<?xml version="1.0"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
		<id>https://wiki.owasp.org/api.php?action=feedcontributions&amp;feedformat=atom&amp;user=Mdoylema</id>
		<title>OWASP - User contributions [en]</title>
		<link rel="self" type="application/atom+xml" href="https://wiki.owasp.org/api.php?action=feedcontributions&amp;feedformat=atom&amp;user=Mdoylema"/>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php/Special:Contributions/Mdoylema"/>
		<updated>2026-05-16T23:35:00Z</updated>
		<subtitle>User contributions</subtitle>
		<generator>MediaWiki 1.27.2</generator>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Category:OWASP_Source_Code_Review_OWASP_Projects_Project&amp;diff=48493</id>
		<title>Category:OWASP Source Code Review OWASP Projects Project</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Category:OWASP_Source_Code_Review_OWASP_Projects_Project&amp;diff=48493"/>
				<updated>2008-12-12T16:09:59Z</updated>
		
		<summary type="html">&lt;p&gt;Mdoylema: /* Process */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;[[:Category:OWASP Project|Click here to return to OWASP Projects page.]]&amp;lt;br&amp;gt;&lt;br /&gt;
[[:Project Information:template Source Code Review OWASP Projects|Click here to see (&amp;amp; edit, if wanted) the template.]] &lt;br /&gt;
{{:Project Information:template Source Code Review OWASP Projects}}&lt;br /&gt;
[[Category:OWASP Project]]&lt;br /&gt;
&lt;br /&gt;
== Summary ==&lt;br /&gt;
&lt;br /&gt;
This project involving creating a process for integrating the Fortify Open Review Process into the OWASP project development lifecycle and working with Fortify to develop and test their new Open Review site at [http://owasp.fortify.com/ http://owasp.fortify.com/].&lt;br /&gt;
&lt;br /&gt;
== Goals ==&lt;br /&gt;
&lt;br /&gt;
The goals of this project were to:&lt;br /&gt;
&lt;br /&gt;
# Create a process for integrating the Fortify Open Review into open source development, so that source code review can be a required step in OWASP development.&lt;br /&gt;
# Test functionality of the new Fortify Open Review site introduced in Summer 2008.&lt;br /&gt;
# Scan 10 OWASP projects with the Fortify Open Review to verify the site's functionality and establish a baseline.&lt;br /&gt;
# Scan 25 popular open source PHP projects to verify the site's ability to handle large scale projects and establish a baseline.&lt;br /&gt;
&lt;br /&gt;
== Process ==&lt;br /&gt;
The workflow diagrams can be found in [https://www.owasp.org/index.php/Image:Workflow_July_11a.zip Workflow.zip].  Within the ZIP file, overview.pdf describes the relationships between the different parts of the workflow. The file start.pdf describes the first step of the workflow which verifies that the project is an OWASP project.  If it is not then the project is added as a new OWASP project [[Image:Workflow_Draft1.pdf#file]].  Once the project is established as an OWASP project, it can be added by an OWASP administrator (contact the project mailing list below to contact an OWASP administrator) to the Fortify Open Review (reference createProject.pdf).  &lt;br /&gt;
&lt;br /&gt;
As described in the Fortify Open Review process, the Project Lead or Source Code Review Lead can choose between a continuous evaluation, where the project is checked out from its repository and the Open Review scan is updated on a weekly basis, or a one time analysis as part of their usual development process (see waterfall.pdf and iterative.pdf) after unit testing and prior to final system testing.   The single analysis requires the evaluator to produce and upload a Fortify FPR scan file, which requires either that the evaluator uses their own copy of Fortify SCA or contacts an OWASP administrator via the project mailing list to request a scan.   In order to track project progress over time, single analyses of major project versions will be maintained on the project web site so that software vulnerability metrics can be tracked.  The continuous evaluation is automated, does not require the developer have a Fortify SCA license.  There are additional open source static analysis tools that can be used as part of a project's development lifecycle on a regular basis, such as FindBugs (see findBugs.pdf) and OWASP Orizon.&lt;br /&gt;
&lt;br /&gt;
Of course, once vulnerabilities are detected, they need to be either fixed or marked as false positives through the Fortify Open Review site interface.  See the [http://www.lulu.com/content/1415989 OWASP Code Review Guide] for information on how to fix common vulnerabilities. &lt;br /&gt;
&lt;br /&gt;
The purpose of this workflow is to integrate and automate SCA into the development cycle of open source applications for the sole purpose of decreasing software vulnerabilities.  This effort can, and should, be supplemented by a manual code review as described in the OWASP Open Review Project.&lt;br /&gt;
&lt;br /&gt;
== OWASP Projects Scanned ==&lt;br /&gt;
&lt;br /&gt;
AntiSamy&lt;br /&gt;
&lt;br /&gt;
CSRFGuard&lt;br /&gt;
&lt;br /&gt;
CSRFTester&lt;br /&gt;
&lt;br /&gt;
DirBuster&lt;br /&gt;
&lt;br /&gt;
JBroFuzz&lt;br /&gt;
&lt;br /&gt;
Lapse&lt;br /&gt;
&lt;br /&gt;
Stinger&lt;br /&gt;
&lt;br /&gt;
Webekci&lt;br /&gt;
&lt;br /&gt;
WebGoat&lt;br /&gt;
&lt;br /&gt;
WebScarab&lt;br /&gt;
&lt;br /&gt;
Non-OWASP projects scanned in MediaWiki, WordPress, and many others. See [https://owasp.fortify.com/ owasp.fortify.com] for details.&lt;br /&gt;
&lt;br /&gt;
== Get involved ==&lt;br /&gt;
&lt;br /&gt;
We need OWASP project leaders to submit their projects for review.  We will work with you to upload your project and review the findings, so that we can get each OWASP project to show zero defects.&lt;br /&gt;
&lt;br /&gt;
Please go to https://lists.owasp.org/mailman/listinfo/owasp-scode-review-owasp-projects to subscribe to the list to contact us. You can post to the mailing list by emailing [mailto:owasp-scode-review-owasp-projects@lists.owasp.org].&lt;br /&gt;
&lt;br /&gt;
== People ==&lt;br /&gt;
&lt;br /&gt;
Project lead: [[User:Walden|James Walden]]&lt;br /&gt;
&lt;br /&gt;
Contributors: Maureen Doyle, Grant Welch, Michael Whelan&lt;br /&gt;
&lt;br /&gt;
Reviewers: Marco Morano, Alex Fry&lt;br /&gt;
&lt;br /&gt;
[http://www.fortify.com Fortify Software] has generously made their Source Code Analyzer (SCA) technology available for use by open source projects at [http://owasp.fortify.com/ owasp.fortify.com].&lt;/div&gt;</summary>
		<author><name>Mdoylema</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Category:OWASP_Source_Code_Review_OWASP_Projects_Project&amp;diff=48475</id>
		<title>Category:OWASP Source Code Review OWASP Projects Project</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Category:OWASP_Source_Code_Review_OWASP_Projects_Project&amp;diff=48475"/>
				<updated>2008-12-11T21:13:48Z</updated>
		
		<summary type="html">&lt;p&gt;Mdoylema: /* Process */  Ready for James&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;[[:Category:OWASP Project|Click here to return to OWASP Projects page.]]&amp;lt;br&amp;gt;&lt;br /&gt;
[[:Project Information:template Source Code Review OWASP Projects|Click here to see (&amp;amp; edit, if wanted) the template.]] &lt;br /&gt;
{{:Project Information:template Source Code Review OWASP Projects}}&lt;br /&gt;
[[Category:OWASP Project]]&lt;br /&gt;
&lt;br /&gt;
== Process ==&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
The OWASP Source Code Review integrates OWASP projects with the Fortify Open Review Process. The workflow diagrams can be found in [https://www.owasp.org/index.php/Image:Workflow_July_11a.zip Workflow.zip] and overview.pdf describes the relationships between the differentparts of the workflow. The file start.pdf describes the first step of the workflow which verifies that the project is an OWASP project.  If it is not then the project is added as a new OWASP project [[Image:Workflow_Draft1.pdf#file]].  Prior to any source code analysis (SCA), the project must also be added as a Fortify Open Review Project(reference createProject.pdf).  &lt;br /&gt;
