<?xml version="1.0"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
		<id>https://wiki.owasp.org/api.php?action=feedcontributions&amp;feedformat=atom&amp;user=Njama</id>
		<title>OWASP - User contributions [en]</title>
		<link rel="self" type="application/atom+xml" href="https://wiki.owasp.org/api.php?action=feedcontributions&amp;feedformat=atom&amp;user=Njama"/>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php/Special:Contributions/Njama"/>
		<updated>2026-05-05T05:54:13Z</updated>
		<subtitle>User contributions</subtitle>
		<generator>MediaWiki 1.27.2</generator>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=ORPRO-process&amp;diff=53352</id>
		<title>ORPRO-process</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=ORPRO-process&amp;diff=53352"/>
				<updated>2009-02-08T15:54:11Z</updated>
		
		<summary type="html">&lt;p&gt;Njama: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;[[Image:ORPRO_process_detail_2.jpg]]&lt;br /&gt;
&lt;br /&gt;
* '''Project intake'''&lt;br /&gt;
** ''PIN.01: Communication with open source project.'' Proposals for open source projects to be reviewed can be sent to one of the ORPRO project leads. Alternatively, the project actively approach open source projects. The open source project must provide at least one primary contact.&lt;br /&gt;
** ''PIN.02: Check entry criteria.'' The open source project will be checked against entry criteria. Entry criteria are:&lt;br /&gt;
*** it must be widely used &lt;br /&gt;
*** its license must allow independent security review&lt;br /&gt;
*** the open source project team should be in a position to remediate security defects that are discovered&lt;br /&gt;
*** the programming language must be supported by ORPRO's automated source code scanners and manual review team&lt;br /&gt;
** ''PIN.03: Risk assessment.'' Before conducting manual reviews we perform a risk assessment on the open source software. The steps taken are:&lt;br /&gt;
*** based on typical business use, conduct a business impact assessment (BIA): determine the maximum business impact of loss of confidentiality, loss of integrity and unavailability of the software under review;&lt;br /&gt;
*** using the results of the BIA, conduct a threat assessment. The results are&lt;br /&gt;
**** critical information assets processed by the software under review;&lt;br /&gt;
**** main threats for the software under review;&lt;br /&gt;
**** prioritized list of source code to be reviewed, highest risk first. In its simplest forms, the list might be based on source code files or directories. In many cases, other ways to address this may be more appropriate: examples are high risk use cases, API calls, and interfaces;&lt;br /&gt;
** ''PIN.04: Assemble team.'' The project leads assigns a review project lead and the lead can additionally assemble a team of reviewers. Reviewers may be involved with architecture review, automated scanning, and/or manual review. &lt;br /&gt;
* '''Architecture review'''&lt;br /&gt;
** ''ARR.01: Obtain architecture information.'' If available, request architecture document from Open Source Project. Otherwise assess architecture based on the source code.&lt;br /&gt;
** ''ARR.02: Review architecture.'' Review architecture for security defects.&lt;br /&gt;
** ''ARR.03: Document results.'' Architecture defects are documented and disclosed to the open source project. In case of serious flaws, the Open Review may end with an advise at this stage and will not continue with code review.&lt;br /&gt;
* '''Review'''&lt;br /&gt;
** '''Automated code review'''&lt;br /&gt;
*** ''ACR.01: Configure tooling.'' Assuming the project uses a platform supported by [http://owasp.fortify.com/ owasp.fortify.com], the source code is run through automated analysis.&lt;br /&gt;
*** ''ACR.02: Run tool on project.'' For more information on this process, see the [http://www.owasp.org/index.php/Category:OWASP_Open_Review_Project_owasp.fortify.com_FAQ OWASP Open Review owasp.fortify.com FAQ]&lt;br /&gt;
*** ''ACR.03: Review findings.'' Defects discovered are manually reviewed.&lt;br /&gt;
*** ''ACR.04: Document results.'' Defects are communicated to the owners of the open source project for remediation.&lt;br /&gt;
** '''Manual code review'''&lt;br /&gt;
*** ''MCR.01: Configure tooling.'' For collaborating on manual reviews ORPRO will be setting up tooling. The tooling needs to be configured for the software under review.&lt;br /&gt;
*** ''MCR.02: Perform manual review.'' The manual review is being performed under supervision of the review project lead. The review project lead assigns source code to individual reviewers. The results from PI.03 (Risk assessment) have specified the prioritization of the reviews to be performed. &lt;br /&gt;
*** ''MCR.03: Document results.'' Identified defects are documented and reported to the owners of the open source project for remediation.&lt;br /&gt;
* '''Reporting'''&lt;br /&gt;
** ''REP.01: Report issues to project.'' Either reviewers or the open source project leaders responsibly disclose the identified security issues. &lt;br /&gt;
** ''REP.02: Final report at OWASP site.'' After finishing a review and having responsibly disclosed security defects ORPRO will document the results on the OWASP site for educational purposes. Apart from the defects being documented details should be made available on the coverage of automated and manual review and the specific defects found by either method.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
The ORPRO project is a relatively new effort and it is expected that these processes will develop and change over time to accommodate new situations as they arise.&lt;/div&gt;</summary>
		<author><name>Njama</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=File:ORPRO_process_detail_2.jpg&amp;diff=53351</id>
		<title>File:ORPRO process detail 2.jpg</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=File:ORPRO_process_detail_2.jpg&amp;diff=53351"/>
				<updated>2009-02-08T15:43:39Z</updated>
		
		<summary type="html">&lt;p&gt;Njama: uploaded a new version of &amp;quot;Image:ORPRO process detail 2.jpg&amp;quot;&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;&lt;/div&gt;</summary>
		<author><name>Njama</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=File:ORPRO_process_detail_2.jpg&amp;diff=53350</id>
		<title>File:ORPRO process detail 2.jpg</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=File:ORPRO_process_detail_2.jpg&amp;diff=53350"/>
				<updated>2009-02-08T15:41:59Z</updated>
		
		<summary type="html">&lt;p&gt;Njama: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;&lt;/div&gt;</summary>
		<author><name>Njama</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=File:ORPRO_process_3.jpg&amp;diff=53349</id>
		<title>File:ORPRO process 3.jpg</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=File:ORPRO_process_3.jpg&amp;diff=53349"/>
				<updated>2009-02-08T15:38:44Z</updated>
		
		<summary type="html">&lt;p&gt;Njama: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;&lt;/div&gt;</summary>
		<author><name>Njama</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Category:OWASP_Open_Review_Project&amp;diff=53348</id>
		<title>Category:OWASP Open Review Project</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Category:OWASP_Open_Review_Project&amp;diff=53348"/>
				<updated>2009-02-08T15:38:14Z</updated>
		
		<summary type="html">&lt;p&gt;Njama: /* Open review process */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;[[:Category:OWASP Project|Click here to return to OWASP Projects page.]]&amp;lt;br&amp;gt;&lt;br /&gt;
[[:Project Information:template Open Review Project|Click here to see (&amp;amp; edit, if wanted) the template.]] &lt;br /&gt;
{{:Project Information:template Open Review Project}}&lt;br /&gt;
[[Category:OWASP Project]]&lt;br /&gt;
&lt;br /&gt;
== Overview ==&lt;br /&gt;
We are surrounded by open source software. Not only the open source software all of us use, also many of the commercial applications contain open source libraries. Think of server and desktop software, but don't forget routers, cars, phones, open source is everywhere.&lt;br /&gt;
&lt;br /&gt;
The OWASP Open Review Project (ORPRO) exists to act as a resource for open source projects and for the community in general.  The goal is to provides facilities for both automated and manual review of open source applications and libraries.&lt;br /&gt;
&lt;br /&gt;
Fortify Software has made their [http://www.fortify.com/products/detect/in_development.jsp Source Code Analyzer (SCA) technology] available to open source projects at [http://owasp.fortify.com owasp.fortify.com].  See the [http://www.owasp.org/index.php/Category:OWASP_Open_Review_Project_owasp.fortify.com_FAQ owasp.fortify.com FAQ] for more information.&lt;br /&gt;
&lt;br /&gt;
== Project Goals ==&lt;br /&gt;
* Provide an independent security review of open source projects with a record of what has been reviewed and by whom in order to best communicate the security state of the open source projects.  This will include both automated and manual review of source code as well as analysis of algorithms such as compression, crypto, etc&lt;br /&gt;
* Provide resources to the community to centrally manage the review of open source projects&lt;br /&gt;
* Engage in responsible disclosure of any security vulnerabilities discovered&lt;br /&gt;
&lt;br /&gt;
== Project Planning ==&lt;br /&gt;
* Settle overlap between OWASP projects: August 2008 (completed)&lt;br /&gt;
* Initial tool selection and implementation: September 2008 (completed)&lt;br /&gt;
* Roll out automated review capabilities for a limited set of projects: September 2008 (completed)&lt;br /&gt;
* First reviews: October 2008 (ongoing: first project has been selected)&lt;br /&gt;
&lt;br /&gt;
== Open review process ==&lt;br /&gt;
The high level process is as follows:&lt;br /&gt;
&lt;br /&gt;
[[Image:ORPRO_process_3.jpg]]&lt;br /&gt;
&lt;br /&gt;
Click [[ORPRO-process|here]] for a more detailed process description.&lt;br /&gt;
&lt;br /&gt;
== Related OWASP Projects ==&lt;br /&gt;
The following OWASP projects have a direct relation with ORPRO:&lt;br /&gt;
* [http://www.owasp.org/index.php/Category:OWASP_Application_Security_Verification_Standard_Project OWASP Application Security Verification Standard Project]&lt;br /&gt;
* [http://www.owasp.org/index.php/Category:OWASP_Code_Review_Project OWASP Code Review Project]&lt;br /&gt;
* [http://www.owasp.org/index.php/Category:OWASP_Orizon_Project OWASP Orizon Project]&lt;br /&gt;
&lt;br /&gt;
== News ==&lt;br /&gt;
* '''5 June 2008'''   OWASP ORPRO launched&lt;br /&gt;
* '''12 September 2008''' [http://owasp.fortify.com/ owasp.fortify.com] made available as a public beta for automated source code review of open source projects&lt;br /&gt;
&lt;br /&gt;
== Get involved ==&lt;br /&gt;
Security review takes both time and expertise. We need people with good secure coding skills in C, C++, .NET, Java, PHP, etc who also have the audacity to review some of the most popular open source projects around.&lt;br /&gt;
&lt;br /&gt;
We also need open source project leaders to submit their projects for review.  If you run an open source project and are interested in participating, please email the mailing list.&lt;br /&gt;
&lt;br /&gt;
Please go to https://lists.owasp.org/mailman/listinfo/open-review-project to subscribe to the list. You can post to the ORPRO mailing list by emailing [mailto:open-review-project@lists.owasp.org open-review-project@lists.owasp.org].&lt;br /&gt;
&lt;br /&gt;
== People ==&lt;br /&gt;
Project leads: [[User:Njama|Mario de Boer]], [[User:Dancornell|Dan Cornell]].&lt;br /&gt;
&lt;br /&gt;
Contributors: [http://www.fortify.com Fortify Software] has generously made their Source Code Analyzer (SCA) technology available for use by open source projects at [http://owasp.fortify.com/ owasp.fortify.com].&lt;br /&gt;
&lt;br /&gt;
[[Category:OWASP Project]]&lt;/div&gt;</summary>
		<author><name>Njama</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=ORPRO-process&amp;diff=53341</id>
		<title>ORPRO-process</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=ORPRO-process&amp;diff=53341"/>
				<updated>2009-02-08T14:38:08Z</updated>
		
		<summary type="html">&lt;p&gt;Njama: Changes in RA&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;[[Image:ORPRO_process_detail_1.jpg]]&lt;br /&gt;
&lt;br /&gt;
* '''Project intake'''&lt;br /&gt;
** ''PI.01: Communication with open source project.'' Proposals for open source projects to be reviewed can be sent to one of the ORPRO project leads. Alternatively, the project actively approach open source projects. The open source project must provide at least one primary contact.&lt;br /&gt;
** ''PI.02: Check entry criteria.'' The open source project will be checked against entry criteria. Entry criteria are:&lt;br /&gt;
*** it must be widely used &lt;br /&gt;
*** its license must allow independent security review&lt;br /&gt;
*** the open source project team should be in a position to remediate security defects that are discovered&lt;br /&gt;
*** the programming language must be supported by ORPRO's automated source code scanners and manual review team&lt;br /&gt;
** ''PI.03: Risk assessment.'' Before conducting manual reviews we perform a risk assessment on the open source software. The steps taken are:&lt;br /&gt;
*** based on typical business use, conduct a business impact assessment (BIA): determine the maximum business impact of loss of confidentiality, loss of integrity and unavailability of the software under review;&lt;br /&gt;
*** using the results of the BIA, conduct a threat assessment. The results are&lt;br /&gt;
**** critical information assets processed by the software under review;&lt;br /&gt;
**** main threats for the software under review;&lt;br /&gt;
**** prioritized list of source code to be reviewed, highest risk first. In its simplest forms, the list might be based on source code files or directories. In many cases, other ways to address this may be more appropriate: examples are high risk use cases, API calls, and interfaces;&lt;br /&gt;
** ''PI.04: Assemble team.'' The project leads assigns a review project lead and the lead can additionally assemble a team of reviewers. Reviewers may be involved with automated scanning, manual review, or both. &lt;br /&gt;
* '''Review'''&lt;br /&gt;
** '''Automated review'''&lt;br /&gt;
*** ''AR.01: Configure tooling.'' Assuming the project uses a platform supported by [http://owasp.fortify.com/ owasp.fortify.com], the source code is run through automated analysis.&lt;br /&gt;
*** ''AR.02: Run tool on project.'' For more information on this process, see the [http://www.owasp.org/index.php/Category:OWASP_Open_Review_Project_owasp.fortify.com_FAQ OWASP Open Review owasp.fortify.com FAQ]&lt;br /&gt;
*** ''AR.03: Review findings.'' Defects discovered are manually reviewed.&lt;br /&gt;
*** ''AR.04: Document results.'' Defects are communicated to the owners of the open source project for remediation.&lt;br /&gt;
** '''Manual Review'''&lt;br /&gt;
*** ''MR.01: Configure tooling.'' For collaborating on manual reviews ORPRO will be setting up tooling. The tooling needs to be configured for the software under review.&lt;br /&gt;
*** ''MR.02: Perform manual review.'' The manual review is being performed under supervision of the review project lead. The review project lead assigns source code to individual reviewers. The results from PI.03 (Risk assessment) have specified the prioritization of the reviews to be performed. &lt;br /&gt;
*** ''MR.03: Document results.'' Identified defects are documented and reported to the owners of the open source project for remediation.&lt;br /&gt;
* '''Reporting'''&lt;br /&gt;
** ''RE.01: Report issues to project.'' Either reviewers or the open source project leaders responsibly disclose the identified security issues. &lt;br /&gt;
** ''RE.02: Final report at OWASP site.'' After finishing a review and having responsibly disclosed security defects ORPRO will document the results on the OWASP site for educational purposes. Apart from the defects being documented details should be made available on the coverage of automated and manual review and the specific defects found by either method.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
The ORPRO project is a relatively new effort and it is expected that these processes will develop and change over time to accommodate new situations as they arise.&lt;/div&gt;</summary>
		<author><name>Njama</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=ORPRO-process&amp;diff=45255</id>
		<title>ORPRO-process</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=ORPRO-process&amp;diff=45255"/>
				<updated>2008-10-31T10:57:49Z</updated>
		
		<summary type="html">&lt;p&gt;Njama: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;[[Image:ORPRO_process_detail_1.jpg]]&lt;br /&gt;
&lt;br /&gt;
* '''Project intake'''&lt;br /&gt;
** ''PI.01: Communication with open source project.'' Proposals for open source projects to be reviewed can be sent to one of the ORPRO project leads. Alternatively, the project actively approach open source projects. The open source project must provide at least one primary contact.&lt;br /&gt;
** ''PI.02: Check entry criteria.'' The open source project will be checked against entry criteria. Entry criteria are:&lt;br /&gt;
*** it must be widely used &lt;br /&gt;
*** its license must allow independent security review&lt;br /&gt;
*** the open source project team should be in a position to remediate security defects that are discovered&lt;br /&gt;
*** the programming language must be supported by ORPRO's automated source code scanners and manual review team&lt;br /&gt;
** ''PI.03: Risk assessment.'' Before conducting manual reviews we perform a risk assessment on the open source software. The minimum results must be:&lt;br /&gt;
*** main threats for the particular software&lt;br /&gt;
*** prioritized list of source code to be reviewed, highest risk first.&lt;br /&gt;
** ''PI.04: Assemble team.'' The project leads assigns a review project lead and the lead can additionally assemble a team of reviewers. Reviewers may be involved with automated scanning, manual review, or both. &lt;br /&gt;
* '''Review'''&lt;br /&gt;
** '''Automated review'''&lt;br /&gt;
*** ''AR.01: Configure tooling.'' Assuming the project uses a platform supported by [http://owasp.fortify.com/ owasp.fortify.com], the source code is run through automated analysis.&lt;br /&gt;
*** ''AR.02: Run tool on project.'' For more information on this process, see the [http://www.owasp.org/index.php/Category:OWASP_Open_Review_Project_owasp.fortify.com_FAQ OWASP Open Review owasp.fortify.com FAQ]&lt;br /&gt;
*** ''AR.03: Review findings.'' Defects discovered are manually reviewed.&lt;br /&gt;
*** ''AR.04: Document results.'' Defects are communicated to the owners of the open source project for remediation.&lt;br /&gt;
** '''Manual Review'''&lt;br /&gt;
*** ''MR.01: Configure tooling.'' For collaborating on manual reviews ORPRO will be setting up tooling. The tooling needs to be configured for the software under review.&lt;br /&gt;
*** ''MR.02: Perform manual review.'' The manual review is being performed under supervision of the review project lead. The review project lead assigns source code to individual reviewers. The results from PI.03 (Risk assessment) have specified the prioritization of the reviews to be performed. &lt;br /&gt;
*** ''MR.03: Document results.'' Identified defects are documented and reported to the owners of the open source project for remediation.&lt;br /&gt;
* '''Reporting'''&lt;br /&gt;
** ''RE.01: Report issues to project.'' Either reviewers or the open source project leaders responsibly disclose the identified security issues. &lt;br /&gt;
** ''RE.02: Final report at OWASP site.'' After finishing a review and having responsibly disclosed security defects ORPRO will document the results on the OWASP site for educational purposes. Apart from the defects being documented details should be made available on the coverage of automated and manual review and the specific defects found by either method.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
The ORPRO project is a relatively new effort and it is expected that these processes will develop and change over time to accommodate new situations as they arise.&lt;/div&gt;</summary>
		<author><name>Njama</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=ORPRO-process&amp;diff=45252</id>
		<title>ORPRO-process</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=ORPRO-process&amp;diff=45252"/>
				<updated>2008-10-31T10:38:09Z</updated>
		
		<summary type="html">&lt;p&gt;Njama: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;[[Image:ORPRO_process_detail_1.jpg]]&lt;br /&gt;
&lt;br /&gt;
* '''Project intake'''&lt;br /&gt;
** ''PI.01: Communication with open source project.'' Proposals for open source projects to be reviewed can be sent to one of the ORPRO project leads. Alternatively, the project actively approache open source projects. The open soure project must provide at least one primary contact.&lt;br /&gt;
** ''PI.02: Check entry criteria.'' The open source project will be checked against entry criteria. Entry criteria are:&lt;br /&gt;
*** it must be widely used &lt;br /&gt;
*** its license must allow independent security review&lt;br /&gt;
*** the open source project team should be in a position to remediate security defects that are discovered&lt;br /&gt;
*** the programming language must be supported by ORPRO's automated source code scanners and manual review team&lt;br /&gt;
** ''PI.03: Risk assessment.'' &lt;br /&gt;
** ''PI.04: Assemble team.'' The project lead assigns a review project lead and the lead can additionally select a team of reviewers.&lt;br /&gt;
* '''Review'''&lt;br /&gt;
** '''Automated review'''&lt;br /&gt;
*** Assuming the project uses a platform supported by [http://owasp.fortify.com/ owasp.fortify.com], the source code is run through automated analysis.  Defects discovered are manually reviewed and then communicated to the owners of the open source project for remediation.  For more information on this process, see the [http://www.owasp.org/index.php/Category:OWASP_Open_Review_Project_owasp.fortify.com_FAQ OWASP Open Review owasp.fortify.com FAQ]&lt;br /&gt;
*** ''AR.01: Configure tooling.''&lt;br /&gt;
*** ''AR.02: Run tool on project.''&lt;br /&gt;
*** ''AR.03: Review findings.''&lt;br /&gt;
*** ''AR.04: Document results.''&lt;br /&gt;
** '''Manual Review'''&lt;br /&gt;
*** ''MR.01: Configure tooling.''&lt;br /&gt;
*** ''MR.02: Perform manual review.''&lt;br /&gt;
*** ''MR.03: Document results.''&lt;br /&gt;
*** Reviewers manually review the application design and source code and communicate identified issues to the owners of the open source project for remediation.&lt;br /&gt;
* '''Reporting'''&lt;br /&gt;
** ''RE.01: Report issues to project.'' Either reviewers or the open source project leaders responsibly disclose the identified security issues&lt;br /&gt;
** ''RE.02: Final report at OWASP site.''&lt;br /&gt;
&lt;br /&gt;
The ORPRO project is a relatively new effort and it is expected that these processes will develop and change over time to accommodate new situations as they arise.&lt;/div&gt;</summary>
		<author><name>Njama</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=ORPRO-process&amp;diff=45251</id>
		<title>ORPRO-process</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=ORPRO-process&amp;diff=45251"/>
				<updated>2008-10-31T10:30:31Z</updated>
		
		<summary type="html">&lt;p&gt;Njama: Documented activities&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;[[Image:ORPRO_process_detail_1.jpg]]&lt;br /&gt;
&lt;br /&gt;
* '''Project intake'''&lt;br /&gt;
** ''PI.01: Communication with Open source project.'' Proposals for open source projects to be reviewed can be sent to one of the ORPRO project leads. &lt;br /&gt;
** ''PI.02: Check entry criteria.'' The open source project will be checked against some entry criteria - for example the open source project team should be in a position to remediate security defects that are discovered.&lt;br /&gt;
** ''PI.03: Risk assessment.''&lt;br /&gt;
** ''PI.04: Assemble team.'' The project lead assigns a review project lead and the lead can additionally select a team of reviewers.&lt;br /&gt;
* '''Review'''&lt;br /&gt;
** '''Automated review'''&lt;br /&gt;
*** Assuming the project uses a platform supported by [http://owasp.fortify.com/ owasp.fortify.com], the source code is run through automated analysis.  Defects discovered are manually reviewed and then communicated to the owners of the open source project for remediation.  For more information on this process, see the [http://www.owasp.org/index.php/Category:OWASP_Open_Review_Project_owasp.fortify.com_FAQ OWASP Open Review owasp.fortify.com FAQ]&lt;br /&gt;
*** ''AR.01: Configure tooling.''&lt;br /&gt;
*** ''AR.02: Run tool on project.''&lt;br /&gt;
*** ''AR.03: Review findings.''&lt;br /&gt;
*** ''AR.04: Document results.''&lt;br /&gt;
** '''Manual Review'''&lt;br /&gt;
*** ''MR.01: Configure tooling.''&lt;br /&gt;
*** ''MR.02: Perform manual review.''&lt;br /&gt;
*** ''MR.03: Document results.''&lt;br /&gt;
*** Reviewers manually review the application design and source code and communicate identified issues to the owners of the open source project for remediation.&lt;br /&gt;
* '''Reporting'''&lt;br /&gt;
** ''RE.01: Report issues to project.'' Either reviewers or the open source project leaders responsibly disclose the identified security issues&lt;br /&gt;
** ''RE.02: Final report at OWASP site.''&lt;br /&gt;
&lt;br /&gt;
The ORPRO project is a relatively new effort and it is expected that these processes will develop and change over time to accommodate new situations as they arise.&lt;/div&gt;</summary>
		<author><name>Njama</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=File:ORPRO_process_detail_1.jpg&amp;diff=45250</id>
		<title>File:ORPRO process detail 1.jpg</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=File:ORPRO_process_detail_1.jpg&amp;diff=45250"/>
				<updated>2008-10-31T10:05:39Z</updated>
		
		<summary type="html">&lt;p&gt;Njama: Orpro detailed activities&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;Orpro detailed activities&lt;/div&gt;</summary>
		<author><name>Njama</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=ORPRO-process&amp;diff=45249</id>
		<title>ORPRO-process</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=ORPRO-process&amp;diff=45249"/>
				<updated>2008-10-31T10:04:37Z</updated>
		
		<summary type="html">&lt;p&gt;Njama: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;[[Image:ORPRO_process_detail_1.jpg]]&lt;br /&gt;
&lt;br /&gt;
* Project intake&lt;br /&gt;
** Proposals for open source projets to be reviewed can be sent to the ORPRO project lead.  The open source project will be checked against some entry criteria - for example the open source project team should be in a position to remediate security defects that are discovered.&lt;br /&gt;
* Team Development&lt;br /&gt;
** The project lead assigns a review project lead and the lead can additionally select a team of reviewers.&lt;br /&gt;
* Review&lt;br /&gt;
** Assuming the project uses a platform supported by [http://owasp.fortify.com/ owasp.fortify.com], the source code is run through automated analysis.  Defects discovered are manually reviewed and then communicated to the owners of the open source project for remediation.  For more information on this process, see the [http://www.owasp.org/index.php/Category:OWASP_Open_Review_Project_owasp.fortify.com_FAQ OWASP Open Review owasp.fortify.com FAQ]&lt;br /&gt;
** Reviewers manually review the application design and source code and communicate identified issues to the owners of the open source project for remediation.&lt;br /&gt;
** Either reviewers or the open source project leaders responsibly disclose the identified security issues&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
The ORPRO project is a relatively new effort and it is expected that these processes will develop and change over time to accommodate new situations as they arise.&lt;/div&gt;</summary>
		<author><name>Njama</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=File:ORPRO_process_2.jpg&amp;diff=45248</id>
		<title>File:ORPRO process 2.jpg</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=File:ORPRO_process_2.jpg&amp;diff=45248"/>
				<updated>2008-10-31T10:03:10Z</updated>
		
		<summary type="html">&lt;p&gt;Njama: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;&lt;/div&gt;</summary>
		<author><name>Njama</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Category:OWASP_Open_Review_Project&amp;diff=45247</id>
		<title>Category:OWASP Open Review Project</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Category:OWASP_Open_Review_Project&amp;diff=45247"/>
				<updated>2008-10-31T10:02:44Z</updated>
		
		<summary type="html">&lt;p&gt;Njama: /* Open review process */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;[[:Category:OWASP Project|Click here to return to OWASP Projects page.]]&amp;lt;br&amp;gt;&lt;br /&gt;
[[:Project Information:template Open Review Project|Click here to see (&amp;amp; edit, if wanted) the template.]] &lt;br /&gt;
{{:Project Information:template Open Review Project}}&lt;br /&gt;
[[Category:OWASP Project]]&lt;br /&gt;
&lt;br /&gt;
== Overview ==&lt;br /&gt;
We are surrounded by open source software. Not only the open source software all of us use, also many of the commercial applications contain open source libraries. Think of server and desktop software, but don't forget routers, cars, phones, open source is everywhere.&lt;br /&gt;
&lt;br /&gt;
The OWASP Open Review Project (ORPRO) exists to act as a resource for open source projects and for the community in general.  The goal is to provides facilities for both automated and manual review of open source applications and libraries.&lt;br /&gt;
&lt;br /&gt;
Fortify Software has made their [http://www.fortify.com/products/detect/in_development.jsp Source Code Analyzer (SCA) technology] available to open source projects at [http://owasp.fortify.com owasp.fortify.com]&lt;br /&gt;
&lt;br /&gt;
== Project Goals ==&lt;br /&gt;
* Provide an independent security review of open source projects with a record of what has been reviewed and by whom in order to best communicate the security state of the open source projects.  This will include both automated and manual review of source code as well as analysis of algorithms such as compression, crypto, etc&lt;br /&gt;
* Provide resources to the community to centrally manage the review of open source projects&lt;br /&gt;
* Engage in responsible disclosure of any security vulnerabilities discovered&lt;br /&gt;
&lt;br /&gt;
== Project Planning ==&lt;br /&gt;
* Settle overlap between OWASP projects: August 2008 (completed)&lt;br /&gt;
* Initial tool selection and implementation: September 2008 (completed)&lt;br /&gt;
* Roll out automated review capabilities for a limited set of projects: September 2008 (completed)&lt;br /&gt;
* First reviews: October 2008 (ongoing: first project has been selected)&lt;br /&gt;
&lt;br /&gt;
== Open review process ==&lt;br /&gt;
The high level process is as follows:&lt;br /&gt;
&lt;br /&gt;
[[Image:ORPRO_process_2.jpg]]&lt;br /&gt;
&lt;br /&gt;
Click [[ORPRO-process|here]] for a more detailed process description.&lt;br /&gt;
&lt;br /&gt;
== Related OWASP Projects ==&lt;br /&gt;
The following OWASP projects have a direct relation with ORPRO:&lt;br /&gt;
* [http://www.owasp.org/index.php/Category:OWASP_Application_Security_Verification_Standard_Project OWASP Application Security Verification Standard Project]&lt;br /&gt;
* [http://www.owasp.org/index.php/Category:OWASP_Code_Review_Project OWASP Code Review Project]&lt;br /&gt;
* [http://www.owasp.org/index.php/Category:OWASP_Orizon_Project OWASP Orizon Project]&lt;br /&gt;
&lt;br /&gt;
== News ==&lt;br /&gt;
* '''5 June 2008'''   OWASP ORPRO launched&lt;br /&gt;
* '''12 September 2008''' [http://owasp.fortify.com/ owasp.fortify.com] made available as a public beta for automated source code review of open source projects&lt;br /&gt;
&lt;br /&gt;
== Get involved ==&lt;br /&gt;
Security review takes both time and expertise. We need people with good secure coding skills in C, C++, .NET, Java, PHP, etc who also have the audacity to review some of the most popular open source projects around.&lt;br /&gt;
&lt;br /&gt;
We also need open source project leaders to submit their projects for review.  If you run an open source project and are interested in participating, please email the mailing list.&lt;br /&gt;
&lt;br /&gt;
Please go to https://lists.owasp.org/mailman/listinfo/open-review-project to subscribe to the list. You can post to the ORPRO mailing list by emailing [mailto:open-review-project@lists.owasp.org open-review-project@lists.owasp.org].&lt;br /&gt;
&lt;br /&gt;
== People ==&lt;br /&gt;
Project leads: [[User:Njama|Mario de Boer]], [[User:Dancornell|Dan Cornell]].&lt;br /&gt;
&lt;br /&gt;
Contributors: [http://www.fortify.com Fortify Software] has generously made their Source Code Analyzer (SCA) technology available for use by open source projects at [http://owasp.fortify.com/ owasp.fortify.com].&lt;br /&gt;
&lt;br /&gt;
[[Category:OWASP Project]]&lt;/div&gt;</summary>
		<author><name>Njama</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=ORPRO-process&amp;diff=45246</id>
		<title>ORPRO-process</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=ORPRO-process&amp;diff=45246"/>
				<updated>2008-10-31T08:51:04Z</updated>
		
		<summary type="html">&lt;p&gt;Njama: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;* Project intake&lt;br /&gt;
** Proposals for open source projets to be reviewed can be sent to the ORPRO project lead.  The open source project will be checked against some entry criteria - for example the open source project team should be in a position to remediate security defects that are discovered.&lt;br /&gt;
* Team Development&lt;br /&gt;
** The project lead assigns a review project lead and the lead can additionally select a team of reviewers.&lt;br /&gt;
* Review&lt;br /&gt;
** Assuming the project uses a platform supported by [http://owasp.fortify.com/ owasp.fortify.com], the source code is run through automated analysis.  Defects discovered are manually reviewed and then communicated to the owners of the open source project for remediation.  For more information on this process, see the [http://www.owasp.org/index.php/Category:OWASP_Open_Review_Project_owasp.fortify.com_FAQ OWASP Open Review owasp.fortify.com FAQ]&lt;br /&gt;
** Reviewers manually review the application design and source code and communicate identified issues to the owners of the open source project for remediation.&lt;br /&gt;
** Either reviewers or the open source project leaders responsibly disclose the identified security issues&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
The ORPRO project is a relatively new effort and it is expected that these processes will develop and change over time to accommodate new situations as they arise.&lt;/div&gt;</summary>
		<author><name>Njama</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=ORPRO-process&amp;diff=45245</id>
		<title>ORPRO-process</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=ORPRO-process&amp;diff=45245"/>
				<updated>2008-10-31T08:43:40Z</updated>
		
		<summary type="html">&lt;p&gt;Njama: New page: * Proposal ** Proposals for open source projets to be reviewed can be sent to the ORPRO project lead.  The open source project will be checked against some entry criteria - for example the...&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;* Proposal&lt;br /&gt;
** Proposals for open source projets to be reviewed can be sent to the ORPRO project lead.  The open source project will be checked against some entry criteria - for example the open source project team should be in a position to remediate security defects that are discovered.&lt;br /&gt;
* Team Development&lt;br /&gt;
** The project lead assigns a review project lead and the lead can additionally select a team of reviewers.&lt;br /&gt;
* Review&lt;br /&gt;
** Assuming the project uses a platform supported by [http://owasp.fortify.com/ owasp.fortify.com], the source code is run through automated analysis.  Defects discovered are manually reviewed and then communicated to the owners of the open source project for remediation.  For more information on this process, see the [http://www.owasp.org/index.php/Category:OWASP_Open_Review_Project_owasp.fortify.com_FAQ OWASP Open Review owasp.fortify.com FAQ]&lt;br /&gt;
** Reviewers manually review the application design and source code and communicate identified issues to the owners of the open source project for remediation.&lt;br /&gt;
** Either reviewers or the open source project leaders responsibly disclose the identified security issues&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
The ORPRO project is a relatively new effort and it is expected that these processes will develop and change over time to accommodate new situations as they arise.&lt;/div&gt;</summary>
		<author><name>Njama</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Category:OWASP_Open_Review_Project&amp;diff=45244</id>
		<title>Category:OWASP Open Review Project</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Category:OWASP_Open_Review_Project&amp;diff=45244"/>
				<updated>2008-10-31T08:43:27Z</updated>
		
		<summary type="html">&lt;p&gt;Njama: /* Open review process */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;[[:Category:OWASP Project|Click here to return to OWASP Projects page.]]&amp;lt;br&amp;gt;&lt;br /&gt;
[[:Project Information:template Open Review Project|Click here to see (&amp;amp; edit, if wanted) the template.]] &lt;br /&gt;
{{:Project Information:template Open Review Project}}&lt;br /&gt;
[[Category:OWASP Project]]&lt;br /&gt;
&lt;br /&gt;
== Overview ==&lt;br /&gt;
We are surrounded by open source software. Not only the open source software all of us use, also many of the commercial applications contain open source libraries. Think of server and desktop software, but don't forget routers, cars, phones, open source is everywhere.&lt;br /&gt;
&lt;br /&gt;
The OWASP Open Review Project (ORPRO) exists to act as a resource for open source projects and for the community in general.  The goal is to provides facilities for both automated and manual review of open source applications and libraries.&lt;br /&gt;
&lt;br /&gt;
Fortify Software has made their [http://www.fortify.com/products/detect/in_development.jsp Source Code Analyzer (SCA) technology] available to open source projects at [http://owasp.fortify.com owasp.fortify.com]&lt;br /&gt;
&lt;br /&gt;
== Project Goals ==&lt;br /&gt;
* Provide an independent security review of open source projects with a record of what has been reviewed and by whom in order to best communicate the security state of the open source projects.  This will include both automated and manual review of source code as well as analysis of algorithms such as compression, crypto, etc&lt;br /&gt;
* Provide resources to the community to centrally manage the review of open source projects&lt;br /&gt;
* Engage in responsible disclosure of any security vulnerabilities discovered&lt;br /&gt;
&lt;br /&gt;
== Project Planning ==&lt;br /&gt;
* Settle overlap between OWASP projects: August 2008 (completed)&lt;br /&gt;
* Initial tool selection and implementation: September 2008 (completed)&lt;br /&gt;
* Roll out automated review capabilities for a limited set of projects: September 2008 (completed)&lt;br /&gt;
* First reviews: October 2008 (ongoing: first project has been selected)&lt;br /&gt;
&lt;br /&gt;
== Open review process ==&lt;br /&gt;
The high level process is as follows:&lt;br /&gt;
&lt;br /&gt;
[[Image:ORPRO_Process1.png]]&lt;br /&gt;
&lt;br /&gt;
Click [[ORPRO-process|here]] for a more detailed process description.&lt;br /&gt;
&lt;br /&gt;
== Related OWASP Projects ==&lt;br /&gt;
The following OWASP projects have a direct relation with ORPRO:&lt;br /&gt;
* [http://www.owasp.org/index.php/Category:OWASP_Application_Security_Verification_Standard_Project OWASP Application Security Verification Standard Project]&lt;br /&gt;
* [http://www.owasp.org/index.php/Category:OWASP_Code_Review_Project OWASP Code Review Project]&lt;br /&gt;
* [http://www.owasp.org/index.php/Category:OWASP_Orizon_Project OWASP Orizon Project]&lt;br /&gt;
&lt;br /&gt;
== News ==&lt;br /&gt;
* '''5 June 2008'''   OWASP ORPRO launched&lt;br /&gt;
* '''12 September 2008''' [http://owasp.fortify.com/ owasp.fortify.com] made available as a public beta for automated source code review of open source projects&lt;br /&gt;
&lt;br /&gt;
== Get involved ==&lt;br /&gt;
Security review takes both time and expertise. We need people with good secure coding skills in C, C++, .NET, Java, PHP, etc who also have the audacity to review some of the most popular open source projects around.&lt;br /&gt;
&lt;br /&gt;
We also need open source project leaders to submit their projects for review.  If you run an open source project and are interested in participating, please email the mailing list.&lt;br /&gt;
&lt;br /&gt;
Please go to https://lists.owasp.org/mailman/listinfo/open-review-project to subscribe to the list. You can post to the ORPRO mailing list by emailing [mailto:open-review-project@lists.owasp.org open-review-project@lists.owasp.org].&lt;br /&gt;
&lt;br /&gt;
== People ==&lt;br /&gt;
Project leads: [[User:Njama|Mario de Boer]], [[User:Dancornell|Dan Cornell]].&lt;br /&gt;
&lt;br /&gt;
Contributors: [http://www.fortify.com Fortify Software] has generously made their Source Code Analyzer (SCA) technology available for use by open source projects at [http://owasp.fortify.com/ owasp.fortify.com].&lt;br /&gt;
&lt;br /&gt;
[[Category:OWASP Project]]&lt;/div&gt;</summary>
		<author><name>Njama</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Category:OWASP_Open_Review_Project&amp;diff=45243</id>
		<title>Category:OWASP Open Review Project</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Category:OWASP_Open_Review_Project&amp;diff=45243"/>
				<updated>2008-10-31T08:42:52Z</updated>
		
		<summary type="html">&lt;p&gt;Njama: /* Open review process */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;[[:Category:OWASP Project|Click here to return to OWASP Projects page.]]&amp;lt;br&amp;gt;&lt;br /&gt;
[[:Project Information:template Open Review Project|Click here to see (&amp;amp; edit, if wanted) the template.]] &lt;br /&gt;
{{:Project Information:template Open Review Project}}&lt;br /&gt;
[[Category:OWASP Project]]&lt;br /&gt;
&lt;br /&gt;
== Overview ==&lt;br /&gt;
We are surrounded by open source software. Not only the open source software all of us use, also many of the commercial applications contain open source libraries. Think of server and desktop software, but don't forget routers, cars, phones, open source is everywhere.&lt;br /&gt;
&lt;br /&gt;
The OWASP Open Review Project (ORPRO) exists to act as a resource for open source projects and for the community in general.  The goal is to provides facilities for both automated and manual review of open source applications and libraries.&lt;br /&gt;
&lt;br /&gt;
Fortify Software has made their [http://www.fortify.com/products/detect/in_development.jsp Source Code Analyzer (SCA) technology] available to open source projects at [http://owasp.fortify.com owasp.fortify.com]&lt;br /&gt;
&lt;br /&gt;
== Project Goals ==&lt;br /&gt;
* Provide an independent security review of open source projects with a record of what has been reviewed and by whom in order to best communicate the security state of the open source projects.  This will include both automated and manual review of source code as well as analysis of algorithms such as compression, crypto, etc&lt;br /&gt;
* Provide resources to the community to centrally manage the review of open source projects&lt;br /&gt;
* Engage in responsible disclosure of any security vulnerabilities discovered&lt;br /&gt;
&lt;br /&gt;
== Project Planning ==&lt;br /&gt;
* Settle overlap between OWASP projects: August 2008 (completed)&lt;br /&gt;
* Initial tool selection and implementation: September 2008 (completed)&lt;br /&gt;
* Roll out automated review capabilities for a limited set of projects: September 2008 (completed)&lt;br /&gt;
* First reviews: October 2008 (ongoing: first project has been selected)&lt;br /&gt;
&lt;br /&gt;
== Open review process ==&lt;br /&gt;
The high level process is as follows:&lt;br /&gt;
&lt;br /&gt;
[[Image:ORPRO_Process1.png]]&lt;br /&gt;
&lt;br /&gt;
Click [[ORPRO-process|here]] for a more detailed process description.&lt;br /&gt;
* Proposal&lt;br /&gt;
** Proposals for open source projets to be reviewed can be sent to the ORPRO project lead.  The open source project will be checked against some entry criteria - for example the open source project team should be in a position to remediate security defects that are discovered.&lt;br /&gt;
* Team Development&lt;br /&gt;
** The project lead assigns a review project lead and the lead can additionally select a team of reviewers.&lt;br /&gt;
* Review&lt;br /&gt;
** Assuming the project uses a platform supported by [http://owasp.fortify.com/ owasp.fortify.com], the source code is run through automated analysis.  Defects discovered are manually reviewed and then communicated to the owners of the open source project for remediation.  For more information on this process, see the [http://www.owasp.org/index.php/Category:OWASP_Open_Review_Project_owasp.fortify.com_FAQ OWASP Open Review owasp.fortify.com FAQ]&lt;br /&gt;
** Reviewers manually review the application design and source code and communicate identified issues to the owners of the open source project for remediation.&lt;br /&gt;
** Either reviewers or the open source project leaders responsibly disclose the identified security issues&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
The ORPRO project is a relatively new effort and it is expected that these processes will develop and change over time to accommodate new situations as they arise.&lt;br /&gt;
&lt;br /&gt;
== Related OWASP Projects ==&lt;br /&gt;
The following OWASP projects have a direct relation with ORPRO:&lt;br /&gt;
* [http://www.owasp.org/index.php/Category:OWASP_Application_Security_Verification_Standard_Project OWASP Application Security Verification Standard Project]&lt;br /&gt;
* [http://www.owasp.org/index.php/Category:OWASP_Code_Review_Project OWASP Code Review Project]&lt;br /&gt;
* [http://www.owasp.org/index.php/Category:OWASP_Orizon_Project OWASP Orizon Project]&lt;br /&gt;
&lt;br /&gt;
== News ==&lt;br /&gt;
* '''5 June 2008'''   OWASP ORPRO launched&lt;br /&gt;
* '''12 September 2008''' [http://owasp.fortify.com/ owasp.fortify.com] made available as a public beta for automated source code review of open source projects&lt;br /&gt;
&lt;br /&gt;
== Get involved ==&lt;br /&gt;
Security review takes both time and expertise. We need people with good secure coding skills in C, C++, .NET, Java, PHP, etc who also have the audacity to review some of the most popular open source projects around.&lt;br /&gt;
&lt;br /&gt;
We also need open source project leaders to submit their projects for review.  If you run an open source project and are interested in participating, please email the mailing list.&lt;br /&gt;
&lt;br /&gt;
Please go to https://lists.owasp.org/mailman/listinfo/open-review-project to subscribe to the list. You can post to the ORPRO mailing list by emailing [mailto:open-review-project@lists.owasp.org open-review-project@lists.owasp.org].&lt;br /&gt;
&lt;br /&gt;
== People ==&lt;br /&gt;
Project leads: [[User:Njama|Mario de Boer]], [[User:Dancornell|Dan Cornell]].&lt;br /&gt;
&lt;br /&gt;
Contributors: [http://www.fortify.com Fortify Software] has generously made their Source Code Analyzer (SCA) technology available for use by open source projects at [http://owasp.fortify.com/ owasp.fortify.com].&lt;br /&gt;
&lt;br /&gt;
[[Category:OWASP Project]]&lt;/div&gt;</summary>
		<author><name>Njama</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Category:OWASP_Open_Review_Project&amp;diff=45242</id>
		<title>Category:OWASP Open Review Project</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Category:OWASP_Open_Review_Project&amp;diff=45242"/>
				<updated>2008-10-31T08:39:43Z</updated>
		
		<summary type="html">&lt;p&gt;Njama: /* Open review process */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;[[:Category:OWASP Project|Click here to return to OWASP Projects page.]]&amp;lt;br&amp;gt;&lt;br /&gt;
[[:Project Information:template Open Review Project|Click here to see (&amp;amp; edit, if wanted) the template.]] &lt;br /&gt;
{{:Project Information:template Open Review Project}}&lt;br /&gt;
[[Category:OWASP Project]]&lt;br /&gt;
&lt;br /&gt;
== Overview ==&lt;br /&gt;
We are surrounded by open source software. Not only the open source software all of us use, also many of the commercial applications contain open source libraries. Think of server and desktop software, but don't forget routers, cars, phones, open source is everywhere.&lt;br /&gt;
&lt;br /&gt;
The OWASP Open Review Project (ORPRO) exists to act as a resource for open source projects and for the community in general.  The goal is to provides facilities for both automated and manual review of open source applications and libraries.&lt;br /&gt;
&lt;br /&gt;
Fortify Software has made their [http://www.fortify.com/products/detect/in_development.jsp Source Code Analyzer (SCA) technology] available to open source projects at [http://owasp.fortify.com owasp.fortify.com]&lt;br /&gt;
&lt;br /&gt;
== Project Goals ==&lt;br /&gt;
* Provide an independent security review of open source projects with a record of what has been reviewed and by whom in order to best communicate the security state of the open source projects.  This will include both automated and manual review of source code as well as analysis of algorithms such as compression, crypto, etc&lt;br /&gt;
* Provide resources to the community to centrally manage the review of open source projects&lt;br /&gt;
* Engage in responsible disclosure of any security vulnerabilities discovered&lt;br /&gt;
&lt;br /&gt;
== Project Planning ==&lt;br /&gt;
* Settle overlap between OWASP projects: August 2008 (completed)&lt;br /&gt;
* Initial tool selection and implementation: September 2008 (completed)&lt;br /&gt;
* Roll out automated review capabilities for a limited set of projects: September 2008 (completed)&lt;br /&gt;
* First reviews: October 2008 (ongoing: first project has been selected)&lt;br /&gt;
&lt;br /&gt;
== Open review process ==&lt;br /&gt;
The high level process is as follows:&lt;br /&gt;
&lt;br /&gt;
[[Image:ORPRO_Process1.png]]&lt;br /&gt;
&lt;br /&gt;
Click [here] for a more detailed process description.&lt;br /&gt;
* Proposal&lt;br /&gt;
** Proposals for open source projets to be reviewed can be sent to the ORPRO project lead.  The open source project will be checked against some entry criteria - for example the open source project team should be in a position to remediate security defects that are discovered.&lt;br /&gt;
* Team Development&lt;br /&gt;
** The project lead assigns a review project lead and the lead can additionally select a team of reviewers.&lt;br /&gt;
* Review&lt;br /&gt;
** Assuming the project uses a platform supported by [http://owasp.fortify.com/ owasp.fortify.com], the source code is run through automated analysis.  Defects discovered are manually reviewed and then communicated to the owners of the open source project for remediation.  For more information on this process, see the [http://www.owasp.org/index.php/Category:OWASP_Open_Review_Project_owasp.fortify.com_FAQ OWASP Open Review owasp.fortify.com FAQ]&lt;br /&gt;
** Reviewers manually review the application design and source code and communicate identified issues to the owners of the open source project for remediation.&lt;br /&gt;
** Either reviewers or the open source project leaders responsibly disclose the identified security issues&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
The ORPRO project is a relatively new effort and it is expected that these processes will develop and change over time to accommodate new situations as they arise.&lt;br /&gt;
&lt;br /&gt;
== Related OWASP Projects ==&lt;br /&gt;
The following OWASP projects have a direct relation with ORPRO:&lt;br /&gt;
* [http://www.owasp.org/index.php/Category:OWASP_Application_Security_Verification_Standard_Project OWASP Application Security Verification Standard Project]&lt;br /&gt;
* [http://www.owasp.org/index.php/Category:OWASP_Code_Review_Project OWASP Code Review Project]&lt;br /&gt;
* [http://www.owasp.org/index.php/Category:OWASP_Orizon_Project OWASP Orizon Project]&lt;br /&gt;
&lt;br /&gt;
== News ==&lt;br /&gt;
* '''5 June 2008'''   OWASP ORPRO launched&lt;br /&gt;
* '''12 September 2008''' [http://owasp.fortify.com/ owasp.fortify.com] made available as a public beta for automated source code review of open source projects&lt;br /&gt;
&lt;br /&gt;
== Get involved ==&lt;br /&gt;
Security review takes both time and expertise. We need people with good secure coding skills in C, C++, .NET, Java, PHP, etc who also have the audacity to review some of the most popular open source projects around.&lt;br /&gt;
&lt;br /&gt;
We also need open source project leaders to submit their projects for review.  If you run an open source project and are interested in participating, please email the mailing list.&lt;br /&gt;
&lt;br /&gt;
Please go to https://lists.owasp.org/mailman/listinfo/open-review-project to subscribe to the list. You can post to the ORPRO mailing list by emailing [mailto:open-review-project@lists.owasp.org open-review-project@lists.owasp.org].&lt;br /&gt;
&lt;br /&gt;
== People ==&lt;br /&gt;
Project leads: [[User:Njama|Mario de Boer]], [[User:Dancornell|Dan Cornell]].&lt;br /&gt;
&lt;br /&gt;
Contributors: [http://www.fortify.com Fortify Software] has generously made their Source Code Analyzer (SCA) technology available for use by open source projects at [http://owasp.fortify.com/ owasp.fortify.com].&lt;br /&gt;
&lt;br /&gt;
[[Category:OWASP Project]]&lt;/div&gt;</summary>
		<author><name>Njama</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=File:ORPRO_Process1.png&amp;diff=45241</id>
		<title>File:ORPRO Process1.png</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=File:ORPRO_Process1.png&amp;diff=45241"/>
				<updated>2008-10-31T08:36:46Z</updated>
		
		<summary type="html">&lt;p&gt;Njama: High level process&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;High level process&lt;/div&gt;</summary>
		<author><name>Njama</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Category:OWASP_Open_Review_Project&amp;diff=45240</id>
		<title>Category:OWASP Open Review Project</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Category:OWASP_Open_Review_Project&amp;diff=45240"/>
				<updated>2008-10-31T08:29:40Z</updated>
		
		<summary type="html">&lt;p&gt;Njama: /* Project Planning */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;[[:Category:OWASP Project|Click here to return to OWASP Projects page.]]&amp;lt;br&amp;gt;&lt;br /&gt;
[[:Project Information:template Open Review Project|Click here to see (&amp;amp; edit, if wanted) the template.]] &lt;br /&gt;
{{:Project Information:template Open Review Project}}&lt;br /&gt;
[[Category:OWASP Project]]&lt;br /&gt;
&lt;br /&gt;
== Overview ==&lt;br /&gt;
We are surrounded by open source software. Not only the open source software all of us use, also many of the commercial applications contain open source libraries. Think of server and desktop software, but don't forget routers, cars, phones, open source is everywhere.&lt;br /&gt;
&lt;br /&gt;
The OWASP Open Review Project (ORPRO) exists to act as a resource for open source projects and for the community in general.  The goal is to provides facilities for both automated and manual review of open source applications and libraries.&lt;br /&gt;
&lt;br /&gt;
Fortify Software has made their [http://www.fortify.com/products/detect/in_development.jsp Source Code Analyzer (SCA) technology] available to open source projects at [http://owasp.fortify.com owasp.fortify.com]&lt;br /&gt;
&lt;br /&gt;
== Project Goals ==&lt;br /&gt;
* Provide an independent security review of open source projects with a record of what has been reviewed and by whom in order to best communicate the security state of the open source projects.  This will include both automated and manual review of source code as well as analysis of algorithms such as compression, crypto, etc&lt;br /&gt;
* Provide resources to the community to centrally manage the review of open source projects&lt;br /&gt;
* Engage in responsible disclosure of any security vulnerabilities discovered&lt;br /&gt;
&lt;br /&gt;
== Project Planning ==&lt;br /&gt;
* Settle overlap between OWASP projects: August 2008 (completed)&lt;br /&gt;
* Initial tool selection and implementation: September 2008 (completed)&lt;br /&gt;
* Roll out automated review capabilities for a limited set of projects: September 2008 (completed)&lt;br /&gt;
* First reviews: October 2008 (ongoing: first project has been selected)&lt;br /&gt;
&lt;br /&gt;
== Open review process ==&lt;br /&gt;
The high level process is as follows:&lt;br /&gt;
* Proposal&lt;br /&gt;
** Proposals for open source projets to be reviewed can be sent to the ORPRO project lead.  The open source project will be checked against some entry criteria - for example the open source project team should be in a position to remediate security defects that are discovered.&lt;br /&gt;
* Team Development&lt;br /&gt;
** The project lead assigns a review project lead and the lead can additionally select a team of reviewers.&lt;br /&gt;
* Review&lt;br /&gt;
** Assuming the project uses a platform supported by [http://owasp.fortify.com/ owasp.fortify.com], the source code is run through automated analysis.  Defects discovered are manually reviewed and then communicated to the owners of the open source project for remediation.  For more information on this process, see the [http://www.owasp.org/index.php/Category:OWASP_Open_Review_Project_owasp.fortify.com_FAQ OWASP Open Review owasp.fortify.com FAQ]&lt;br /&gt;
** Reviewers manually review the application design and source code and communicate identified issues to the owners of the open source project for remediation.&lt;br /&gt;
** Either reviewers or the open source project leaders responsibly disclose the identified security issues&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
The ORPRO project is a relatively new effort and it is expected that these processes will develop and change over time to accommodate new situations as they arise.&lt;br /&gt;
&lt;br /&gt;
== Related OWASP Projects ==&lt;br /&gt;
The following OWASP projects have a direct relation with ORPRO:&lt;br /&gt;
* [http://www.owasp.org/index.php/Category:OWASP_Application_Security_Verification_Standard_Project OWASP Application Security Verification Standard Project]&lt;br /&gt;
* [http://www.owasp.org/index.php/Category:OWASP_Code_Review_Project OWASP Code Review Project]&lt;br /&gt;
* [http://www.owasp.org/index.php/Category:OWASP_Orizon_Project OWASP Orizon Project]&lt;br /&gt;
&lt;br /&gt;
== News ==&lt;br /&gt;
* '''5 June 2008'''   OWASP ORPRO launched&lt;br /&gt;
* '''12 September 2008''' [http://owasp.fortify.com/ owasp.fortify.com] made available as a public beta for automated source code review of open source projects&lt;br /&gt;
&lt;br /&gt;
== Get involved ==&lt;br /&gt;
Security review takes both time and expertise. We need people with good secure coding skills in C, C++, .NET, Java, PHP, etc who also have the audacity to review some of the most popular open source projects around.&lt;br /&gt;
&lt;br /&gt;
We also need open source project leaders to submit their projects for review.  If you run an open source project and are interested in participating, please email the mailing list.&lt;br /&gt;
&lt;br /&gt;
Please go to https://lists.owasp.org/mailman/listinfo/open-review-project to subscribe to the list. You can post to the ORPRO mailing list by emailing [mailto:open-review-project@lists.owasp.org open-review-project@lists.owasp.org].&lt;br /&gt;
&lt;br /&gt;
== People ==&lt;br /&gt;
Project leads: [[User:Njama|Mario de Boer]], [[User:Dancornell|Dan Cornell]].&lt;br /&gt;
&lt;br /&gt;
Contributors: [http://www.fortify.com Fortify Software] has generously made their Source Code Analyzer (SCA) technology available for use by open source projects at [http://owasp.fortify.com/ owasp.fortify.com].&lt;br /&gt;
&lt;br /&gt;
[[Category:OWASP Project]]&lt;/div&gt;</summary>
		<author><name>Njama</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Category:OWASP_Open_Review_Project&amp;diff=45239</id>
		<title>Category:OWASP Open Review Project</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Category:OWASP_Open_Review_Project&amp;diff=45239"/>
				<updated>2008-10-31T08:27:55Z</updated>
		
