otp icon indicating copy to clipboard operation
otp copied to clipboard

system: Add Secure Coding Guidelines

Open jhogberg opened this issue 1 month ago • 0 comments

Our benefactors want a secure coding standard/guideline for Erlang, and in contrast to EEF's Secure Coding Recommendations they want it to be more along the lines of the SEI CERT Coding Standards. We need to have numbered and concrete rules, mappings to CWEs and OWASP risks and back, and must address the top N CWEs and OWASP risks.

This is an early draft to get a discussion started on how it should look, which recommendations/rules should be included, and so on. It is quite incomplete at the moment, and any and all feedback is most welcome.

jhogberg avatar Dec 02 '25 18:12 jhogberg