&lt;br /&gt;
As described in the Fortify Open Review Process, the Project Lead or Source Code Review Lead can choose between a continuous evaluation, where SCA is done weekly, or a one time analysis as part of their usual development process (see waterfall.pdf and iterative.pdf) after unit testing and prior to final system testing.   The single analysis requires the evaluator to submit a Fortify output file which requires the evaluator to own a copy of Fortify 360.   The continuous evaluation is automated, does not require the developer have a Fortify 360 license,  and in accordance with the [http://www.lulu.com/content/1415989 OWASP Code Review Guide] these results can be used to remove common problems.  The common problems, along with other software errors exposed by findBugs (reference findBugs.pdf) will then be documented as known problems in the project's bug list.  &lt;br /&gt;
&lt;br /&gt;
The purpose of this workflow is to integrate and automate SCA into the development cycle of open source applications for the sole purpose of decreasing software vulnerabilities.  This effort can, and should, be supplemented by a Manual Code Review as described in the OWASP Open Review Project.&lt;br /&gt;
&lt;br /&gt;
== OWASP Projects Scanned ==&lt;br /&gt;
&lt;br /&gt;
AntiSamy&lt;br /&gt;
&lt;br /&gt;
CSRFGuard&lt;br /&gt;
&lt;br /&gt;
CSRFTester&lt;br /&gt;
&lt;br /&gt;
DirBuster&lt;br /&gt;
&lt;br /&gt;
JBroFuzz&lt;br /&gt;
&lt;br /&gt;
Lapse&lt;br /&gt;
&lt;br /&gt;
Stinger&lt;br /&gt;
&lt;br /&gt;
Webekci&lt;br /&gt;
&lt;br /&gt;
WebGoat&lt;br /&gt;
&lt;br /&gt;
WebScarab&lt;br /&gt;
&lt;br /&gt;
Non-OWASP projects scanned in MediaWiki, WordPress, and many others. See [https://owasp.fortify.com/ owasp.fortify.com] for details.&lt;br /&gt;
&lt;br /&gt;
== Get involved ==&lt;br /&gt;
&lt;br /&gt;
We need OWASP project leaders to submit their projects for review.  We will work with you to upload your project and review the findings, so that we can get each OWASP project to show zero defects.&lt;br /&gt;
&lt;br /&gt;
Please go to https://lists.owasp.org/mailman/listinfo/owasp-scode-review-owasp-projects to subscribe to the list to contact us. You can post to the mailing list by emailing [mailto:owasp-scode-review-owasp-projects@lists.owasp.org].&lt;br /&gt;
&lt;br /&gt;
== People ==&lt;br /&gt;
&lt;br /&gt;
Project lead: [[User:Walden|James Walden]]&lt;br /&gt;
&lt;br /&gt;
Contributors: Maureen Doyle, Grant Welch, Michael Whelan&lt;br /&gt;
&lt;br /&gt;
Reviewers: Marco Morano, Alex Fry&lt;br /&gt;
&lt;br /&gt;
[http://www.fortify.com Fortify Software] has generously made their Source Code Analyzer (SCA) technology available for use by open source projects at [http://owasp.fortify.com/ owasp.fortify.com].&lt;/div&gt;</summary>
		<author><name>Mdoylema</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Category:OWASP_Source_Code_Review_OWASP_Projects_Project&amp;diff=48465</id>
		<title>Category:OWASP Source Code Review OWASP Projects Project</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Category:OWASP_Source_Code_Review_OWASP_Projects_Project&amp;diff=48465"/>
				<updated>2008-12-11T20:15:47Z</updated>
		
		<summary type="html">&lt;p&gt;Mdoylema: /* Process */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;[[:Category:OWASP Project|Click here to return to OWASP Projects page.]]&amp;lt;br&amp;gt;&lt;br /&gt;
[[:Project Information:template Source Code Review OWASP Projects|Click here to see (&amp;amp; edit, if wanted) the template.]] &lt;br /&gt;
{{:Project Information:template Source Code Review OWASP Projects}}&lt;br /&gt;
[[Category:OWASP Project]]&lt;br /&gt;
&lt;br /&gt;
== Process ==&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
The OWASP Source Code Review integrates OWASP projects with the Fortify Open Review Process. The workflow can be found in [https://www.owasp.org/index.php/Image:Workflow_July_11a.zip Workflow.zip]  Therefore, any open source project using this workflow must first be added as an OWASP project as illustrated in [[Image:Workflow_Draft1.pdf#file]].  &lt;br /&gt;
&lt;br /&gt;
As described in the Fortify Open Review Process, the Project Lead or Source Code Review Lead can choose between a continuous evaluation, where SCA is done weekly, or one time analysis.  The single analysis requires the evaluator to submit a Fortify output file, which requires the evaluator to own a copy of Fortify.   The continuous evaluation is automated and in accordance with the [http://www.lulu.com/content/1415989 OWASP Code Review Guide], these results can be used to remove common problems.  The common problems, along with other software errors exposed by findBugs, will be documented as known problems.  &lt;br /&gt;
&lt;br /&gt;
The single analysis or any one of the continuous analysis can be followed by a code review Manual Review as described in the OWASP Open Review Project.&lt;br /&gt;
&lt;br /&gt;
== OWASP Projects Scanned ==&lt;br /&gt;
&lt;br /&gt;
AntiSamy&lt;br /&gt;
&lt;br /&gt;
CSRFGuard&lt;br /&gt;
&lt;br /&gt;
CSRFTester&lt;br /&gt;
&lt;br /&gt;
DirBuster&lt;br /&gt;
&lt;br /&gt;
JBroFuzz&lt;br /&gt;
&lt;br /&gt;
Lapse&lt;br /&gt;
&lt;br /&gt;
Stinger&lt;br /&gt;
&lt;br /&gt;
Webekci&lt;br /&gt;
&lt;br /&gt;
WebGoat&lt;br /&gt;
&lt;br /&gt;
WebScarab&lt;br /&gt;
&lt;br /&gt;
Non-OWASP projects scanned in MediaWiki, WordPress, and many others. See [https://owasp.fortify.com/ owasp.fortify.com] for details.&lt;br /&gt;
&lt;br /&gt;
== Get involved ==&lt;br /&gt;
&lt;br /&gt;
We need OWASP project leaders to submit their projects for review.  We will work with you to upload your project and review the findings, so that we can get each OWASP project to show zero defects.&lt;br /&gt;
&lt;br /&gt;
Please go to https://lists.owasp.org/mailman/listinfo/owasp-scode-review-owasp-projects to subscribe to the list to contact us. You can post to the mailing list by emailing [mailto:owasp-scode-review-owasp-projects@lists.owasp.org].&lt;br /&gt;
&lt;br /&gt;
== People ==&lt;br /&gt;
&lt;br /&gt;
Project lead: [[User:Walden|James Walden]]&lt;br /&gt;
&lt;br /&gt;
Contributors: Maureen Doyle, Grant Welch, Michael Whelan&lt;br /&gt;
&lt;br /&gt;
Reviewers: Marco Morano, Alex Fry&lt;br /&gt;
&lt;br /&gt;
[http://www.fortify.com Fortify Software] has generously made their Source Code Analyzer (SCA) technology available for use by open source projects at [http://owasp.fortify.com/ owasp.fortify.com].&lt;/div&gt;</summary>
		<author><name>Mdoylema</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Category:OWASP_Source_Code_Review_OWASP_Projects_Project&amp;diff=48464</id>
		<title>Category:OWASP Source Code Review OWASP Projects Project</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Category:OWASP_Source_Code_Review_OWASP_Projects_Project&amp;diff=48464"/>
				<updated>2008-12-11T20:13:55Z</updated>
		
		<summary type="html">&lt;p&gt;Mdoylema: /* Process */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;[[:Category:OWASP Project|Click here to return to OWASP Projects page.]]&amp;lt;br&amp;gt;&lt;br /&gt;
[[:Project Information:template Source Code Review OWASP Projects|Click here to see (&amp;amp; edit, if wanted) the template.]] &lt;br /&gt;
{{:Project Information:template Source Code Review OWASP Projects}}&lt;br /&gt;
[[Category:OWASP Project]]&lt;br /&gt;
&lt;br /&gt;
== Process ==&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
The OWASP Source Code Review integrates OWASP projects with the Fortify Open Review Process. The workflow can be found in [[https://www.owasp.org/index.php/Image:Workflow_July_11a.zip Workflow.zip]]  Therefore, any open source project using this workflow must first be added as an OWASP project as illustrated in [[Image:Workflow_Draft1.pdf#file]].  &lt;br /&gt;
&lt;br /&gt;
As described in the Fortify Open Review Process, the Project Lead or Source Code Review Lead can choose between a continuous evaluation, where SCA is done weekly, or one time analysis.  The single analysis requires the evaluator to submit a Fortify output file, which requires the evaluator to own a copy of Fortify.   The continuous evaluation is automated and in accordance with the [ http://www.lulu.com/content/1415989 OWASP Code Review Guide], these results can be used to remove common problems.  The common problems, along with other software errors exposed by findBugs, will be documented as known problems.  &lt;br /&gt;
&lt;br /&gt;
The single analysis or any one of the continuous analysis can be followed by a code review Manual Review as described in the OWASP Open Review Project.&lt;br /&gt;
&lt;br /&gt;
== OWASP Projects Scanned ==&lt;br /&gt;
&lt;br /&gt;
AntiSamy&lt;br /&gt;
&lt;br /&gt;
CSRFGuard&lt;br /&gt;
&lt;br /&gt;
CSRFTester&lt;br /&gt;
&lt;br /&gt;
DirBuster&lt;br /&gt;
&lt;br /&gt;
JBroFuzz&lt;br /&gt;
&lt;br /&gt;
Lapse&lt;br /&gt;
&lt;br /&gt;
Stinger&lt;br /&gt;
&lt;br /&gt;
Webekci&lt;br /&gt;
&lt;br /&gt;
WebGoat&lt;br /&gt;
&lt;br /&gt;
WebScarab&lt;br /&gt;
&lt;br /&gt;
Non-OWASP projects scanned in MediaWiki, WordPress, and many others. See [https://owasp.fortify.com/ owasp.fortify.com] for details.&lt;br /&gt;
&lt;br /&gt;
== Get involved ==&lt;br /&gt;
&lt;br /&gt;
We need OWASP project leaders to submit their projects for review.  We will work with you to upload your project and review the findings, so that we can get each OWASP project to show zero defects.&lt;br /&gt;
&lt;br /&gt;
Please go to https://lists.owasp.org/mailman/listinfo/owasp-scode-review-owasp-projects to subscribe to the list to contact us. You can post to the mailing list by emailing [mailto:owasp-scode-review-owasp-projects@lists.owasp.org].&lt;br /&gt;
&lt;br /&gt;
== People ==&lt;br /&gt;
&lt;br /&gt;
Project lead: [[User:Walden|James Walden]]&lt;br /&gt;
&lt;br /&gt;
Contributors: Maureen Doyle, Grant Welch, Michael Whelan&lt;br /&gt;
&lt;br /&gt;
Reviewers: Marco Morano, Alex Fry&lt;br /&gt;
&lt;br /&gt;
[http://www.fortify.com Fortify Software] has generously made their Source Code Analyzer (SCA) technology available for use by open source projects at [http://owasp.fortify.com/ owasp.fortify.com].&lt;/div&gt;</summary>
		<author><name>Mdoylema</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Category:OWASP_Source_Code_Review_OWASP_Projects_Project&amp;diff=48463</id>
		<title>Category:OWASP Source Code Review OWASP Projects Project</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Category:OWASP_Source_Code_Review_OWASP_Projects_Project&amp;diff=48463"/>
				<updated>2008-12-11T20:10:58Z</updated>
		
		<summary type="html">&lt;p&gt;Mdoylema: /* Process */  Added workflow zip&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;[[:Category:OWASP Project|Click here to return to OWASP Projects page.]]&amp;lt;br&amp;gt;&lt;br /&gt;
[[:Project Information:template Source Code Review OWASP Projects|Click here to see (&amp;amp; edit, if wanted) the template.]] &lt;br /&gt;
{{:Project Information:template Source Code Review OWASP Projects}}&lt;br /&gt;
[[Category:OWASP Project]]&lt;br /&gt;
&lt;br /&gt;
== Process ==&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
The OWASP Source Code Review integrates OWASP projects with the Fortify Open Review Process. The workflow can be found in [[Image:https://www.owasp.org/index.php/Image:Workflow_July_11a.zip]  Therefore, any open source project using this workflow must first be added as an OWASP project as illustrated in [[Image:Workflow_Draft1.pdf#file]].  &lt;br /&gt;
&lt;br /&gt;
As described in the Fortify Open Review Process, the Project Lead or Source Code Review Lead can choose between a continuous evaluation, where SCA is done weekly, or one time analysis.  The single analysis requires the evaluator to submit a Fortify output file, which requires the evaluator to own a copy of Fortify.   The continuous evaluation is automated and in accordance with the [ http://www.lulu.com/content/1415989 OWASP Code Review Guide], these results can be used to remove common problems.  The common problems, along with other software errors exposed by findBugs, will be documented as known problems.  &lt;br /&gt;
&lt;br /&gt;
The single analysis or any one of the continuous analysis can be followed by a code review Manual Review as described in the OWASP Open Review Project.&lt;br /&gt;
&lt;br /&gt;
== OWASP Projects Scanned ==&lt;br /&gt;
&lt;br /&gt;
AntiSamy&lt;br /&gt;
&lt;br /&gt;
CSRFGuard&lt;br /&gt;
&lt;br /&gt;
CSRFTester&lt;br /&gt;
&lt;br /&gt;
DirBuster&lt;br /&gt;
&lt;br /&gt;
JBroFuzz&lt;br /&gt;
&lt;br /&gt;
Lapse&lt;br /&gt;
&lt;br /&gt;
Stinger&lt;br /&gt;
&lt;br /&gt;
Webekci&lt;br /&gt;
&lt;br /&gt;
WebGoat&lt;br /&gt;
&lt;br /&gt;
WebScarab&lt;br /&gt;
&lt;br /&gt;
Non-OWASP projects scanned in MediaWiki, WordPress, and many others. See [https://owasp.fortify.com/ owasp.fortify.com] for details.&lt;br /&gt;
&lt;br /&gt;
== Get involved ==&lt;br /&gt;
&lt;br /&gt;
We need OWASP project leaders to submit their projects for review.  We will work with you to upload your project and review the findings, so that we can get each OWASP project to show zero defects.&lt;br /&gt;
&lt;br /&gt;
Please go to https://lists.owasp.org/mailman/listinfo/owasp-scode-review-owasp-projects to subscribe to the list to contact us. You can post to the mailing list by emailing [mailto:owasp-scode-review-owasp-projects@lists.owasp.org].&lt;br /&gt;
&lt;br /&gt;
== People ==&lt;br /&gt;
&lt;br /&gt;
Project lead: [[User:Walden|James Walden]]&lt;br /&gt;
&lt;br /&gt;
Contributors: Maureen Doyle, Grant Welch, Michael Whelan&lt;br /&gt;
&lt;br /&gt;
Reviewers: Marco Morano, Alex Fry&lt;br /&gt;
&lt;br /&gt;
[http://www.fortify.com Fortify Software] has generously made their Source Code Analyzer (SCA) technology available for use by open source projects at [http://owasp.fortify.com/ owasp.fortify.com].&lt;/div&gt;</summary>
		<author><name>Mdoylema</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Category:OWASP_Source_Code_Review_OWASP_Projects_Project&amp;diff=48324</id>
		<title>Category:OWASP Source Code Review OWASP Projects Project</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Category:OWASP_Source_Code_Review_OWASP_Projects_Project&amp;diff=48324"/>
				<updated>2008-12-11T05:06:32Z</updated>
		
		<summary type="html">&lt;p&gt;Mdoylema: /* Process */  Added a bit more for James to review&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;[[:Category:OWASP Project|Click here to return to OWASP Projects page.]]&amp;lt;br&amp;gt;&lt;br /&gt;
[[:Project Information:template Source Code Review OWASP Projects|Click here to see (&amp;amp; edit, if wanted) the template.]] &lt;br /&gt;
{{:Project Information:template Source Code Review OWASP Projects}}&lt;br /&gt;
[[Category:OWASP Project]]&lt;br /&gt;
&lt;br /&gt;
== Process ==&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
The OWASP Source Code Review integrates OWASP projects with the Fortify Open Review Process.  Therefore, any open source project using this workflow must first be added as an OWASP project as illustrated in [[Image:Workflow_Draft1.pdf#file]].  &lt;br /&gt;
&lt;br /&gt;
As described in the Fortify Open Review Process, the Project Lead or Source Code Review Lead can choose between a continuous evaluation, where SCA is done weekly, or one time analysis.  The single analysis requires the evaluator to submit a Fortify output file, which requires the evaluator to own a copy of Fortify.   The continuous evaluation is automated and in accordance with the [ http://www.lulu.com/content/1415989 OWASP Code Review Guide], these results can be used to remove common problems.  The common problems, along with other software errors exposed by findBugs, will be documented as known problems.  &lt;br /&gt;
&lt;br /&gt;
The single analysis or any one of the continuous analysis can be followed by a code review Manual Review as described in the OWASP Open Review Project.&lt;br /&gt;
&lt;br /&gt;
== OWASP Projects Scanned ==&lt;br /&gt;
&lt;br /&gt;
AntiSamy&lt;br /&gt;
&lt;br /&gt;
CSRFGuard&lt;br /&gt;
&lt;br /&gt;
CSRFTester&lt;br /&gt;
&lt;br /&gt;
DirBuster&lt;br /&gt;
&lt;br /&gt;
JBroFuzz&lt;br /&gt;
&lt;br /&gt;
Lapse&lt;br /&gt;
&lt;br /&gt;
Stinger&lt;br /&gt;
&lt;br /&gt;
Webekci&lt;br /&gt;
&lt;br /&gt;
WebGoat&lt;br /&gt;
&lt;br /&gt;
WebScarab&lt;br /&gt;
&lt;br /&gt;
Non-OWASP projects scanned in MediaWiki, WordPress, and many others. See [https://owasp.fortify.com/ owasp.fortify.com] for details.&lt;br /&gt;
&lt;br /&gt;
== Get involved ==&lt;br /&gt;
&lt;br /&gt;
We need OWASP project leaders to submit their projects for review.  We will work with you to upload your project and review the findings, so that we can get each OWASP project to show zero defects.&lt;br /&gt;
&lt;br /&gt;
Please go to https://lists.owasp.org/mailman/listinfo/owasp-scode-review-owasp-projects to subscribe to the list to contact us. You can post to the mailing list by emailing [mailto:owasp-scode-review-owasp-projects@lists.owasp.org].&lt;br /&gt;
&lt;br /&gt;
== People ==&lt;br /&gt;
&lt;br /&gt;
Project lead: [[User:Walden|James Walden]]&lt;br /&gt;
&lt;br /&gt;
Contributors: Maureen Doyle, Grant Welch, Michael Whelan&lt;br /&gt;
&lt;br /&gt;
Reviewers: Marco Morano, Alex Fry&lt;br /&gt;
&lt;br /&gt;
[http://www.fortify.com Fortify Software] has generously made their Source Code Analyzer (SCA) technology available for use by open source projects at [http://owasp.fortify.com/ owasp.fortify.com].&lt;/div&gt;</summary>
		<author><name>Mdoylema</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Category:OWASP_Source_Code_Review_OWASP_Projects_Project&amp;diff=48323</id>
		<title>Category:OWASP Source Code Review OWASP Projects Project</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Category:OWASP_Source_Code_Review_OWASP_Projects_Project&amp;diff=48323"/>
				<updated>2008-12-11T04:52:58Z</updated>
		
		<summary type="html">&lt;p&gt;Mdoylema: /* Process */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;[[:Category:OWASP Project|Click here to return to OWASP Projects page.]]&amp;lt;br&amp;gt;&lt;br /&gt;
[[:Project Information:template Source Code Review OWASP Projects|Click here to see (&amp;amp; edit, if wanted) the template.]] &lt;br /&gt;
{{:Project Information:template Source Code Review OWASP Projects}}&lt;br /&gt;
[[Category:OWASP Project]]&lt;br /&gt;
&lt;br /&gt;
== Process ==&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
The OWASP Source Code Review integrates OWASP projects with the Fortify Open Review Process.  Therefore, any open source project using this workflow must first be added as an OWASP project as illustrated in [[Image:Workflow_Draft1.pdf#file]].&lt;br /&gt;
&lt;br /&gt;
== OWASP Projects Scanned ==&lt;br /&gt;
&lt;br /&gt;
AntiSamy&lt;br /&gt;
&lt;br /&gt;
CSRFGuard&lt;br /&gt;
&lt;br /&gt;
CSRFTester&lt;br /&gt;
&lt;br /&gt;
DirBuster&lt;br /&gt;
&lt;br /&gt;
JBroFuzz&lt;br /&gt;
&lt;br /&gt;
Lapse&lt;br /&gt;
&lt;br /&gt;
Stinger&lt;br /&gt;
&lt;br /&gt;
Webekci&lt;br /&gt;
&lt;br /&gt;
WebGoat&lt;br /&gt;
&lt;br /&gt;
WebScarab&lt;br /&gt;
&lt;br /&gt;
Non-OWASP projects scanned in MediaWiki, WordPress, and many others. See [https://owasp.fortify.com/ owasp.fortify.com] for details.&lt;br /&gt;
&lt;br /&gt;
== Get involved ==&lt;br /&gt;
&lt;br /&gt;
We need OWASP project leaders to submit their projects for review.  We will work with you to upload your project and review the findings, so that we can get each OWASP project to show zero defects.&lt;br /&gt;
&lt;br /&gt;
Please go to https://lists.owasp.org/mailman/listinfo/owasp-scode-review-owasp-projects to subscribe to the list to contact us. You can post to the mailing list by emailing [mailto:owasp-scode-review-owasp-projects@lists.owasp.org].&lt;br /&gt;
&lt;br /&gt;
== People ==&lt;br /&gt;
&lt;br /&gt;
Project lead: [[User:Walden|James Walden]]&lt;br /&gt;
&lt;br /&gt;
Contributors: Maureen Doyle, Grant Welch, Michael Whelan&lt;br /&gt;
&lt;br /&gt;
Reviewers: Marco Morano, Alex Fry&lt;br /&gt;
&lt;br /&gt;
[http://www.fortify.com Fortify Software] has generously made their Source Code Analyzer (SCA) technology available for use by open source projects at [http://owasp.fortify.com/ owasp.fortify.com].&lt;/div&gt;</summary>
		<author><name>Mdoylema</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Category:OWASP_Source_Code_Review_OWASP_Projects_Project&amp;diff=48322</id>
		<title>Category:OWASP Source Code Review OWASP Projects Project</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Category:OWASP_Source_Code_Review_OWASP_Projects_Project&amp;diff=48322"/>
				<updated>2008-12-11T04:52:00Z</updated>
		
		<summary type="html">&lt;p&gt;Mdoylema: /* Process */  -- Started process description&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;[[:Category:OWASP Project|Click here to return to OWASP Projects page.]]&amp;lt;br&amp;gt;&lt;br /&gt;
[[:Project Information:template Source Code Review OWASP Projects|Click here to see (&amp;amp; edit, if wanted) the template.]] &lt;br /&gt;
{{:Project Information:template Source Code Review OWASP Projects}}&lt;br /&gt;
[[Category:OWASP Project]]&lt;br /&gt;
&lt;br /&gt;
== Process ==&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
The OWASP Source Code Review integrates OWASP projects with the Fortify Open Review Process.  Therefore, any open source project using this workflow must first be added as an OWASP project as illustrated in [[images/c/c2/Workflow_Draft1.pdf]].&lt;br /&gt;
&lt;br /&gt;
== OWASP Projects Scanned ==&lt;br /&gt;
&lt;br /&gt;
AntiSamy&lt;br /&gt;
&lt;br /&gt;
CSRFGuard&lt;br /&gt;
&lt;br /&gt;
CSRFTester&lt;br /&gt;
&lt;br /&gt;
DirBuster&lt;br /&gt;
&lt;br /&gt;
JBroFuzz&lt;br /&gt;
&lt;br /&gt;
Lapse&lt;br /&gt;
&lt;br /&gt;
Stinger&lt;br /&gt;
&lt;br /&gt;
Webekci&lt;br /&gt;
&lt;br /&gt;
WebGoat&lt;br /&gt;
&lt;br /&gt;
WebScarab&lt;br /&gt;
&lt;br /&gt;
Non-OWASP projects scanned in MediaWiki, WordPress, and many others. See [https://owasp.fortify.com/ owasp.fortify.com] for details.&lt;br /&gt;
&lt;br /&gt;
== Get involved ==&lt;br /&gt;
&lt;br /&gt;
We need OWASP project leaders to submit their projects for review.  We will work with you to upload your project and review the findings, so that we can get each OWASP project to show zero defects.&lt;br /&gt;
&lt;br /&gt;
Please go to https://lists.owasp.org/mailman/listinfo/owasp-scode-review-owasp-projects to subscribe to the list to contact us. You can post to the mailing list by emailing [mailto:owasp-scode-review-owasp-projects@lists.owasp.org].&lt;br /&gt;
&lt;br /&gt;
== People ==&lt;br /&gt;
&lt;br /&gt;
Project lead: [[User:Walden|James Walden]]&lt;br /&gt;
&lt;br /&gt;
Contributors: Maureen Doyle, Grant Welch, Michael Whelan&lt;br /&gt;
&lt;br /&gt;
Reviewers: Marco Morano, Alex Fry&lt;br /&gt;
&lt;br /&gt;
[http://www.fortify.com Fortify Software] has generously made their Source Code Analyzer (SCA) technology available for use by open source projects at [http://owasp.fortify.com/ owasp.fortify.com].&lt;/div&gt;</summary>
		<author><name>Mdoylema</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Project_Information:template_Source_Code_Review_OWASP_Projects&amp;diff=33900</id>
		<title>Project Information:template Source Code Review OWASP Projects</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Project_Information:template_Source_Code_Review_OWASP_Projects&amp;diff=33900"/>
				<updated>2008-07-11T22:20:29Z</updated>
		
		<summary type="html">&lt;p&gt;Mdoylema: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;{| style=&amp;quot;width:100%&amp;quot; border=&amp;quot;0&amp;quot; align=&amp;quot;center&amp;quot;&lt;br /&gt;
 ! colspan=&amp;quot;7&amp;quot; align=&amp;quot;center&amp;quot; style=&amp;quot;background:#4058A0; color:white&amp;quot;|&amp;lt;font color=&amp;quot;white&amp;quot;&amp;gt;'''PROJECT IDENTIFICATION''' &lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;width:15%; background:#7B8ABD&amp;quot; align=&amp;quot;center&amp;quot;|'''Project Name'''&lt;br /&gt;
 | colspan=&amp;quot;6&amp;quot; style=&amp;quot;width:85%; background:#cccccc&amp;quot; align=&amp;quot;left&amp;quot;|&amp;lt;font color=&amp;quot;black&amp;quot;&amp;gt;'''OWASP Source Code Review OWASP-Projects Project''' &lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;width:15%; background:#7B8ABD&amp;quot; align=&amp;quot;center&amp;quot;| '''Short Project Description''' &lt;br /&gt;
 | colspan=&amp;quot;6&amp;quot; style=&amp;quot;width:85%; background:#cccccc&amp;quot; align=&amp;quot;left&amp;quot;|The objectives of this project are: 1. Develop and document a workflow for open source projects to incorporate static analysis into the Software Development Life Cycle (SDLC); 2. Apply the above workflow as a required step for OWASP projects; 3. Aid in auditing select open source projects to create a baseline for comparing security amongst open source projects. &lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;width:15%; background:#7B8ABD&amp;quot; align=&amp;quot;center&amp;quot;|'''Email Contacts'''&lt;br /&gt;
 | style=&amp;quot;width:14%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|Project Leader&amp;lt;br&amp;gt;[mailto:dan@denimgroup.com '''Dan Cornell''']&amp;lt;br&amp;gt;SoC's Project Leader&amp;lt;br&amp;gt;[mailto:waldenj1@nku.edu '''James Walden''']&lt;br /&gt;
 | style=&amp;quot;width:14%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|Project Contributors&amp;lt;br&amp;gt;[mailto:jderry@owasp.org '''Justin Derry''']&amp;lt;br&amp;gt;&lt;br /&gt;
[mailto:doylem3@nku.edu '''Maureen Doyle''']&amp;lt;br&amp;gt;&lt;br /&gt;
[mailto:whelanm87@gmail.com '''Michael Whelan''']&lt;br /&gt;
 | style=&amp;quot;width:14%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|[https://lists.owasp.org/mailman/listinfo/owasp-scode-review-owasp-projects '''Mailing List/Subscribe''']&amp;lt;br&amp;gt;[mailto:OWASP-SCode-Review-OWASP-Projects(at)lists.owasp.org '''Mailing List/Use''']&lt;br /&gt;
 | style=&amp;quot;width:14%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|First Reviewer&amp;lt;br&amp;gt;[mailto:afry(at)strongcrypto.biz '''Alex Fry''']&amp;lt;br&amp;gt;[http://www.linkedin.com/in/alexanderfry Profile]&lt;br /&gt;
 | style=&amp;quot;width:14%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|Second Reviewer&amp;lt;br&amp;gt;[mailto:marco.m.morana(at)gmail.com '''Marco M. Morana''']&amp;lt;br&amp;gt;[[OWASP Summer of Code 2008 Projects Authors Status Target and Reviewers Marco M Morana Curriculum|Curriculum]]&lt;br /&gt;
 | style=&amp;quot;width:15%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|OWASP Board Member&amp;lt;br&amp;gt;[mailto:name(at)name '''Name&amp;amp;Email''']&lt;br /&gt;
 |}&lt;br /&gt;
{| style=&amp;quot;width:100%&amp;quot; border=&amp;quot;0&amp;quot; align=&amp;quot;center&amp;quot;&lt;br /&gt;
 ! colspan=&amp;quot;6&amp;quot; align=&amp;quot;center&amp;quot; style=&amp;quot;background:#4058A0; color:white&amp;quot;|&amp;lt;font color=&amp;quot;white&amp;quot;&amp;gt;'''PROJECT MAIN LINKS''' &lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;width:100%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|&lt;br /&gt;
* 7/11/08 - Updated workflow [[Image:Workflow_July_11a.zip]]&lt;br /&gt;
* replaced 7/11/08 - [[Image:Workflow_Draft1.pdf]]&lt;br /&gt;
* replaced 7/11/08 - [[Image:CreateProjectExample.pdf]]&lt;br /&gt;
 |}&lt;br /&gt;
{| style=&amp;quot;width:100%&amp;quot; border=&amp;quot;0&amp;quot; align=&amp;quot;center&amp;quot;&lt;br /&gt;
 ! colspan=&amp;quot;6&amp;quot; align=&amp;quot;center&amp;quot; style=&amp;quot;background:#4058A0; color:white&amp;quot;|&amp;lt;font color=&amp;quot;white&amp;quot;&amp;gt;'''RELATED PROJECTS''' &lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;width:100%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|&lt;br /&gt;
[https://opensource.fortify.com/teamserver/welcome.fhtml Fortify Code Review Application]&lt;br /&gt;
 |}&lt;br /&gt;
{| style=&amp;quot;width:100%&amp;quot; border=&amp;quot;0&amp;quot; align=&amp;quot;center&amp;quot;&lt;br /&gt;
 ! colspan=&amp;quot;6&amp;quot; align=&amp;quot;center&amp;quot; style=&amp;quot;background:#4058A0; color:white&amp;quot;|&amp;lt;font color=&amp;quot;white&amp;quot;&amp;gt;'''SPONSORS &amp;amp; GUIDELINES''' &lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;width:50%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|[[OWASP Summer of Code 2008|Sponsor - '''OWASP Summer of Code 2008''']] &lt;br /&gt;
 | style=&amp;quot;width:50%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|[[OWASP Summer of Code 2008 Applications - Need Futher Clarifications#Source Code Review OWASP Projects|'''Sponsored Project/Guidelines/Roadmap''']]&lt;br /&gt;
 |}&lt;br /&gt;
{| style=&amp;quot;width:100%&amp;quot; border=&amp;quot;0&amp;quot; align=&amp;quot;center&amp;quot;&lt;br /&gt;
 ! colspan=&amp;quot;5&amp;quot; align=&amp;quot;center&amp;quot; style=&amp;quot;background:#4058A0; color:white&amp;quot;|ASSESSMENT AND REVIEW PROCESS&lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;width:15%; background:#6C82B5&amp;quot; align=&amp;quot;center&amp;quot;|'''Review/Reviewer''' &lt;br /&gt;
 | style=&amp;quot;width:21%; background:#b3b3b3&amp;quot; align=&amp;quot;center&amp;quot;|'''Author's Self Evaluation'''&amp;lt;br&amp;gt;(applicable for Alpha Quality &amp;amp; further) &lt;br /&gt;
 | style=&amp;quot;width:21%; background:#b3b3b3&amp;quot; align=&amp;quot;center&amp;quot;|'''First Reviewer'''&amp;lt;br&amp;gt;(applicable for Alpha Quality &amp;amp; further)&lt;br /&gt;
 | style=&amp;quot;width:21%; background:#b3b3b3&amp;quot; align=&amp;quot;center&amp;quot;|'''Second Reviewer'''&amp;lt;br&amp;gt;(applicable for Beta Quality &amp;amp; further)&lt;br /&gt;
 | style=&amp;quot;width:22%; background:#b3b3b3&amp;quot; align=&amp;quot;center&amp;quot;|'''OWASP Board Member'''&amp;lt;br&amp;gt;(applicable just for Release Quality) &lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;width:15%; background:#7B8ABD&amp;quot; align=&amp;quot;center&amp;quot;|'''50% Review''' &lt;br /&gt;
 | style=&amp;quot;width:21%; background:#C2C2C2&amp;quot; align=&amp;quot;center&amp;quot;|Objectives &amp;amp; Deliveries reached?&amp;lt;br&amp;gt;'''Yes/No''' (To update)&amp;lt;br&amp;gt;---------&amp;lt;br&amp;gt;[[Project Information:template Source Code Review OWASP Projects - 50 Review - Self Evaluation - A|See&amp;amp;Edit:50% Review/Self-Evaluation (A)]]&lt;br /&gt;
 | style=&amp;quot;width:21%; background:#C2C2C2&amp;quot; align=&amp;quot;center&amp;quot;|Objectives &amp;amp; Deliveries reached?&amp;lt;br&amp;gt;'''Yes/No''' (To update)&amp;lt;br&amp;gt;---------&amp;lt;br&amp;gt;[[Project Information:template Source Code Review OWASP Projects - 50 Review - First Reviewer - C|See&amp;amp;Edit: 50% Review/1st Reviewer (C)]]&lt;br /&gt;
 | style=&amp;quot;width:21%; background:#C2C2C2&amp;quot; align=&amp;quot;center&amp;quot;|Objectives &amp;amp; Deliveries reached?&amp;lt;br&amp;gt;'''Yes/No''' (To update)&amp;lt;br&amp;gt;---------&amp;lt;br&amp;gt;[[Project Information:template Source Code Review OWASP Projects 50 Review Second Review E|See&amp;amp;Edit: 50%Review/2nd Reviewer (E)]]&lt;br /&gt;
 | style=&amp;quot;width:22%; background:#C2C2C2&amp;quot; align=&amp;quot;center&amp;quot;|X &lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;width:15%; background:#7B8ABD&amp;quot; align=&amp;quot;center&amp;quot;|'''Final Review''' &lt;br /&gt;
 | style=&amp;quot;width:21%; background:#C2C2C2&amp;quot; align=&amp;quot;center&amp;quot;|Objectives &amp;amp; Deliveries reached?&amp;lt;br&amp;gt;'''Yes/No''' (To update)&amp;lt;br&amp;gt;---------&amp;lt;br&amp;gt;Which status has been reached?&amp;lt;br&amp;gt;'''Season of Code''' - (To update)&amp;lt;br&amp;gt;---------&amp;lt;br&amp;gt;[[Project Information:template Source Code Review OWASP Projects - Final Review - Self Evaluation - B|See&amp;amp;Edit: Final Review/SelfEvaluation (B)]]&lt;br /&gt;
 | style=&amp;quot;width:21%; background:#C2C2C2&amp;quot; align=&amp;quot;center&amp;quot;|Objectives &amp;amp; Deliveries reached?&amp;lt;br&amp;gt;'''Yes/No''' (To update)&amp;lt;br&amp;gt;---------&amp;lt;br&amp;gt;Which status has been reached?&amp;lt;br&amp;gt;'''Season of Code''' - (To update)&amp;lt;br&amp;gt;---------&amp;lt;br&amp;gt;[[Project Information:template Source Code Review OWASP Projects - Final Review - First Reviewer - D|See&amp;amp;Edit: Final Review/1st Reviewer (D)]]&lt;br /&gt;
 | style=&amp;quot;width:21%; background:#C2C2C2&amp;quot; align=&amp;quot;center&amp;quot;|Objectives &amp;amp; Deliveries reached?&amp;lt;br&amp;gt;'''Yes/No''' (To update)&amp;lt;br&amp;gt;---------&amp;lt;br&amp;gt;Which status has been reached?&amp;lt;br&amp;gt;'''Season of Code''' - (To update)&amp;lt;br&amp;gt;---------&amp;lt;br&amp;gt;[[Project Information:template Source Code Review OWASP Projects - Final Review - Second Reviewer - F|See&amp;amp;Edit: Final Review/2nd Reviewer (F)]]&lt;br /&gt;
 | style=&amp;quot;width:22%; background:#C2C2C2&amp;quot; align=&amp;quot;center&amp;quot;|Objectives &amp;amp; Deliveries reached?&amp;lt;br&amp;gt;'''Yes/No''' (To update)&amp;lt;br&amp;gt;---------&amp;lt;br&amp;gt;Which status has been reached?&amp;lt;br&amp;gt;'''Season of Code''' - (To update)&amp;lt;br&amp;gt;---------&amp;lt;br&amp;gt;[[Project Information:template Source Code Review OWASP Projects - Final Review - OWASP Board Member - G|See/Edit: Final Review/Board Member (G)]]&lt;br /&gt;
 |-&lt;br /&gt;
 |}&lt;/div&gt;</summary>
		<author><name>Mdoylema</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Project_Information:template_Source_Code_Review_OWASP_Projects&amp;diff=33899</id>
		<title>Project Information:template Source Code Review OWASP Projects</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Project_Information:template_Source_Code_Review_OWASP_Projects&amp;diff=33899"/>
				<updated>2008-07-11T22:18:15Z</updated>
		
		<summary type="html">&lt;p&gt;Mdoylema: Added workflow incorporating reviewer comments&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;{| style=&amp;quot;width:100%&amp;quot; border=&amp;quot;0&amp;quot; align=&amp;quot;center&amp;quot;&lt;br /&gt;
 ! colspan=&amp;quot;7&amp;quot; align=&amp;quot;center&amp;quot; style=&amp;quot;background:#4058A0; color:white&amp;quot;|&amp;lt;font color=&amp;quot;white&amp;quot;&amp;gt;'''PROJECT IDENTIFICATION''' &lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;width:15%; background:#7B8ABD&amp;quot; align=&amp;quot;center&amp;quot;|'''Project Name'''&lt;br /&gt;
 | colspan=&amp;quot;6&amp;quot; style=&amp;quot;width:85%; background:#cccccc&amp;quot; align=&amp;quot;left&amp;quot;|&amp;lt;font color=&amp;quot;black&amp;quot;&amp;gt;'''OWASP Source Code Review OWASP-Projects Project''' &lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;width:15%; background:#7B8ABD&amp;quot; align=&amp;quot;center&amp;quot;| '''Short Project Description''' &lt;br /&gt;
 | colspan=&amp;quot;6&amp;quot; style=&amp;quot;width:85%; background:#cccccc&amp;quot; align=&amp;quot;left&amp;quot;|The objectives of this project are: 1. Develop and document a workflow for open source projects to incorporate static analysis into the Software Development Life Cycle (SDLC); 2. Apply the above workflow as a required step for OWASP projects; 3. Aid in auditing select open source projects to create a baseline for comparing security amongst open source projects. &lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;width:15%; background:#7B8ABD&amp;quot; align=&amp;quot;center&amp;quot;|'''Email Contacts'''&lt;br /&gt;
 | style=&amp;quot;width:14%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|Project Leader&amp;lt;br&amp;gt;[mailto:dan@denimgroup.com '''Dan Cornell''']&amp;lt;br&amp;gt;SoC's Project Leader&amp;lt;br&amp;gt;[mailto:waldenj1@nku.edu '''James Walden''']&lt;br /&gt;
 | style=&amp;quot;width:14%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|Project Contributors&amp;lt;br&amp;gt;[mailto:jderry@owasp.org '''Justin Derry''']&amp;lt;br&amp;gt;&lt;br /&gt;
[mailto:doylem3@nku.edu '''Maureen Doyle''']&amp;lt;br&amp;gt;&lt;br /&gt;
[mailto:whelanm87@gmail.com '''Michael Whelan''']&lt;br /&gt;
 | style=&amp;quot;width:14%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|[https://lists.owasp.org/mailman/listinfo/owasp-scode-review-owasp-projects '''Mailing List/Subscribe''']&amp;lt;br&amp;gt;[mailto:OWASP-SCode-Review-OWASP-Projects(at)lists.owasp.org '''Mailing List/Use''']&lt;br /&gt;
 | style=&amp;quot;width:14%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|First Reviewer&amp;lt;br&amp;gt;[mailto:afry(at)strongcrypto.biz '''Alex Fry''']&amp;lt;br&amp;gt;[http://www.linkedin.com/in/alexanderfry Profile]&lt;br /&gt;
 | style=&amp;quot;width:14%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|Second Reviewer&amp;lt;br&amp;gt;[mailto:marco.m.morana(at)gmail.com '''Marco M. Morana''']&amp;lt;br&amp;gt;[[OWASP Summer of Code 2008 Projects Authors Status Target and Reviewers Marco M Morana Curriculum|Curriculum]]&lt;br /&gt;
 | style=&amp;quot;width:15%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|OWASP Board Member&amp;lt;br&amp;gt;[mailto:name(at)name '''Name&amp;amp;Email''']&lt;br /&gt;
 |}&lt;br /&gt;
{| style=&amp;quot;width:100%&amp;quot; border=&amp;quot;0&amp;quot; align=&amp;quot;center&amp;quot;&lt;br /&gt;
 ! colspan=&amp;quot;6&amp;quot; align=&amp;quot;center&amp;quot; style=&amp;quot;background:#4058A0; color:white&amp;quot;|&amp;lt;font color=&amp;quot;white&amp;quot;&amp;gt;'''PROJECT MAIN LINKS''' &lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;width:100%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|&lt;br /&gt;
* 7/11/08 - Updated workflow [[Image:Workflow_July11a.zip]]&lt;br /&gt;
* replaced 7/11/08 - [[Image:Workflow_Draft1.pdf]]&lt;br /&gt;
* replaced 7/11/08 - [[Image:CreateProjectExample.pdf]]&lt;br /&gt;
 |}&lt;br /&gt;
{| style=&amp;quot;width:100%&amp;quot; border=&amp;quot;0&amp;quot; align=&amp;quot;center&amp;quot;&lt;br /&gt;
 ! colspan=&amp;quot;6&amp;quot; align=&amp;quot;center&amp;quot; style=&amp;quot;background:#4058A0; color:white&amp;quot;|&amp;lt;font color=&amp;quot;white&amp;quot;&amp;gt;'''RELATED PROJECTS''' &lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;width:100%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|&lt;br /&gt;
[https://opensource.fortify.com/teamserver/welcome.fhtml Fortify Code Review Application]&lt;br /&gt;
 |}&lt;br /&gt;
{| style=&amp;quot;width:100%&amp;quot; border=&amp;quot;0&amp;quot; align=&amp;quot;center&amp;quot;&lt;br /&gt;
 ! colspan=&amp;quot;6&amp;quot; align=&amp;quot;center&amp;quot; style=&amp;quot;background:#4058A0; color:white&amp;quot;|&amp;lt;font color=&amp;quot;white&amp;quot;&amp;gt;'''SPONSORS &amp;amp; GUIDELINES''' &lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;width:50%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|[[OWASP Summer of Code 2008|Sponsor - '''OWASP Summer of Code 2008''']] &lt;br /&gt;
 | style=&amp;quot;width:50%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|[[OWASP Summer of Code 2008 Applications - Need Futher Clarifications#Source Code Review OWASP Projects|'''Sponsored Project/Guidelines/Roadmap''']]&lt;br /&gt;
 |}&lt;br /&gt;
{| style=&amp;quot;width:100%&amp;quot; border=&amp;quot;0&amp;quot; align=&amp;quot;center&amp;quot;&lt;br /&gt;
 ! colspan=&amp;quot;5&amp;quot; align=&amp;quot;center&amp;quot; style=&amp;quot;background:#4058A0; color:white&amp;quot;|ASSESSMENT AND REVIEW PROCESS&lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;width:15%; background:#6C82B5&amp;quot; align=&amp;quot;center&amp;quot;|'''Review/Reviewer''' &lt;br /&gt;
 | style=&amp;quot;width:21%; background:#b3b3b3&amp;quot; align=&amp;quot;center&amp;quot;|'''Author's Self Evaluation'''&amp;lt;br&amp;gt;(applicable for Alpha Quality &amp;amp; further) &lt;br /&gt;
 | style=&amp;quot;width:21%; background:#b3b3b3&amp;quot; align=&amp;quot;center&amp;quot;|'''First Reviewer'''&amp;lt;br&amp;gt;(applicable for Alpha Quality &amp;amp; further)&lt;br /&gt;
 | style=&amp;quot;width:21%; background:#b3b3b3&amp;quot; align=&amp;quot;center&amp;quot;|'''Second Reviewer'''&amp;lt;br&amp;gt;(applicable for Beta Quality &amp;amp; further)&lt;br /&gt;
 | style=&amp;quot;width:22%; background:#b3b3b3&amp;quot; align=&amp;quot;center&amp;quot;|'''OWASP Board Member'''&amp;lt;br&amp;gt;(applicable just for Release Quality) &lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;width:15%; background:#7B8ABD&amp;quot; align=&amp;quot;center&amp;quot;|'''50% Review''' &lt;br /&gt;
 | style=&amp;quot;width:21%; background:#C2C2C2&amp;quot; align=&amp;quot;center&amp;quot;|Objectives &amp;amp; Deliveries reached?&amp;lt;br&amp;gt;'''Yes/No''' (To update)&amp;lt;br&amp;gt;---------&amp;lt;br&amp;gt;[[Project Information:template Source Code Review OWASP Projects - 50 Review - Self Evaluation - A|See&amp;amp;Edit:50% Review/Self-Evaluation (A)]]&lt;br /&gt;
 | style=&amp;quot;width:21%; background:#C2C2C2&amp;quot; align=&amp;quot;center&amp;quot;|Objectives &amp;amp; Deliveries reached?&amp;lt;br&amp;gt;'''Yes/No''' (To update)&amp;lt;br&amp;gt;---------&amp;lt;br&amp;gt;[[Project Information:template Source Code Review OWASP Projects - 50 Review - First Reviewer - C|See&amp;amp;Edit: 50% Review/1st Reviewer (C)]]&lt;br /&gt;
 | style=&amp;quot;width:21%; background:#C2C2C2&amp;quot; align=&amp;quot;center&amp;quot;|Objectives &amp;amp; Deliveries reached?&amp;lt;br&amp;gt;'''Yes/No''' (To update)&amp;lt;br&amp;gt;---------&amp;lt;br&amp;gt;[[Project Information:template Source Code Review OWASP Projects 50 Review Second Review E|See&amp;amp;Edit: 50%Review/2nd Reviewer (E)]]&lt;br /&gt;
 | style=&amp;quot;width:22%; background:#C2C2C2&amp;quot; align=&amp;quot;center&amp;quot;|X &lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;width:15%; background:#7B8ABD&amp;quot; align=&amp;quot;center&amp;quot;|'''Final Review''' &lt;br /&gt;
 | style=&amp;quot;width:21%; background:#C2C2C2&amp;quot; align=&amp;quot;center&amp;quot;|Objectives &amp;amp; Deliveries reached?&amp;lt;br&amp;gt;'''Yes/No''' (To update)&amp;lt;br&amp;gt;---------&amp;lt;br&amp;gt;Which status has been reached?&amp;lt;br&amp;gt;'''Season of Code''' - (To update)&amp;lt;br&amp;gt;---------&amp;lt;br&amp;gt;[[Project Information:template Source Code Review OWASP Projects - Final Review - Self Evaluation - B|See&amp;amp;Edit: Final Review/SelfEvaluation (B)]]&lt;br /&gt;
 | style=&amp;quot;width:21%; background:#C2C2C2&amp;quot; align=&amp;quot;center&amp;quot;|Objectives &amp;amp; Deliveries reached?&amp;lt;br&amp;gt;'''Yes/No''' (To update)&amp;lt;br&amp;gt;---------&amp;lt;br&amp;gt;Which status has been reached?&amp;lt;br&amp;gt;'''Season of Code''' - (To update)&amp;lt;br&amp;gt;---------&amp;lt;br&amp;gt;[[Project Information:template Source Code Review OWASP Projects - Final Review - First Reviewer - D|See&amp;amp;Edit: Final Review/1st Reviewer (D)]]&lt;br /&gt;
 | style=&amp;quot;width:21%; background:#C2C2C2&amp;quot; align=&amp;quot;center&amp;quot;|Objectives &amp;amp; Deliveries reached?&amp;lt;br&amp;gt;'''Yes/No''' (To update)&amp;lt;br&amp;gt;---------&amp;lt;br&amp;gt;Which status has been reached?&amp;lt;br&amp;gt;'''Season of Code''' - (To update)&amp;lt;br&amp;gt;---------&amp;lt;br&amp;gt;[[Project Information:template Source Code Review OWASP Projects - Final Review - Second Reviewer - F|See&amp;amp;Edit: Final Review/2nd Reviewer (F)]]&lt;br /&gt;
 | style=&amp;quot;width:22%; background:#C2C2C2&amp;quot; align=&amp;quot;center&amp;quot;|Objectives &amp;amp; Deliveries reached?&amp;lt;br&amp;gt;'''Yes/No''' (To update)&amp;lt;br&amp;gt;---------&amp;lt;br&amp;gt;Which status has been reached?&amp;lt;br&amp;gt;'''Season of Code''' - (To update)&amp;lt;br&amp;gt;---------&amp;lt;br&amp;gt;[[Project Information:template Source Code Review OWASP Projects - Final Review - OWASP Board Member - G|See/Edit: Final Review/Board Member (G)]]&lt;br /&gt;
 |-&lt;br /&gt;
 |}&lt;/div&gt;</summary>
		<author><name>Mdoylema</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Project_Information:template_Source_Code_Review_OWASP_Projects&amp;diff=33898</id>
		<title>Project Information:template Source Code Review OWASP Projects</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Project_Information:template_Source_Code_Review_OWASP_Projects&amp;diff=33898"/>
				<updated>2008-07-11T22:17:04Z</updated>
		
		<summary type="html">&lt;p&gt;Mdoylema: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;{| style=&amp;quot;width:100%&amp;quot; border=&amp;quot;0&amp;quot; align=&amp;quot;center&amp;quot;&lt;br /&gt;
 ! colspan=&amp;quot;7&amp;quot; align=&amp;quot;center&amp;quot; style=&amp;quot;background:#4058A0; color:white&amp;quot;|&amp;lt;font color=&amp;quot;white&amp;quot;&amp;gt;'''PROJECT IDENTIFICATION''' &lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;width:15%; background:#7B8ABD&amp;quot; align=&amp;quot;center&amp;quot;|'''Project Name'''&lt;br /&gt;
 | colspan=&amp;quot;6&amp;quot; style=&amp;quot;width:85%; background:#cccccc&amp;quot; align=&amp;quot;left&amp;quot;|&amp;lt;font color=&amp;quot;black&amp;quot;&amp;gt;'''OWASP Source Code Review OWASP-Projects Project''' &lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;width:15%; background:#7B8ABD&amp;quot; align=&amp;quot;center&amp;quot;| '''Short Project Description''' &lt;br /&gt;
 | colspan=&amp;quot;6&amp;quot; style=&amp;quot;width:85%; background:#cccccc&amp;quot; align=&amp;quot;left&amp;quot;|The objectives of this project are: 1. Develop and document a workflow for open source projects to incorporate static analysis into the Software Development Life Cycle (SDLC); 2. Apply the above workflow as a required step for OWASP projects; 3. Aid in auditing select open source projects to create a baseline for comparing security amongst open source projects. &lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;width:15%; background:#7B8ABD&amp;quot; align=&amp;quot;center&amp;quot;|'''Email Contacts'''&lt;br /&gt;
 | style=&amp;quot;width:14%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|Project Leader&amp;lt;br&amp;gt;[mailto:dan@denimgroup.com '''Dan Cornell''']&amp;lt;br&amp;gt;SoC's Project Leader&amp;lt;br&amp;gt;[mailto:waldenj1@nku.edu '''James Walden''']&lt;br /&gt;
 | style=&amp;quot;width:14%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|Project Contributors&amp;lt;br&amp;gt;[mailto:jderry@owasp.org '''Justin Derry''']&amp;lt;br&amp;gt;&lt;br /&gt;
[mailto:doylem3@nku.edu '''Maureen Doyle''']&amp;lt;br&amp;gt;&lt;br /&gt;
[mailto:whelanm87@gmail.com '''Michael Whelan''']&lt;br /&gt;
 | style=&amp;quot;width:14%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|[https://lists.owasp.org/mailman/listinfo/owasp-scode-review-owasp-projects '''Mailing List/Subscribe''']&amp;lt;br&amp;gt;[mailto:OWASP-SCode-Review-OWASP-Projects(at)lists.owasp.org '''Mailing List/Use''']&lt;br /&gt;
 | style=&amp;quot;width:14%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|First Reviewer&amp;lt;br&amp;gt;[mailto:afry(at)strongcrypto.biz '''Alex Fry''']&amp;lt;br&amp;gt;[http://www.linkedin.com/in/alexanderfry Profile]&lt;br /&gt;
 | style=&amp;quot;width:14%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|Second Reviewer&amp;lt;br&amp;gt;[mailto:marco.m.morana(at)gmail.com '''Marco M. Morana''']&amp;lt;br&amp;gt;[[OWASP Summer of Code 2008 Projects Authors Status Target and Reviewers Marco M Morana Curriculum|Curriculum]]&lt;br /&gt;
 | style=&amp;quot;width:15%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|OWASP Board Member&amp;lt;br&amp;gt;[mailto:name(at)name '''Name&amp;amp;Email''']&lt;br /&gt;
 |}&lt;br /&gt;
{| style=&amp;quot;width:100%&amp;quot; border=&amp;quot;0&amp;quot; align=&amp;quot;center&amp;quot;&lt;br /&gt;
 ! colspan=&amp;quot;6&amp;quot; align=&amp;quot;center&amp;quot; style=&amp;quot;background:#4058A0; color:white&amp;quot;|&amp;lt;font color=&amp;quot;white&amp;quot;&amp;gt;'''PROJECT MAIN LINKS''' &lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;width:100%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|&lt;br /&gt;
* 7/11/08 - Updated workflow [[Image:Workflow July11a.zip]]&lt;br /&gt;
* replaced 7/11/08 - [[Image:Workflow_Draft1.pdf]]&lt;br /&gt;
* replaced 7/11/08 - [[Image:CreateProjectExample.pdf]]&lt;br /&gt;
 |}&lt;br /&gt;
{| style=&amp;quot;width:100%&amp;quot; border=&amp;quot;0&amp;quot; align=&amp;quot;center&amp;quot;&lt;br /&gt;
 ! colspan=&amp;quot;6&amp;quot; align=&amp;quot;center&amp;quot; style=&amp;quot;background:#4058A0; color:white&amp;quot;|&amp;lt;font color=&amp;quot;white&amp;quot;&amp;gt;'''RELATED PROJECTS''' &lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;width:100%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|&lt;br /&gt;
[https://opensource.fortify.com/teamserver/welcome.fhtml Fortify Code Review Application]&lt;br /&gt;
 |}&lt;br /&gt;
{| style=&amp;quot;width:100%&amp;quot; border=&amp;quot;0&amp;quot; align=&amp;quot;center&amp;quot;&lt;br /&gt;
 ! colspan=&amp;quot;6&amp;quot; align=&amp;quot;center&amp;quot; style=&amp;quot;background:#4058A0; color:white&amp;quot;|&amp;lt;font color=&amp;quot;white&amp;quot;&amp;gt;'''SPONSORS &amp;amp; GUIDELINES''' &lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;width:50%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|[[OWASP Summer of Code 2008|Sponsor - '''OWASP Summer of Code 2008''']] &lt;br /&gt;
 | style=&amp;quot;width:50%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|[[OWASP Summer of Code 2008 Applications - Need Futher Clarifications#Source Code Review OWASP Projects|'''Sponsored Project/Guidelines/Roadmap''']]&lt;br /&gt;
 |}&lt;br /&gt;
{| style=&amp;quot;width:100%&amp;quot; border=&amp;quot;0&amp;quot; align=&amp;quot;center&amp;quot;&lt;br /&gt;
 ! colspan=&amp;quot;5&amp;quot; align=&amp;quot;center&amp;quot; style=&amp;quot;background:#4058A0; color:white&amp;quot;|ASSESSMENT AND REVIEW PROCESS&lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;width:15%; background:#6C82B5&amp;quot; align=&amp;quot;center&amp;quot;|'''Review/Reviewer''' &lt;br /&gt;
 | style=&amp;quot;width:21%; background:#b3b3b3&amp;quot; align=&amp;quot;center&amp;quot;|'''Author's Self Evaluation'''&amp;lt;br&amp;gt;(applicable for Alpha Quality &amp;amp; further) &lt;br /&gt;
 | style=&amp;quot;width:21%; background:#b3b3b3&amp;quot; align=&amp;quot;center&amp;quot;|'''First Reviewer'''&amp;lt;br&amp;gt;(applicable for Alpha Quality &amp;amp; further)&lt;br /&gt;
 | style=&amp;quot;width:21%; background:#b3b3b3&amp;quot; align=&amp;quot;center&amp;quot;|'''Second Reviewer'''&amp;lt;br&amp;gt;(applicable for Beta Quality &amp;amp; further)&lt;br /&gt;
 | style=&amp;quot;width:22%; background:#b3b3b3&amp;quot; align=&amp;quot;center&amp;quot;|'''OWASP Board Member'''&amp;lt;br&amp;gt;(applicable just for Release Quality) &lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;width:15%; background:#7B8ABD&amp;quot; align=&amp;quot;center&amp;quot;|'''50% Review''' &lt;br /&gt;
 | style=&amp;quot;width:21%; background:#C2C2C2&amp;quot; align=&amp;quot;center&amp;quot;|Objectives &amp;amp; Deliveries reached?&amp;lt;br&amp;gt;'''Yes/No''' (To update)&amp;lt;br&amp;gt;---------&amp;lt;br&amp;gt;[[Project Information:template Source Code Review OWASP Projects - 50 Review - Self Evaluation - A|See&amp;amp;Edit:50% Review/Self-Evaluation (A)]]&lt;br /&gt;
 | style=&amp;quot;width:21%; background:#C2C2C2&amp;quot; align=&amp;quot;center&amp;quot;|Objectives &amp;amp; Deliveries reached?&amp;lt;br&amp;gt;'''Yes/No''' (To update)&amp;lt;br&amp;gt;---------&amp;lt;br&amp;gt;[[Project Information:template Source Code Review OWASP Projects - 50 Review - First Reviewer - C|See&amp;amp;Edit: 50% Review/1st Reviewer (C)]]&lt;br /&gt;
 | style=&amp;quot;width:21%; background:#C2C2C2&amp;quot; align=&amp;quot;center&amp;quot;|Objectives &amp;amp; Deliveries reached?&amp;lt;br&amp;gt;'''Yes/No''' (To update)&amp;lt;br&amp;gt;---------&amp;lt;br&amp;gt;[[Project Information:template Source Code Review OWASP Projects 50 Review Second Review E|See&amp;amp;Edit: 50%Review/2nd Reviewer (E)]]&lt;br /&gt;
 | style=&amp;quot;width:22%; background:#C2C2C2&amp;quot; align=&amp;quot;center&amp;quot;|X &lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;width:15%; background:#7B8ABD&amp;quot; align=&amp;quot;center&amp;quot;|'''Final Review''' &lt;br /&gt;
 | style=&amp;quot;width:21%; background:#C2C2C2&amp;quot; align=&amp;quot;center&amp;quot;|Objectives &amp;amp; Deliveries reached?&amp;lt;br&amp;gt;'''Yes/No''' (To update)&amp;lt;br&amp;gt;---------&amp;lt;br&amp;gt;Which status has been reached?&amp;lt;br&amp;gt;'''Season of Code''' - (To update)&amp;lt;br&amp;gt;---------&amp;lt;br&amp;gt;[[Project Information:template Source Code Review OWASP Projects - Final Review - Self Evaluation - B|See&amp;amp;Edit: Final Review/SelfEvaluation (B)]]&lt;br /&gt;
 | style=&amp;quot;width:21%; background:#C2C2C2&amp;quot; align=&amp;quot;center&amp;quot;|Objectives &amp;amp; Deliveries reached?&amp;lt;br&amp;gt;'''Yes/No''' (To update)&amp;lt;br&amp;gt;---------&amp;lt;br&amp;gt;Which status has been reached?&amp;lt;br&amp;gt;'''Season of Code''' - (To update)&amp;lt;br&amp;gt;---------&amp;lt;br&amp;gt;[[Project Information:template Source Code Review OWASP Projects - Final Review - First Reviewer - D|See&amp;amp;Edit: Final Review/1st Reviewer (D)]]&lt;br /&gt;
 | style=&amp;quot;width:21%; background:#C2C2C2&amp;quot; align=&amp;quot;center&amp;quot;|Objectives &amp;amp; Deliveries reached?&amp;lt;br&amp;gt;'''Yes/No''' (To update)&amp;lt;br&amp;gt;---------&amp;lt;br&amp;gt;Which status has been reached?&amp;lt;br&amp;gt;'''Season of Code''' - (To update)&amp;lt;br&amp;gt;---------&amp;lt;br&amp;gt;[[Project Information:template Source Code Review OWASP Projects - Final Review - Second Reviewer - F|See&amp;amp;Edit: Final Review/2nd Reviewer (F)]]&lt;br /&gt;
 | style=&amp;quot;width:22%; background:#C2C2C2&amp;quot; align=&amp;quot;center&amp;quot;|Objectives &amp;amp; Deliveries reached?&amp;lt;br&amp;gt;'''Yes/No''' (To update)&amp;lt;br&amp;gt;---------&amp;lt;br&amp;gt;Which status has been reached?&amp;lt;br&amp;gt;'''Season of Code''' - (To update)&amp;lt;br&amp;gt;---------&amp;lt;br&amp;gt;[[Project Information:template Source Code Review OWASP Projects - Final Review - OWASP Board Member - G|See/Edit: Final Review/Board Member (G)]]&lt;br /&gt;
 |-&lt;br /&gt;
 |}&lt;/div&gt;</summary>
		<author><name>Mdoylema</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=File:Workflow_July_11a.zip&amp;diff=33897</id>
		<title>File:Workflow July 11a.zip</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=File:Workflow_July_11a.zip&amp;diff=33897"/>
				<updated>2008-07-11T22:13:22Z</updated>
		
		<summary type="html">&lt;p&gt;Mdoylema: Updated Workflow for OWASP Source Code Review for OWASP Projects (OWASP Summer of Code 2008)&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;Updated Workflow for OWASP Source Code Review for OWASP Projects (OWASP Summer of Code 2008)&lt;/div&gt;</summary>
		<author><name>Mdoylema</name></author>	</entry>

	</feed>