sgit newsroom v0.1.29 · snapshot 2026-09-24

Reading room · riskmandate.ai

Reading room / riskmandate.ai · raw text · live ↗

From riskmandate.ai, the page as fetched on 2026-09-24 · open the live page ↗Everything on this sheet is the source site's own text; the newsroom's chrome is outside it.

OWASP and open source first

The lead's memo of today (D17↗) says where the business cases should start with other people's work: with open source, which anybody can deploy without a commercial conversation. It asks for OWASP above all, because the lead is closely involved there and wants to bring RiskMandate's ideas to it. It asks for a semantic graph of OWASP, which it says does not exist. And it asks for enough cases that the section is worth a commercial vendor's time.

What was not done: OWASP's documents, the Top 10s, ASVS and SAMM, are not cases. They change what a team knows, not what an agent can reach, so they sit in the graph. Across the eighteen projects, nothing moves who owns the stop, the side effects of stopping, the procedure after it, or the class of data in reach. Those are decisions, not software. Outreach to OWASP projects, maintainers and companies is the lead's, after review.