OWASP and open source first
The lead's memo of today (D17↗) says where the business cases should start with other people's work: with open source, which anybody can deploy without a commercial conversation. It asks for OWASP above all, because the lead is closely involved there and wants to bring RiskMandate's ideas to it. It asks for a semantic graph of OWASP, which it says does not exist. And it asks for enough cases that the section is worth a commercial vendor's time.
- OWASP, as a graph↗. You can zoom from the foundation, through four families, to 52 projects and documents, and down to 110 numbered items of eleven lists, titles only. It shows 62 relationships, each taken from OWASP's own pages, including the frameworks outside OWASP that its projects map to. Each project shows its level from its live page. OWASP also records levels in two other places, the three disagree for several projects, and the page says so. Four other contradictions are published unresolved, among them two different titles for the sixth item of the MCP Top 10. The data is published as graph.json↗, to be offered to OWASP.
- The graph meets the model. Each item of the Agentic Top 10 is joined to the answers in our model that bound it, the risks those answers establish, and the open-source cases that change them. The join is computed from the cases, and the reading of each item is ours. Three items touch nothing in the model: supply chain, memory and context, and agents talking to agents. That says where the model has to grow.
- Eighteen open-source cases, OWASP's first: Coraza, Threat Dragon with pytm, then Open Policy Agent, OpenFGA, Cedar, Keycloak, OpenBao, Cilium, Squid, gVisor, agentgateway, LiteLLM, Langfuse, Falco, Unleash, Velero, PostgreSQL point-in-time recovery, and LangGraph's human-in-the-loop. Every change is backed by a sentence from the project's own documentation. Each sentence was checked on the page, together with the condition it depends on, the project's documented failure behaviour and any contradictions between its pages. Each case also says what adopting the project takes, because free is not free and customising it is most of the work. agentgateway moves from draft to published under the lead's direction for open source.
- Eighteen companies built on open source, from Codific, DefectDojo and iteratec beside OWASP to the companies around the projects above. A quote appears only where it was checked word for word, and three that could not be are plain descriptions instead.
What was not done: OWASP's documents, the Top 10s, ASVS and SAMM, are not cases. They change what a team knows, not what an agent can reach, so they sit in the graph. Across the eighteen projects, nothing moves who owns the stop, the side effects of stopping, the procedure after it, or the class of data in reach. Those are decisions, not software. Outreach to OWASP projects, maintainers and companies is the lead's, after review.