Repository navigation
[1.01] Fix broken ASVS links, stale 1.0 text, and 1.01 credits - #1155
Merged
Merged
Conversation
Patch-level only: no requirement text or level changes. - Repoint five ASVS links: owasp.org moved project pages to /projects/ and the old URL now ends in a 404. New target is https://owasp.org/projects/asvs. - Align two Appendix B rows with the 1.01 text of C10.2.7 and C9.2.1. - Replace three leftover "version 1.0" strings in the Preface, Using AISVS, and Frontispiece. - Credit the merged 1.01 authors in the Frontispiece and drop the link for a GitHub account that no longer exists. - README: stop quoting a requirement count that drifts, say the wiki tracks 1.01-dev, and link the frozen 1.0 wiki. - CONTRIBUTING: patch fixes land in 1.01-dev, not the locked 1.0 folder; refresh the translations note; link the OWASP project page. - Add the new contributor name tokens to the cspell dictionary. Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
Use "Iman" as the profile shows instead of a surname inferred from the handle, and leave out the AI-agent account behind #1095 until the leads decide how agent-submitted work is credited. Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Patch-level fixes only under RELEASE.md: broken links, editorial text, credits. No requirement text or level changes.
Broken ASVS links
owasp.org moved project pages to
/projects/<slug>. The old ASVS URLhttps://owasp.org/www-project-application-security-verification-standard/now redirects to a page that returns 404. Repointed five occurrences tohttps://owasp.org/projects/asvs: three in Using AISVS, one in the Appendix B references, one in the README. The other owasp.org links in the repo still redirect correctly and are left alone.Appendix B rows behind the 1.01 text
C10.2.7 row read "No pass-through of client access tokens to downstream APIs". The requirement now reads:
Row is now "MCP servers accept only tokens explicitly issued for them".
C9.2.1 row read "privileged, high-impact, or irreversible actions". Clarify C9.2 reversibility approval wording #1095 removed "high-impact" from the requirement; the row now matches.
Stale version strings in 1.01-dev
Frontispiece credits
Added the authors of merged 1.01 changes under the names their profiles show: Amine Khazraj (#1127, C10.4.10), Iman (#1121, C11.3.5), MRX (#1153, Appendix B). Removed the link for Khalid Al-Amri because the GitHub account no longer exists; the name is kept.
Not added: the author of #1095 is an AI-agent account operated by another GitHub user, and the PR did not disclose that. How agent-submitted work is credited is a lead decision, so it is left out of this patch PR.
README and CONTRIBUTING
1.0/researchwiki for readers of the released standard.1.01-dev/. The translations note no longer says "after v1.0 is released" and asks contributors to open an issue first, which is the open question on trans: Add Panjabi (pa-IN) translation of AISVS 1.0 #1128. The "What is the AISVS" heading now links the OWASP project page instead of the site docs repository.Checks
markdownlint and cspell pass locally on all six changed files; four contributor name tokens were added to the custom dictionary. Requirement count is unchanged at 197 and Appendix B still references every requirement exactly once.
🤖 Generated with Claude Code