		<summary type="html">&lt;p&gt;Njama: /* Open review process */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;[[:Category:OWASP Project|Click here to return to OWASP Projects page.]]&amp;lt;br&amp;gt;&lt;br /&gt;
[[:Project Information:template Open Review Project|Click here to see (&amp;amp; edit, if wanted) the template.]] &lt;br /&gt;
{{:Project Information:template Open Review Project}}&lt;br /&gt;
[[Category:OWASP Project]]&lt;br /&gt;
&lt;br /&gt;
== Overview ==&lt;br /&gt;
We are surrounded by open source software. Not only the open source software all of us use, also many of the commercial applications contain open source libraries. Think of server and desktop software, but don't forget routers, cars, phones, open source is everywhere.&lt;br /&gt;
&lt;br /&gt;
The OWASP Open Review Project (ORPRO) exists to act as a resource for open source projects and for the community in general.  The goal is to provides facilities for both automated and manual review of open source applications and libraries.&lt;br /&gt;
&lt;br /&gt;
Fortify Software has made their [http://www.fortify.com/products/detect/in_development.jsp Source Code Analyzer (SCA) technology] available to open source projects at [http://owasp.fortify.com owasp.fortify.com]&lt;br /&gt;
&lt;br /&gt;
== Project Goals ==&lt;br /&gt;
* Provide an independent security review of open source projects with a record of what has been reviewed and by whom in order to best communicate the security state of the open source projects.  This will include both automated and manual review of source code as well as analysis of algorithms such as compression, crypto, etc&lt;br /&gt;
* Provide resources to the community to centrally manage the review of open source projects&lt;br /&gt;
* Engage in responsible disclosure of any security vulnerabilities discovered&lt;br /&gt;
&lt;br /&gt;
== Project Planning ==&lt;br /&gt;
* Settle overlap between OWASP projects: August 2008 (completed)&lt;br /&gt;
* Initial tool selection and implementation: September 2008 (completed)&lt;br /&gt;
* Roll out automated review capabilities for a limited set of projects: September 2008&lt;br /&gt;
* First reviews: October 2008&lt;br /&gt;
&lt;br /&gt;
== Open review process ==&lt;br /&gt;
The high level process is as follows:&lt;br /&gt;
* Proposal&lt;br /&gt;
** Proposals for open source projets to be reviewed can be sent to the ORPRO project lead.  The open source project will be checked against some entry criteria - for example the open source project team should be in a position to remediate security defects that are discovered.&lt;br /&gt;
* Team Development&lt;br /&gt;
** The project lead assigns a review project lead and the lead can additionally select a team of reviewers.&lt;br /&gt;
* Review&lt;br /&gt;
** Assuming the project uses a platform supported by [http://owasp.fortify.com/ owasp.fortify.com], the source code is run through automated analysis.  Defects discovered are manually reviewed and then communicated to the owners of the open source project for remediation.  For more information on this process, see the [http://www.owasp.org/index.php/Category:OWASP_Open_Review_Project_owasp.fortify.com_FAQ OWASP Open Review owasp.fortify.com FAQ]&lt;br /&gt;
** Reviewers manually review the application design and source code and communicate identified issues to the owners of the open source project for remediation.&lt;br /&gt;
** Either reviewers or the open source project leaders responsibly disclose the identified security issues&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
The ORPRO project is a relatively new effort and it is expected that these processes will develop and change over time to accommodate new situations as they arise.&lt;br /&gt;
&lt;br /&gt;
== Related OWASP Projects ==&lt;br /&gt;
The following OWASP projects have a direct relation with ORPRO:&lt;br /&gt;
* [http://www.owasp.org/index.php/Category:OWASP_Application_Security_Verification_Standard_Project OWASP Application Security Verification Standard Project]&lt;br /&gt;
* [http://www.owasp.org/index.php/Category:OWASP_Code_Review_Project OWASP Code Review Project]&lt;br /&gt;
* [http://www.owasp.org/index.php/Category:OWASP_Orizon_Project OWASP Orizon Project]&lt;br /&gt;
&lt;br /&gt;
== News ==&lt;br /&gt;
* '''5 June 2008'''   OWASP ORPRO launched&lt;br /&gt;
* '''12 September 2008''' [http://owasp.fortify.com/ owasp.fortify.com] made available as a public beta for automated source code review of open source projects&lt;br /&gt;
&lt;br /&gt;
== Get involved ==&lt;br /&gt;
Security review takes both time and expertise. We need people with good secure coding skills in C, C++, .NET, Java, PHP, etc who also have the audacity to review some of the most popular open source projects around.&lt;br /&gt;
&lt;br /&gt;
We also need open source project leaders to submit their projects for review.  If you run an open source project and are interested in participating, please email the mailing list.&lt;br /&gt;
&lt;br /&gt;
Please go to https://lists.owasp.org/mailman/listinfo/open-review-project to subscribe to the list. You can post to the ORPRO mailing list by emailing [mailto:open-review-project@lists.owasp.org open-review-project@lists.owasp.org].&lt;br /&gt;
&lt;br /&gt;
== People ==&lt;br /&gt;
Project leads: [[User:Njama|Mario de Boer]], [[User:Dancornell|Dan Cornell]].&lt;br /&gt;
&lt;br /&gt;
Contributors: [http://www.fortify.com Fortify Software] has generously made their Source Code Analyzer (SCA) technology available for use by open source projects at [http://owasp.fortify.com/ owasp.fortify.com].&lt;br /&gt;
&lt;br /&gt;
[[Category:OWASP Project]]&lt;/div&gt;</summary>
		<author><name>Njama</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Category:OWASP_Open_Review_Project&amp;diff=45238</id>
		<title>Category:OWASP Open Review Project</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Category:OWASP_Open_Review_Project&amp;diff=45238"/>
				<updated>2008-10-31T08:23:47Z</updated>
		
		<summary type="html">&lt;p&gt;Njama: /* Overview */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;[[:Category:OWASP Project|Click here to return to OWASP Projects page.]]&amp;lt;br&amp;gt;&lt;br /&gt;
[[:Project Information:template Open Review Project|Click here to see (&amp;amp; edit, if wanted) the template.]] &lt;br /&gt;
{{:Project Information:template Open Review Project}}&lt;br /&gt;
[[Category:OWASP Project]]&lt;br /&gt;
&lt;br /&gt;
== Overview ==&lt;br /&gt;
We are surrounded by open source software. Not only the open source software all of us use, also many of the commercial applications contain open source libraries. Think of server and desktop software, but don't forget routers, cars, phones, open source is everywhere.&lt;br /&gt;
&lt;br /&gt;
The OWASP Open Review Project (ORPRO) exists to act as a resource for open source projects and for the community in general.  The goal is to provides facilities for both automated and manual review of open source applications and libraries.&lt;br /&gt;
&lt;br /&gt;
Fortify Software has made their [http://www.fortify.com/products/detect/in_development.jsp Source Code Analyzer (SCA) technology] available to open source projects at [http://owasp.fortify.com owasp.fortify.com]&lt;br /&gt;
&lt;br /&gt;
== Project Goals ==&lt;br /&gt;
* Provide an independent security review of open source projects with a record of what has been reviewed and by whom in order to best communicate the security state of the open source projects.  This will include both automated and manual review of source code as well as analysis of algorithms such as compression, crypto, etc&lt;br /&gt;
* Provide resources to the community to centrally manage the review of open source projects&lt;br /&gt;
* Engage in responsible disclosure of any security vulnerabilities discovered&lt;br /&gt;
&lt;br /&gt;
== Project Planning ==&lt;br /&gt;
* Settle overlap between OWASP projects: August 2008 (completed)&lt;br /&gt;
* Initial tool selection and implementation: September 2008 (completed)&lt;br /&gt;
* Roll out automated review capabilities for a limited set of projects: September 2008&lt;br /&gt;
* First reviews: October 2008&lt;br /&gt;
&lt;br /&gt;
== Open review process ==&lt;br /&gt;
The high level process is as follows:&lt;br /&gt;
* Proposal&lt;br /&gt;
** Proposals for open source projets to be reviewed can be sent to the ORPRO project lead.  The open source project will be checked against some entry criteria - for example the open source project team should be in a position to remediate security defects that are discovered.&lt;br /&gt;
* Team Development&lt;br /&gt;
** The project lead assigns a review project lead and the lead can additionally select a team of reviewers.&lt;br /&gt;
* Review&lt;br /&gt;
** Assuming the project uses a platform supported by [http://owasp.fortify.com/ owasp.fortify.com], the source code is run through automated analysis.  Defects discovered are manually reviewed and then communicated to the owners of the open source project for remediation.  For more information on this process, see the [http://www.owasp.org/index.php/Category:OWASP_Open_Review_Project_owasp.fortify.com_FAQ OWASP Open Review owasp.fortify.com FAQ]&lt;br /&gt;
** Reviewers manually review the application design and source code and communicate identified issues to the owners of the open source project for remediation.&lt;br /&gt;
** Either reviewers or the open source project leaders responsibly disclose the identified security issues&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
The ORPRO project is a relatively new effort and it is expected that these processes will develop and change over time to accommodate new situations as they arise.&lt;br /&gt;
&lt;br /&gt;
== News ==&lt;br /&gt;
* '''5 June 2008'''   OWASP ORPRO launched&lt;br /&gt;
* '''12 September 2008''' [http://owasp.fortify.com/ owasp.fortify.com] made available as a public beta for automated source code review of open source projects&lt;br /&gt;
&lt;br /&gt;
== Get involved ==&lt;br /&gt;
Security review takes both time and expertise. We need people with good secure coding skills in C, C++, .NET, Java, PHP, etc who also have the audacity to review some of the most popular open source projects around.&lt;br /&gt;
&lt;br /&gt;
We also need open source project leaders to submit their projects for review.  If you run an open source project and are interested in participating, please email the mailing list.&lt;br /&gt;
&lt;br /&gt;
Please go to https://lists.owasp.org/mailman/listinfo/open-review-project to subscribe to the list. You can post to the ORPRO mailing list by emailing [mailto:open-review-project@lists.owasp.org open-review-project@lists.owasp.org].&lt;br /&gt;
&lt;br /&gt;
== People ==&lt;br /&gt;
Project leads: [[User:Njama|Mario de Boer]], [[User:Dancornell|Dan Cornell]].&lt;br /&gt;
&lt;br /&gt;
Contributors: [http://www.fortify.com Fortify Software] has generously made their Source Code Analyzer (SCA) technology available for use by open source projects at [http://owasp.fortify.com/ owasp.fortify.com].&lt;br /&gt;
&lt;br /&gt;
[[Category:OWASP Project]]&lt;/div&gt;</summary>
		<author><name>Njama</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Category:OWASP_Open_Review_Project&amp;diff=35140</id>
		<title>Category:OWASP Open Review Project</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Category:OWASP_Open_Review_Project&amp;diff=35140"/>
				<updated>2008-08-01T08:20:28Z</updated>
		
		<summary type="html">&lt;p&gt;Njama: /* Project Planning */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;[[:Category:OWASP Project|Click here to return to OWASP Projects page.]]&amp;lt;br&amp;gt;&lt;br /&gt;
[[:Project Information:template Open Review Project|Click here to see (&amp;amp; edit, if wanted) the template.]] &lt;br /&gt;
{{:Project Information:template Open Review Project}}&lt;br /&gt;
[[Category:OWASP Project]]&lt;br /&gt;
&lt;br /&gt;
== Overview ==&lt;br /&gt;
We are surrounded by open source software. Not only the open source software all of us use, also many of the commercial applications contain open source libraries. Think of server and desktop software, but don't forget routers, cars, phones, open source is everywhere.&lt;br /&gt;
&lt;br /&gt;
In the OWASP Open Review Project (ORPRO) we perform open reviews of open source projects. We focus on security, are independent, and use the excellent deliverables from other OWASP projects to achieve traceable assurance statements on the security of the code. Users, both end-users and organizations using open source in their products, may benefit from ORPRO’s results.&lt;br /&gt;
&lt;br /&gt;
== Project Goals ==&lt;br /&gt;
* Independent security review of open source projects;&lt;br /&gt;
* Centrally managed review projects;&lt;br /&gt;
* Independent statement on what is reviewed and by whom, resulting in a form of assurance that the software is free from security bugs;&lt;br /&gt;
* Analysis not limited to code review, including digging into hard algorithms (compression, crypto, etc);&lt;br /&gt;
* Responsible disclosure of any security vulnerabilities discovered.&lt;br /&gt;
&lt;br /&gt;
== Project Planning ==&lt;br /&gt;
* Settle overlap between OWASP projects: August 2008&lt;br /&gt;
* Tool selection and implementation: October 2008&lt;br /&gt;
* First reviews: October 2008&lt;br /&gt;
&lt;br /&gt;
== Open review process ==&lt;br /&gt;
The high level process is as follows:&lt;br /&gt;
* Proposal&lt;br /&gt;
** Proposals for open source projets to be reviewed can be sent to the ORPRO project lead&lt;br /&gt;
* Entry criteria&lt;br /&gt;
** Project lead checks entry criteria for open source projects&lt;br /&gt;
* Team&lt;br /&gt;
** Project lead assigns review project lead&lt;br /&gt;
** Review project lead assign team of reviewers&lt;br /&gt;
* Review&lt;br /&gt;
** Review project is managed by Review project leader&lt;br /&gt;
** Progress reports are published&lt;br /&gt;
** Communication with developer project&lt;br /&gt;
** Responsible disclosure of bugs/defects&lt;br /&gt;
&lt;br /&gt;
== News ==&lt;br /&gt;
'''5 June 2008'''   OWASP ORPRO launched&lt;br /&gt;
&lt;br /&gt;
== Get involved ==&lt;br /&gt;
Security review takes both time and expertise. We need people with good secure coding skills in C, C++, .NET, Java, php, etc and that have the audacity to review some of the most popular open source projects around.&lt;br /&gt;
&lt;br /&gt;
Please go to https://lists.owasp.org/mailman/listinfo/open-review-project to subscribe to the list. You can post to the ORPRO mailing list by emailing [mailto:open-review-project@lists.owasp.org open-review-project@lists.owasp.org]. &lt;br /&gt;
&lt;br /&gt;
== People ==&lt;br /&gt;
Project lead: [[User:Njama|Mario de Boer]].&lt;br /&gt;
&lt;br /&gt;
Contributors: None yet, any help more than appreciated.&lt;br /&gt;
&lt;br /&gt;
[[Category:OWASP Project]]&lt;/div&gt;</summary>
		<author><name>Njama</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Category:OWASP_Open_Review_Project&amp;diff=35134</id>
		<title>Category:OWASP Open Review Project</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Category:OWASP_Open_Review_Project&amp;diff=35134"/>
				<updated>2008-08-01T07:53:46Z</updated>
		
