OWASP-Benchmark/BenchmarkJava
OWASP Benchmark is a test suite designed to verify the speed and accuracy of software vulnerability detection tools. A fully runnable web app written in Java, it supports analysis by Static (SAST), Dynamic (DAST), and Runtime (IAST) tools that support Java. The idea is that since it is fully runnable and all the vulnerabilities are actually exploitable, it’s a fair test for any kind of vulnerability detection tool. For more details on this project, please see the OWASP Benchmark Project home page.
JavaGPL-2.0
Issues
- 1
Is Checkmarx CxOne supported?
#234 opened by junghanlee - 8
Push linux/amd64 Docker image
#223 opened by thc202 - 7
- 5
Add some new vulnerability types
#203 opened by springkill - 11
- 1
- 1
Add Fluid Attacks as a SAST tool to Benchmark
#144 opened by kamadorueda - 0
add a new IAST detection tool
#171 opened by exexute - 13
- 5
Owasp benchmark version in 2018
#192 opened by kelvimSaidel - 2
- 2
How to download the dataset
#215 opened by heewonB - 28
- 6
- 4
- 6
- 2
- 4
Trying to create scorecard for Semgrep results but I get empty FluidAttacks scorecard
#199 opened by simonevallifuoco - 8
/usr/bin/jq: Argument list too long
#187 opened by mahdirezaie336 - 0
deleted
#194 opened by spring-cs-2023 - 8
Send custom csv file in createScorecards.sh
#191 opened by giper45 - 7
mvn compile or mvn install - Failed to execute goal com.diffplug.spotless:spotless-maven-plugin.
#184 opened by ebolles - 2
createScorecards.bat - Error resolving version for plugin 'org.owasp:benchmarkutils-maven-plugin' from the repositories
#183 opened by ebolles - 4
BUILD FAILURE:Failed to execute goal com.diffplug.spotless:spotless-maven-plugin:2.22.1:apply (spotless-apply) on project benchmark: Execution spotless-apply of goal com.diffplug.spotless:spotless-maven-plugin:2.22.1:apply failed: Cannot find git repository in any parent directory
#179 opened by fatshi - 2
- 9
scripts/runHorusec.sh no longer works
#176 opened by davewichers - 3
buildDockerImage script fails
#167 opened by arunmuthu255 - 1
- 5
SAXParseException generating Scorecard for SonarQube
#117 opened by akhvee - 1
- 15
the score may not reflect the tools' performance
#131 opened by NEUZhangy - 1
[DepShield] (CVSS 6.1) Vulnerability due to usage of org.owasp.antisamy:antisamy:1.6.3
#161 opened by sonatype-depshield - 3
Offline maven compile/run NOT supported
#156 opened by glansbur - 8
Adopt Standard Coding Format for Entire Project.
#142 opened by kamadorueda - 1
Add a new iAST detection tool
#124 opened by 1229256875 - 1
[DepShield] (CVSS 7.4) Vulnerability due to usage of org.hibernate:hibernate-core:3.6.10.Final
#153 opened by sonatype-depshield - 1
[DepShield] (CVSS 9.8) Vulnerability due to usage of log4j:log4j:1.2.17
#149 opened by sonatype-depshield - 1
- 4
unintended cookie attribute injections
#139 opened by maltek - 7
Maven build fails inside Docker on Debian Host
#137 opened by alexpostolache - 2
- 1
Add CodeQL as a SAST tool to Benchmark
#132 opened by Niweera - 5
Update Findbugs/spotbugs parser
#126 opened by BertSchoovaerts - 5
Bug in XSS ajax tests?
#120 opened by iosebyte - 5
Ask questions
#122 opened by Guodafeng-tl - 4
请大佬解答一下对于benchmark项目,mvn命令怎么进行debug调试程序呢
#119 opened by Guodafeng-tl - 5
Reader for VisualCodeGrepper
#113 opened by gitnachogo - 2
[DepShield] (CVSS 7.3) Vulnerability due to usage of commons-beanutils:commons-beanutils:1.9.3
#100 opened by sonatype-depshield - 0
- 6
Expected results file extensions?
#104 opened by LuisVentuzelos