Qortora · Search · Indexed page
owasp.org Fetched 2026-09-15T01:53:53Z
OWASP Foundation - The Open Source Foundation for Application Security The Open Web Application Security Project® (OWASP) is a nonprofit foundation that works to improve the security of software through open-source tools, expert education, and collaborative innovation.
Open original source · Full cached text
OWASP Foundation - The Open Source Foundation for Application Security Explore the World of Cyber Security Empowering a global community to build secure software through open-source tools, expert education, and collaborative innovation — free for everyone, everywhere. Explore OWASP Projects Join the Community Become a Corporate Supporter 22 SEP 2026 OWASP 25th Anniversary Virtual Conference Global Join us as we celebrate OWASP's 25th Anniversary with a free virtual conference dedicated to the global community that makes our mission possible. This milestone event features a dynamic lineup of insightful talks and inspiring highlights from OWASP chapters. Register Now More Info Free! Latest News Stay updated with OWASP announcements, events, and community highlights. DependencyTrack 5.0 released! OWASP Dependency-Track, the open source platform that organizations use to identify and reduce risk in the software supply chain, today announced the general availability of version 5.0. Developed under the codename Hyades, v5 is the most extensive redesign since the platform’s inception. It rebuilds how Dependency-Track scales, survives failure, and reasons about risk, while keeping the workflows teams already rely on. Lauren Thomas DependencyTrack 5.0 released! OWASP Dependency-Track, the open source platform that organizations use to identify and reduce risk in the software supply chain, today announced the general availability of version 5.0. Developed under the codename Hyades, v5 is the most extensive redesign since the platform’s inception. It rebuilds how Dependency-Track scales, survives failure, and reasons about risk, while keeping the workflows teams already rely on. Horizontal scaling and active/active high availability. Stateless API server instances coordinate through PostgreSQL alone, with no message broker and no peer to peer networking, so a cluster can span availability zones and scale up or down without reconfiguration. Processing that survives crashes. An embedded durable execution engine resumes bill of materials processing, vulnerability analysis, and notification delivery from the exact step they reached, and retries failed steps automatically with backoff instead of waiting for someone to trigger them again. Software supply chain integrity verification. Dependency-Track now flags components whose published hashes do not match what the upstream package registry served, catching typosquatting and registry side tampering, a class of attack that v4 left to tools further down the pipeline. Smarter, expression based policies. A new policy engine built on Common Expression Language (CEL) powers component policies, vulnerability policies that can automatically audit or suppress findings before they reach analysts, and notification filters that can match on any field of an event, such as firing only at or above a chosen severity. One database, fewer failure modes. v5 standardizes on PostgreSQL and moves search, caching, and metrics into the database. The local search index disappears, along with the index corruption and disk space failures that came with it, and metrics become a proper time series with bounded retention. Built for operations. A dedicated management endpoint exposes Prometheus metrics and Kubernetes style liveness and readiness probes on their own port, integration secrets are centralized behind a pluggable provider for easier rotation and audit, and pluggable file storage supports shared volumes or S3 compatible object storage. Governance and data lifecycle. Portfolio access control graduates out of beta with bounded overhead at scale, and configurable retention keeps inactive project versions and time series metrics from growing without bound. Continue Reading GSoC 2026 What's on Deck? Contributors will get hands-on experience improving and expanding some of OWASP's most vital tools: Juice Shop A globally-used, intentionally insecure web app for security training. Nettacker A fast, automated network scanner built for vulnerability detection. Offensive Web Testing Framework A smart framework for streamlined penetration testing. Bug Logging Tool (BLT) A next-gen bug tracker focused on gamification to incentivize bug and security reporting. Nest Core infrastructure to power and enable the OWASP projects and contributors ecosystem. PyGoat A Python-based sandbox for learning and exposing security flaws in modern stacks. OpenCRE A collaborative cybersecurity knowledge base & reference system. Upcoming Events Stay connected with the global AppSec community through OWASP's upcoming conferences, chapter meetups, and training sessions. See All Events Join the OWASP Community Connect with developers and security professionals worldwide. Contribute to open-source projects building the future of application security. Become a Member Corporate Supporters Become a Corporate Supporter OWASP is a nonprofit foundation improving software security through open-source projects, global communities, and education. All resources are free and open to everyone. Quick Links AwardsChaptersCommunityContactCorporate SupportersEventsImpact Report 2025NewsProjectsStaffStrategic Plan 2026Visit Store Legal & Governance About OWASPBoardBoard EUFinance & GovernanceFinance (all documents)Legal Socials BlueskyGitHubLinkedInMastodonSlackXYouTube Make a DonationJoin NowJoin Slack OWASP, the OWASP logo, and Global AppSec are registered trademarks and AppSec Days, AppSec California, AppSec Cali, SnowFROC, OWASP Boston Application Security Conference, and LASCON are trademarks of the OWASP Foundation, Inc. © 2026, OWASP Foundation Inc. All rights reserved. Outline Explore the World of Cyber Security OWASP 25th Anniversary Virtual Conference Latest News DependencyTrack 5.0 released! DependencyTrack 5.0 released! What's on Deck? Juice Shop Nettacker Offensive Web Testing Framework Keywords OWASP, cybersecurity, web application security, software security, security tools, open source
Presented by Qortora, a product of Qortora, LLC. Content remains the property of the original publisher. This reference page supports transparent discovery within the Qortora index.