## OWASP and open source first

The lead's memo of today ([D17](briefs.html)) says where the business cases should start with
other people's work: with open source, which anybody can deploy without a commercial conversation.
It asks for OWASP above all, because the lead is closely involved there and wants to bring
RiskMandate's ideas to it. It asks for a semantic graph of OWASP, which it says does not exist. And
it asks for enough cases that the section is worth a commercial vendor's time.

- **[OWASP, as a graph](owasp-graph.html).** You can zoom from the foundation, through four
  families, to 52 projects and documents, and down to 110 numbered items of eleven lists, titles
  only. It shows 62 relationships, each taken from OWASP's own pages, including the frameworks
  outside OWASP that its projects map to. Each project shows its level from its live page. OWASP
  also records levels in two other places, the three disagree for several projects, and the page
  says so. Four other contradictions are published unresolved, among them two different titles for
  the sixth item of the MCP Top 10. The data is published as
  [graph.json](business-case/owasp/graph.json), to be offered to OWASP.
- **The graph meets the model.** Each item of the Agentic Top 10 is joined to the answers in our
  model that bound it, the risks those answers establish, and the open-source cases that change
  them. The join is computed from the cases, and the reading of each item is ours. Three items
  touch nothing in the model: supply chain, memory and context, and agents talking to agents. That
  says where the model has to grow.
- **Eighteen open-source cases**, OWASP's first: Coraza, Threat Dragon with pytm, then Open Policy
  Agent, OpenFGA, Cedar, Keycloak, OpenBao, Cilium, Squid, gVisor, agentgateway, LiteLLM, Langfuse,
  Falco, Unleash, Velero, PostgreSQL point-in-time recovery, and LangGraph's human-in-the-loop.
  Every change is backed by a sentence from the project's own documentation. Each sentence was
  checked on the page, together with the condition it depends on, the project's documented failure
  behaviour and any contradictions between its pages. Each case also says what adopting the
  project takes, because free is not free and customising it is most of the work. agentgateway
  moves from draft to published under the lead's direction for open source.
- **Eighteen companies built on open source**, from Codific, DefectDojo and iteratec beside OWASP
  to the companies around the projects above. A quote appears only where it was checked word for
  word, and three that could not be are plain descriptions instead.

What was not done: OWASP's documents, the Top 10s, ASVS and SAMM, are not cases. They change what
a team knows, not what an agent can reach, so they sit in the graph. Across the eighteen projects,
nothing moves who owns the stop, the side effects of stopping, the procedure after it, or the class
of data in reach. Those are decisions, not software. Outreach to OWASP projects, maintainers and
companies is the lead's, after review.
