+
Skip to content

Releases: OWASP/cornucopia

Release v2.5.0

02 Oct 18:10
a09392f
Compare
Choose a tag to compare

How do you get your dev team to shift left for real?
Shift-left doesn't start with scanning code for security vulnerabilities; it begins with designing it.
Play yourself secure with the latest release of OWASP Cornucopia Website Edition v2.2!
threat modeling for security people

In our next version of OWASP Cornucopia Website App Edition version 2.2 we have a special treat for you.
We have gathered all our threat modeling expertise, created threat modeling scenarios for each card, and analyzed which STRIDE categories each scenario belongs to. Much of this material has been contributed to the project from @jefmeijvis and dotNET Lab.
If you have bought an OWASP Cornucopia deck with QR codes, you can now give your team advice on threat scenarios, threat vectors, attack patterns, mitigation strategies, and STRIDE when playing the game by letting them scan the QR codes on each card. Each scenario follows "Shostack's Four Question Frame for Threat Modeling", making it easy for your security champions to come up with the threats and mitigations themselves.
In addition, we have added additional CAPECs that correspond to each card and added references to the OWASP Developer Guide's Web Application Checklist that will link your threat modeling to OWASP secure coding practices and the OWASP Top 10 Proactive controls, this, thanks to @jgadsden
from the OWASP Developer Guide project.

Latest pre-release

24 Sep 17:28
878b68c
Compare
Choose a tag to compare
Latest pre-release Pre-release
Pre-release

Commits

  • 364cca5: Adding the wiki deck to each card and adding STRIDE explanation that can be used in threat modeling sessions. (sydseter) #1695
  • da18909: Add instructions regarding using the mapping (sydseter) #1695

Release v2.4.8

22 Sep 09:38
f448ecf
Compare
Choose a tag to compare
Merge pull request #1677 from OWASP/urls-to-devguide

Add urls to the OWASP Developer Guide from Cornucopia

Release v2.4.7

16 Sep 06:58
fbee366
Compare
Choose a tag to compare
Merge pull request #1661 from OWASP/licensing

Update licensing to make way for the next version

Release v2.4.6

15 Sep 18:41
3d6ea01
Compare
Choose a tag to compare
Merge pull request #1653 from OWASP/dependabot/pip/types-requests-2.3…

Release v2.4.5

06 Sep 08:14
56bd694
Compare
Choose a tag to compare
Merge pull request #1629 from OWASP/cw-owasp-patch-1

Added Max's video to How to Play page

Release v2.4.4

04 Sep 09:15
ecb1319
Compare
Choose a tag to compare
Merge pull request #1620 from OWASP/code-coverage

#1487 and #1614 Allow failure, but publish results

Release v2.4.3

28 Aug 07:48
24a214e
Compare
Choose a tag to compare
Merge pull request #1603 from OWASP/dependabot/npm_and_yarn/cornucopi…

v2.4.2 release

06 Aug 14:30
df766ad
Compare
Choose a tag to compare
Merge pull request #1549 from OWASP/companion-edition

Companion edition post

v2.4.1

03 Aug 19:10
a28b741
Compare
Choose a tag to compare
Merge pull request #1528 from OWASP/dependabot/npm_and_yarn/cornucopi…
点击 这是indexloc提供的php浏览器服务,不要输入任何密码和下载