed the link for Khalid Al-Amri because the GitHub account no longer exists; the name is kept.

Not added: the author of #1095 is an AI-agent account operated by another GitHub user, and the PR did not disclose that. How agent-submitted work is credited is a lead decision, so it is left out of this patch PR.

README and CONTRIBUTING

  • README said the wiki covers "191 requirements across 60 pages" while linking the 1.01-dev wiki, which documents 197. Reworded without counts, stated that the wiki tracks the in-progress 1.01 release, and linked the frozen 1.0/research wiki for readers of the released standard.
  • CONTRIBUTING said the project "accepts patch-level fixes for the released 1.0 content", which contradicts LOCKED.md and RELEASE.md. It now says all work lands in 1.01-dev/. The translations note no longer says "after v1.0 is released" and asks contributors to open an issue first, which is the open question on trans: Add Panjabi (pa-IN) translation of AISVS 1.0 #1128. The "What is the AISVS" heading now links the OWASP project page instead of the site docs repository.

Checks

markdownlint and cspell pass locally on all six changed files; four contributor name tokens were added to the custom dictionary. Requirement count is unchanged at 197 and Appendix B still references every requirement exactly once.

🤖 Generated with Claude Code

jmanico and others added 2 commits September 18, 2026 06:05
Patch-level only: no requirement text or level changes.

- Repoint five ASVS links: owasp.org moved project pages to /projects/
  and the old URL now ends in a 404. New target is
  https://owasp.org/projects/asvs.
- Align two Appendix B rows with the 1.01 text of C10.2.7 and C9.2.1.
- Replace three leftover "version 1.0" strings in the Preface, Using
  AISVS, and Frontispiece.
- Credit the merged 1.01 authors in the Frontispiece and drop the link
  for a GitHub account that no longer exists.
- README: stop quoting a requirement count that drifts, say the wiki
  tracks 1.01-dev, and link the frozen 1.0 wiki.
- CONTRIBUTING: patch fixes land in 1.01-dev, not the locked 1.0
  folder; refresh the translations note; link the OWASP project page.
- Add the new contributor name tokens to the cspell dictionary.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
Use "Iman" as the profile shows instead of a surname inferred from the
handle, and leave out the AI-agent account behind #1095 until the leads
decide how agent-submitted work is credited.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
@jmanico
jmanico merged commit d84a780 into main Sep 18, 2026
5 checks passed
@jmanico
jmanico deleted the 1.01-links-and-stale-text branch September 18, 2026 15:01
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant