Uncle Joe

Results 70 comments of Uncle Joe

Further in the future, wouldn't also combining these two processes make it possible to automate the resolution of these threats according to the applicable security requirements found during the threat...

Also, what if you could use an AI as a facilitator or dungeon master to facilitate threat modeling sessions or the threat modeling game instead of an application security engineer...

I appreciate your enthusiasm, let me get back to you on this. Not everything is completely clear in this story.

Do you need help with this? If so, how do you prefer to solve it? Do you want to have 2 Indexes covering ASVS 4.0 and ASVS 5.0, or is...

Great! At OWASP Cornucopi we use the ASVS 4.0 index to link to the cheat sheet pages: https://cornucopia.owasp.org/cards/VE3#card But we are ready to move to ASVS 5.0 Elar Lang made...

Note to self: remember to document how the CAPECs are mapped to ASVS.

Adding the Threat Dragon model json: [Integration between OWASP Cornucopia and OWASP Threat Dragon.json](https://github.com/user-attachments/files/23419967/Integration.between.OWASP.Cornucopia.and.OWASP.Threat.Dragon.json)

The api has the categories added to the section field: webapp: https://cornucopia.owasp.org/api/cre/webapp/en (supported languages: "en", "es", "fr", "nl", "no-nb", "pt-br", "pt-pt", "it", "ru", "hu") mobileapp: https://cornucopia.owasp.org/api/cre/mobileapp/en (supported languages: "en") How...

That is great! Sure, the files for the cards are here: https://github.com/OWASP/cornucopia/tree/master/source You only need to translate the latest version of an edition. Thank you for getting in thouch!

There is a 3.0 version of the Website App Edition that we will release soon. Text in the sourcefolder in the repo.