		<summary type="html">&lt;p&gt;Njama: /* Project Goals */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;[[:Category:OWASP Project|Click here to return to OWASP Projects page.]]&amp;lt;br&amp;gt;&lt;br /&gt;
[[:Project Information:template Open Review Project|Click here to see (&amp;amp; edit, if wanted) the template.]] &lt;br /&gt;
{{:Project Information:template Open Review Project}}&lt;br /&gt;
[[Category:OWASP Project]]&lt;br /&gt;
&lt;br /&gt;
== Overview ==&lt;br /&gt;
We are surrounded by open source software. Not only the open source software all of us use, also many of the commercial applications contain open source libraries. Think of server and desktop software, but don't forget routers, cars, phones, open source is everywhere.&lt;br /&gt;
&lt;br /&gt;
In the OWASP Open Review Project (ORPRO) we perform open reviews of open source projects. We focus on security, are independent, and use the excellent deliverables from other OWASP projects to achieve traceable assurance statements on the security of the code. Users, both end-users and organizations using open source in their products, may benefit from ORPRO’s results.&lt;br /&gt;
&lt;br /&gt;
== Project Goals ==&lt;br /&gt;
* Independent security review of open source projects;&lt;br /&gt;
* Centrally managed review projects;&lt;br /&gt;
* Independent statement on what is reviewed and by whom, resulting in a form of assurance that the software is free from security bugs;&lt;br /&gt;
* Analysis not limited to code review, including digging into hard algorithms (compression, crypto, etc);&lt;br /&gt;
* Responsible disclosure of any security vulnerabilities discovered.&lt;br /&gt;
&lt;br /&gt;
== Project Planning ==&lt;br /&gt;
* Settle overlap between OWASP projects: August 2008&lt;br /&gt;
* Tool selection and implementation: October 2008&lt;br /&gt;
* First reviews: October 2008&lt;br /&gt;
&lt;br /&gt;
== News ==&lt;br /&gt;
'''5 June 2008'''   OWASP ORPRO launched&lt;br /&gt;
&lt;br /&gt;
== Get involved ==&lt;br /&gt;
Security review takes both time and expertise. We need people with good secure coding skills in C, C++, .NET, Java, php, etc and that have the audacity to review some of the most popular open source projects around.&lt;br /&gt;
&lt;br /&gt;
Please go to https://lists.owasp.org/mailman/listinfo/open-review-project to subscribe to the list. You can post to the ORPRO mailing list by emailing [mailto:open-review-project@lists.owasp.org open-review-project@lists.owasp.org]. &lt;br /&gt;
&lt;br /&gt;
== People ==&lt;br /&gt;
Project lead: [[User:Njama|Mario de Boer]].&lt;br /&gt;
&lt;br /&gt;
Contributors: None yet, any help more than appreciated.&lt;br /&gt;
&lt;br /&gt;
[[Category:OWASP Project]]&lt;/div&gt;</summary>
		<author><name>Njama</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Category:OWASP_Open_Review_Project&amp;diff=30622</id>
		<title>Category:OWASP Open Review Project</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Category:OWASP_Open_Review_Project&amp;diff=30622"/>
				<updated>2008-06-06T18:31:44Z</updated>
		
		<summary type="html">&lt;p&gt;Njama: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;{{:Project Information:template Open Review Project}}&lt;br /&gt;
&lt;br /&gt;
== Overview ==&lt;br /&gt;
We are surrounded by open source software. Not only the open source software all of us use, also many of the commercial applications contain open source libraries. Think of server and desktop software, but don't forget routers, cars, phones, open source is everywhere.&lt;br /&gt;
&lt;br /&gt;
In the OWASP Open Review Project (ORPRO) we perform open reviews of open source projects. We focus on security, are independent, and use the excellent deliverables from other OWASP projects to achieve traceable assurance statements on the security of the code. Users, both end-users and organizations using open source in their products, may benefit from ORPRO’s results.&lt;br /&gt;
&lt;br /&gt;
== Project Goals ==&lt;br /&gt;
* Independent security review of open source projects;&lt;br /&gt;
* Centrally managed review projects;&lt;br /&gt;
* Independent statement on what is reviewed and by whom, resulting in a form of assurance that the software is free from security bugs;&lt;br /&gt;
* Analysis not limited to code review, including digging into hard algorithms (compression, crypto, etc);&lt;br /&gt;
* Responsible disclosure of any security vulnerabilities discovered.&lt;br /&gt;
&lt;br /&gt;
== News ==&lt;br /&gt;
'''5 June 2008'''   OWASP ORPRO launched&lt;br /&gt;
&lt;br /&gt;
== Get involved ==&lt;br /&gt;
Security review takes both time and expertise. We need people with good secure coding skills in C, C++, .NET, Java, php, etc and that have the audacity to review some of the most popular open source projects around.&lt;br /&gt;
&lt;br /&gt;
Please go to https://lists.owasp.org/mailman/listinfo/open-review-project to subscribe to the list. You can post to the ORPRO mailing list by emailing [mailto:open-review-project@lists.owasp.org open-review-project@lists.owasp.org]. &lt;br /&gt;
&lt;br /&gt;
== People ==&lt;br /&gt;
Project lead: [[User:Njama|Mario de Boer]].&lt;br /&gt;
&lt;br /&gt;
Contributors: None yet, any help more than appreciated.&lt;br /&gt;
&lt;br /&gt;
[[Category:OWASP Project]]&lt;/div&gt;</summary>
		<author><name>Njama</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Category:OWASP_Open_Review_Project&amp;diff=30562</id>
		<title>Category:OWASP Open Review Project</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Category:OWASP_Open_Review_Project&amp;diff=30562"/>
				<updated>2008-06-05T19:44:12Z</updated>
		
		<summary type="html">&lt;p&gt;Njama: /* Overview */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;== Overview ==&lt;br /&gt;
We are surrounded by open source software. Not only the open source software all of us use, also many of the commercial applications contain open source libraries. Think of server and desktop software, but don't forget routers, cars, phones, open source is everywhere.&lt;br /&gt;
&lt;br /&gt;
In the OWASP Open Review Project (ORPRO) we perform open reviews of open source projects. We focus on security, are independent, and use the excellent deliverables from other OWASP projects to achieve traceable assurance statements on the security of the code. Users, both end-users and organizations using open source in their products, may benefit from ORPRO’s results.&lt;br /&gt;
&lt;br /&gt;
== Project Goals ==&lt;br /&gt;
* Independent security review of open source projects;&lt;br /&gt;
* Centrally managed review projects;&lt;br /&gt;
* Independent statement on what is reviewed and by whom, resulting in a form of assurance that the software is free from security bugs;&lt;br /&gt;
* Analysis not limited to code review, including digging into hard algorithms (compression, crypto, etc);&lt;br /&gt;
* Responsible disclosure of any security vulnerabilities discovered.&lt;br /&gt;
&lt;br /&gt;
== News ==&lt;br /&gt;
'''5 June 2008'''   OWASP ORPRO launched&lt;br /&gt;
&lt;br /&gt;
== Get involved ==&lt;br /&gt;
Security review takes both time and expertise. We need people with good secure coding skills in C, C++, .NET, Java, php, etc and that have the audacity to review some of the most popular open source projects around.&lt;br /&gt;
&lt;br /&gt;
Please go to https://lists.owasp.org/mailman/listinfo/open-review-project to subscribe to the list. You can post to the ORPRO mailing list by emailing [mailto:open-review-project@lists.owasp.org open-review-project@lists.owasp.org]. &lt;br /&gt;
&lt;br /&gt;
== People ==&lt;br /&gt;
Project lead: [[User:Njama|Mario de Boer]].&lt;br /&gt;
&lt;br /&gt;
Contributors: None yet, any help more than appreciated.&lt;/div&gt;</summary>
		<author><name>Njama</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Category:OWASP_Open_Review_Project&amp;diff=30557</id>
		<title>Category:OWASP Open Review Project</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Category:OWASP_Open_Review_Project&amp;diff=30557"/>
				<updated>2008-06-05T19:41:45Z</updated>
		
		<summary type="html">&lt;p&gt;Njama: /* Project Goals */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;== Overview ==&lt;br /&gt;
We are surrounded by open source software. Not only the open source software all of us use, also many of the commercial applications contain open source libraries. And in our routers, our cars, our phones, everywhere...&lt;br /&gt;
&lt;br /&gt;
In the OWASP Open Review Project (ORPRO) we perform open reviews of open source projects. We focus on security, are independent, and use the excellent deliverables from other OWASP projects to achieve traceable assurance statements on the security of the code. Users, both end-users and organizations using open source in their products, may benefit from ORPRO’s results.&lt;br /&gt;
&lt;br /&gt;
== Project Goals ==&lt;br /&gt;
* Independent security review of open source projects;&lt;br /&gt;
* Centrally managed review projects;&lt;br /&gt;
* Independent statement on what is reviewed and by whom, resulting in a form of assurance that the software is free from security bugs;&lt;br /&gt;
* Analysis not limited to code review, including digging into hard algorithms (compression, crypto, etc);&lt;br /&gt;
* Responsible disclosure of any security vulnerabilities discovered.&lt;br /&gt;
&lt;br /&gt;
== News ==&lt;br /&gt;
'''5 June 2008'''   OWASP ORPRO launched&lt;br /&gt;
&lt;br /&gt;
== Get involved ==&lt;br /&gt;
Security review takes both time and expertise. We need people with good secure coding skills in C, C++, .NET, Java, php, etc and that have the audacity to review some of the most popular open source projects around.&lt;br /&gt;
&lt;br /&gt;
Please go to https://lists.owasp.org/mailman/listinfo/open-review-project to subscribe to the list. You can post to the ORPRO mailing list by emailing [mailto:open-review-project@lists.owasp.org open-review-project@lists.owasp.org]. &lt;br /&gt;
&lt;br /&gt;
== People ==&lt;br /&gt;
Project lead: [[User:Njama|Mario de Boer]].&lt;br /&gt;
&lt;br /&gt;
Contributors: None yet, any help more than appreciated.&lt;/div&gt;</summary>
		<author><name>Njama</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=User:Njama&amp;diff=30552</id>
		<title>User:Njama</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=User:Njama&amp;diff=30552"/>
				<updated>2008-06-05T19:37:14Z</updated>
		
