This site is the archived OWASP Foundation Wiki and is no longer accepting Account Requests.
To view the new OWASP Foundation website, please visit https://owasp.org
Project Information:template Code Crawler - 50 Review - First Reviewer - C
Clik here to return to the previous page.
50% REVIEW PROCESS | ||
---|---|---|
Project Deliveries & Objectives |
||
QUESTIONS | ANSWERS | |
1. At what extent have the project deliveries & objectives been accomplished? Having in consideration the assumed ones, please exemplify writing down those of them that haven't been realised. |
The Applicaiton is definitly at least 50% complete. It has come a long way since the original version Alessio and i discussed many months ago. it is a great addition to support the code review guide and of high quality. A comprehensive intalss requirements and useage guide should accompany this tool to encourage use. | |
2. At what extent have the project deliveries & objectives been accomplished? Having in consideration the assumed ones, please quantify in terms of percentage. |
XML Driven Code Scan with OWASP Code Review Guide Database (updated) - Nice and extensible. Additional signatures can be added with ease. This is very important. 1.Easy to use UI for a faster and more friendly code review: The tool is now much eaier to navigate and view issues. ease of use is key to the adoption of such a tool to the wider community. 2.HTML Type Reports functionality will generate reports based on easy to build personalised templates.: Works, should me a selection of templates to choose from. Some people would like to simply use the tool and not be worried about customisation. XSLT Ready to use XSLT templates for a "ready to go" installation.: Works but it is important that clear documentation be delivered along with the tool so that users can start usong the tool in a quick manner. | |
3. Please do use the right hand side column to provide advice and make work suggestions. |
Good documentation is required. Looking foreward to Visual Studio .NET Solutions scans. A diff solution would be good. Metrics are also useful in an enterprise environment. (See metrics section in new code review guide). |