Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

CWE mapping #15

Open
gitnachogo opened this issue Aug 28, 2020 · 1 comment
Open

CWE mapping #15

gitnachogo opened this issue Aug 28, 2020 · 1 comment

Comments

@gitnachogo
Copy link

Hi!
I am doing a research of many different SAST applications for the final project of my cybersecurity master, and I've reached VCG. After some tests, I wanted to have an OWASP Benchmark of this tool, but I've realized there is not a reader for VCG in it.
Anyway, I am up to dev this integration, but there is a handicap due to the tool does not report the CWE number of the code issues it finds.
Anyone knows how could I map these code issues into CWE numbers in order to integrate it into OWASP Benchmark?
Thankssss :)

@gitnachogo
Copy link
Author

I've integrated VisualCodeGrepper into OWASP Benchmark, but there are many code issues whose related CWE number is unknown for me, so it would be great if you guys could make it in your side and I just would add it easily.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

1 participant