		<summary type="html">&lt;p&gt;Njama: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;Hi, my name is Mario de Boer. I am with the Dutch OWASP Chapter, and run the Open Review Project.&lt;br /&gt;
&lt;br /&gt;
Please contact me at [mailto:njama@owasp.org njama@owasp.org].&lt;/div&gt;</summary>
		<author><name>Njama</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Category:OWASP_Open_Review_Project&amp;diff=30548</id>
		<title>Category:OWASP Open Review Project</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Category:OWASP_Open_Review_Project&amp;diff=30548"/>
				<updated>2008-06-05T19:34:01Z</updated>
		
		<summary type="html">&lt;p&gt;Njama: /* People */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;== Overview ==&lt;br /&gt;
We are surrounded by open source software. Not only the open source software all of us use, also many of the commercial applications contain open source libraries. And in our routers, our cars, our phones, everywhere...&lt;br /&gt;
&lt;br /&gt;
In the OWASP Open Review Project (ORPRO) we perform open reviews of open source projects. We focus on security, are independent, and use the excellent deliverables from other OWASP projects to achieve traceable assurance statements on the security of the code. Users, both end-users and organizations using open source in their products, may benefit from ORPRO’s results.&lt;br /&gt;
&lt;br /&gt;
== Project Goals ==&lt;br /&gt;
* Independent security review of open source projects;&lt;br /&gt;
* Centrally managed;&lt;br /&gt;
* Independent statement on what is reviewed and by whom, resulting in a form of assurance that the software is free from security bugs;&lt;br /&gt;
* Analysis not limited to code review, including digging into hard algorithms (compression, crypto, etc);&lt;br /&gt;
* Responsible disclosure of any security vulnerabilities discovered.&lt;br /&gt;
&lt;br /&gt;
== News ==&lt;br /&gt;
'''5 June 2008'''   OWASP ORPRO launched&lt;br /&gt;
&lt;br /&gt;
== Get involved ==&lt;br /&gt;
Security review takes both time and expertise. We need people with good secure coding skills in C, C++, .NET, Java, php, etc and that have the audacity to review some of the most popular open source projects around.&lt;br /&gt;
&lt;br /&gt;
Please go to https://lists.owasp.org/mailman/listinfo/open-review-project to subscribe to the list. You can post to the ORPRO mailing list by emailing [mailto:open-review-project@lists.owasp.org open-review-project@lists.owasp.org]. &lt;br /&gt;
&lt;br /&gt;
== People ==&lt;br /&gt;
Project lead: [[User:Njama|Mario de Boer]].&lt;br /&gt;
&lt;br /&gt;
Contributors: None yet, any help more than appreciated.&lt;/div&gt;</summary>
		<author><name>Njama</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Category:OWASP_Open_Review_Project&amp;diff=30544</id>
		<title>Category:OWASP Open Review Project</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Category:OWASP_Open_Review_Project&amp;diff=30544"/>
				<updated>2008-06-05T19:30:05Z</updated>
		
		<summary type="html">&lt;p&gt;Njama: /* Project Goals */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;== Overview ==&lt;br /&gt;
We are surrounded by open source software. Not only the open source software all of us use, also many of the commercial applications contain open source libraries. And in our routers, our cars, our phones, everywhere...&lt;br /&gt;
&lt;br /&gt;
In the OWASP Open Review Project (ORPRO) we perform open reviews of open source projects. We focus on security, are independent, and use the excellent deliverables from other OWASP projects to achieve traceable assurance statements on the security of the code. Users, both end-users and organizations using open source in their products, may benefit from ORPRO’s results.&lt;br /&gt;
&lt;br /&gt;
== Project Goals ==&lt;br /&gt;
* Independent security review of open source projects;&lt;br /&gt;
* Centrally managed;&lt;br /&gt;
* Independent statement on what is reviewed and by whom, resulting in a form of assurance that the software is free from security bugs;&lt;br /&gt;
* Analysis not limited to code review, including digging into hard algorithms (compression, crypto, etc);&lt;br /&gt;
* Responsible disclosure of any security vulnerabilities discovered.&lt;br /&gt;
&lt;br /&gt;
== News ==&lt;br /&gt;
'''5 June 2008'''   OWASP ORPRO launched&lt;br /&gt;
&lt;br /&gt;
== Get involved ==&lt;br /&gt;
Security review takes both time and expertise. We need people with good secure coding skills in C, C++, .NET, Java, php, etc and that have the audacity to review some of the most popular open source projects around.&lt;br /&gt;
&lt;br /&gt;
Please go to https://lists.owasp.org/mailman/listinfo/open-review-project to subscribe to the list. You can post to the ORPRO mailing list by emailing [mailto:open-review-project@lists.owasp.org open-review-project@lists.owasp.org]. &lt;br /&gt;
&lt;br /&gt;
== People ==&lt;br /&gt;
Project lead: [[User:Mario de Boer|Mario de Boer]].&lt;br /&gt;
&lt;br /&gt;
Contributors: None yet, any help more than appreciated.&lt;/div&gt;</summary>
		<author><name>Njama</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Category:OWASP_Open_Review_Project&amp;diff=30543</id>
		<title>Category:OWASP Open Review Project</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Category:OWASP_Open_Review_Project&amp;diff=30543"/>
				<updated>2008-06-05T19:28:19Z</updated>
		
		<summary type="html">&lt;p&gt;Njama: /* Overview */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;== Overview ==&lt;br /&gt;
We are surrounded by open source software. Not only the open source software all of us use, also many of the commercial applications contain open source libraries. And in our routers, our cars, our phones, everywhere...&lt;br /&gt;
&lt;br /&gt;
In the OWASP Open Review Project (ORPRO) we perform open reviews of open source projects. We focus on security, are independent, and use the excellent deliverables from other OWASP projects to achieve traceable assurance statements on the security of the code. Users, both end-users and organizations using open source in their products, may benefit from ORPRO’s results.&lt;br /&gt;
&lt;br /&gt;
== Project Goals ==&lt;br /&gt;
* Independent security review of open source projects;&lt;br /&gt;
* Centrally managed;&lt;br /&gt;
* Independent statement on what is reviewed and by whom, leading a form of assurance that the software is free from security bugs;&lt;br /&gt;
* Analysis beyond code review, including digging into hard algorithms (compression, crypto, etc);&lt;br /&gt;
* Responsible disclosure of any security vulnerabilities discovered.&lt;br /&gt;
&lt;br /&gt;
== News ==&lt;br /&gt;
'''5 June 2008'''   OWASP ORPRO launched&lt;br /&gt;
&lt;br /&gt;
== Get involved ==&lt;br /&gt;
Security review takes both time and expertise. We need people with good secure coding skills in C, C++, .NET, Java, php, etc and that have the audacity to review some of the most popular open source projects around.&lt;br /&gt;
&lt;br /&gt;
Please go to https://lists.owasp.org/mailman/listinfo/open-review-project to subscribe to the list. You can post to the ORPRO mailing list by emailing [mailto:open-review-project@lists.owasp.org open-review-project@lists.owasp.org]. &lt;br /&gt;
&lt;br /&gt;
== People ==&lt;br /&gt;
Project lead: [[User:Mario de Boer|Mario de Boer]].&lt;br /&gt;
&lt;br /&gt;
Contributors: None yet, any help more than appreciated.&lt;/div&gt;</summary>
		<author><name>Njama</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Category:OWASP_Open_Review_Project&amp;diff=30542</id>
		<title>Category:OWASP Open Review Project</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Category:OWASP_Open_Review_Project&amp;diff=30542"/>
				<updated>2008-06-05T19:25:37Z</updated>
		
		<summary type="html">&lt;p&gt;Njama: Added some sections&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;== Overview ==&lt;br /&gt;
We are surrounded by open source. Not only the open source software all of us use, also many of the commercial applications contain open source libraries. And in our routers, our cars, our phones, everywhere...&lt;br /&gt;
In the OWASP Open Review Project (ORPRO) we perform open reviews of open source projects. We focus on security, are independent, and use the excellent deliverables from other OWASP projects to achieve traceable assurance statements on the security of the code. Users, both individuals and integrators, may benefit from ORPRO’s results.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Project Goals ==&lt;br /&gt;
* Independent security review of open source projects;&lt;br /&gt;
* Centrally managed;&lt;br /&gt;
* Independent statement on what is reviewed and by whom, leading a form of assurance that the software is free from security bugs;&lt;br /&gt;
* Analysis beyond code review, including digging into hard algorithms (compression, crypto, etc);&lt;br /&gt;
* Responsible disclosure of any security vulnerabilities discovered.&lt;br /&gt;
&lt;br /&gt;
== News ==&lt;br /&gt;
'''5 June 2008'''   OWASP ORPRO launched&lt;br /&gt;
&lt;br /&gt;
== Get involved ==&lt;br /&gt;
Security review takes both time and expertise. We need people with good secure coding skills in C, C++, .NET, Java, php, etc and that have the audacity to review some of the most popular open source projects around.&lt;br /&gt;
&lt;br /&gt;
Please go to https://lists.owasp.org/mailman/listinfo/open-review-project to subscribe to the list. You can post to the ORPRO mailing list by emailing [mailto:open-review-project@lists.owasp.org open-review-project@lists.owasp.org]. &lt;br /&gt;
&lt;br /&gt;
== People ==&lt;br /&gt;
Project lead: [[User:Mario de Boer|Mario de Boer]].&lt;br /&gt;
&lt;br /&gt;
Contributors: None yet, any help more than appreciated.&lt;/div&gt;</summary>
		<author><name>Njama</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Category:OWASP_Open_Review_Project&amp;diff=30538</id>
		<title>Category:OWASP Open Review Project</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Category:OWASP_Open_Review_Project&amp;diff=30538"/>
				<updated>2008-06-05T19:12:53Z</updated>
		
		<summary type="html">&lt;p&gt;Njama: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;&lt;br /&gt;
== Overview ==&lt;br /&gt;
We are surrounded by open source. Not only the open source software all of us use, also many of the commercial applications contain open source libraries. And in our routers, our cars, our phones, everywhere...&lt;br /&gt;
In the OWASP Open Review Project (ORPRO) we perform open reviews of open source projects. We focus on security, are independent, and use the excellent deliverables from other OWASP projects to achieve traceable assurance statements on the security of the code. Users, both individuals and integrators, may benefit from ORPRO’s results.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Project Goals ==&lt;br /&gt;
* Independent security review of open source projects;&lt;br /&gt;
* Centrally managed;&lt;br /&gt;
* Independent statement on what is reviewed and by whom, leading a form of assurance that the software is free from security bugs;&lt;br /&gt;
* Analysis beyond code review, including digging into hard algorithms (compression, crypto, etc);&lt;br /&gt;
* Responsible disclosure of any security vulnerabilities discovered.&lt;/div&gt;</summary>
		<author><name>Njama</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Category:OWASP_Open_Review_Project_RoadMap&amp;diff=30537</id>
		<title>Category:OWASP Open Review Project RoadMap</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Category:OWASP_Open_Review_Project_RoadMap&amp;diff=30537"/>
				<updated>2008-06-05T19:00:40Z</updated>
		
		<summary type="html">&lt;p&gt;Njama: Removed contents: was old mail, now on main page&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;&lt;/div&gt;</summary>
		<author><name>Njama</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=User:Njama&amp;diff=30377</id>
		<title>User:Njama</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=User:Njama&amp;diff=30377"/>
				<updated>2008-06-04T19:18:14Z</updated>
		
		<summary type="html">&lt;p&gt;Njama: Njama's first info&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;Hi, my name is Mario de Boer. I am with the Dutch OWASP Chapter, and run the Open Review Project.&lt;/div&gt;</summary>
		<author><name>Njama</name></author>	</entry>

	</feed>