You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Copy file name to clipboardExpand all lines: docs/contributing/index.md
+15-9Lines changed: 15 additions & 9 deletions
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -6,7 +6,7 @@ _First of all,_ [⭐ Give us a Star in GitHub](https://github.com/OWASP/mastg)!
6
6
7
7
<br>
8
8
9
-
The MAS project is an opensource effort and we welcome all kinds of contributions and feedback.
9
+
The MAS project is an open-source effort, and we welcome all kinds of contributions and feedback.
10
10
11
11
**Help us improve & join our community:**
12
12
@@ -16,20 +16,26 @@ The MAS project is an open source effort and we welcome all kinds of contributio
16
16
17
17
**Contribute with content:**
18
18
19
-
- 💡 Propose ideas or suggest improvements ([MASTG](https://github.com/OWASP/mastg/discussions/categories/ideas)/[MASVS](https://github.com/OWASP/masvs/discussions/categories/ideas)). If it qualifies we'll promote it to an Issue.
19
+
- 💡 Propose ideas or suggest improvements ([MASTG](https://github.com/OWASP/mastg/discussions/categories/ideas)/[MASVS](https://github.com/OWASP/masvs/discussions/categories/ideas)). If it qualifies, we'll promote it to an Issue.
20
20
- 📄 [Create a Pull Request](3_PRs_and_Reviews.md#how-to-open-a-pr) for concrete fixes (e.g. grammar/typos) or content already approved by the core team.
21
21
22
-
Before you start contributing, please check our pages ["How Can You Contribute?"](1_How_Can_You_Contribute.md) and ["Getting Started"](2_Getting_Started.md). If you have any doubts [please contact us](../contact.md).
22
+
Before you start contributing, please check our pages ["How Can You Contribute?"](1_How_Can_You_Contribute.md) and ["Getting Started"](2_Getting_Started.md). If you have any doubts,[please contact us](../contact.md).
23
23
24
24
## 🚫 What not to do
25
25
26
26
Although we greatly appreciate any and all contributions to the project, there are a few things that you should take into consideration:
27
27
28
-
-**No advertisement**: The OWASP mobile Security Project cannot be used as a platform for advertisement of commercial tools, companies or individuals. Technical content such as the implementation of certain techniques or tests should be written with free and open-source tools in mind. Commercial tools are typically not accepted, but might be referenced in some specific cases.
28
+
-**No advertisement**: The OWASP Mobile Security Project cannot be used as a platform for advertisement of commercial tools, companies, or individuals. Technical content, such as the implementation of certain techniques or tests, should be written with free and open-source tools in mind. Commercial tools are typically not accepted, but might be referenced in some specific cases.
29
29
-**No unnecessary self-promotion of tools or blog posts**: If you have a relation with one of the URLs or tools you are referencing, please state so in the PR so that we can verify that the reference is in line with the rest of the guide.
30
30
31
31
Please be sure to take a careful look at our [Code of Conduct](https://github.com/OWASP/mastg/blob/master/.github/CODE_OF_CONDUCT.md"Code of Conduct") for all the details and [ask us](../contact.md) in case of doubt.
32
32
33
+
## CPEs (Continuing Professional Education) and CEUs (Continuing Education Units) accreditation
34
+
35
+
Information security professionals holding certifications from major organizations, such as (ISC)², ISACA, and GIAC, may be eligible to claim Continuing Professional Education (CPE) credits or CompTIA Continuing Education Units (CEUs) for their active contributions to the OWASP Mobile Application Security (MAS) project.
36
+
37
+
Please refer to the respective certification body's guidelines for claiming CPEs or CEUs, as they may have specific requirements regarding the type and extent of contributions that qualify for credit. Generally, contributions such as technical writing for the MASVS, MASWE, and MASTG may be eligible for professional credits in a ratio of 1 hour of contribution to the Profession = 1 CPE/CEU.
38
+
33
39
## Tool Inclusion Disclaimer for Contributors
34
40
35
41
OWASP MASTG encourages community contributions, including security testing tools that provide clear and practical value. However, all tool submissions are subject to review and may be rejected if they appear to be self-promotional, lack relevance, or do not meet minimum quality standards (e.g., documentation, usability, maintenance).
@@ -40,11 +46,11 @@ To be considered for inclusion, tools should be:
40
46
- Clearly documented and usable by the community
41
47
- Actively maintained, with updates tracking Android and iOS platform changes whenever applicable
42
48
43
-
Even after inclusion, tools are subject to removal if they become outdated, broken, unmaintained, or otherwise no longer align with the goals of the MASTG. Inclusion is not permanent and does not imply endorsement by OWASP.
49
+
Even after inclusion, tools may be removed if they become outdated, broken, unmaintained, or no longer align with the goals of the MASTG. Inclusion is not permanent and does not imply endorsement by OWASP.
44
50
45
-
In instances where no suitable open-source alternative exists, we may include closed-source tools. However, any closed-source tools included must be free to use, as we aim to avoid featuring paid tools whenever possible. This also extends to freeware or community editions of commercial tools.
51
+
When no suitable open-source alternative exists, we may include closed-source tools. However, any closed-source tools included must be free to use, as we aim to avoid featuring paid tools whenever possible. This also extends to freeware or community editions of commercial tools.
46
52
47
-
Our goal is to be vendor-neutral and to serve as a trusted learning resource, which is why we've **avoid the inclusion of "automated mobile application security scanners"** due to the competitive challenges they pose. Instead, we focus on tools that provide full code access and comprehensive testing, as they are better suited for educational purposes. Tools that lack this transparency, even if they offer a free version, typically do not meet the OWASP MAS project's inclusion criteria.
53
+
Our goal is to be vendor-neutral and serve as a trusted learning resource, which is why we've **avoided the inclusion of "automated mobile application security scanners"** due to the competitive challenges they pose. Instead, we focus on tools that provide full code access and comprehensive testing, as they are better suited for educational purposes. Tools that lack this transparency, even if they offer a free version, typically do not meet the OWASP MAS project's inclusion criteria.
48
54
49
55
<br>
50
56
@@ -71,7 +77,7 @@ _Coming soon..._
71
77
72
78
### OWASP MASVS V1
73
79
74
-
The latest version of the MASVS v1 including all translations is available here: <https://github.com/OWASP/masvs/releases/tag/v1.5.0>
80
+
The latest version of the MASVS v1, including all translations, is available here: <https://github.com/OWASP/masvs/releases/tag/v1.5.0>
75
81
76
82
| Project Lead | Lead Author | Contributors and Reviewers |
77
83
| ------- | --- | ----------------- |
@@ -105,7 +111,7 @@ The latest version of the MASTG v1 is available here: <https://github.com/OWASP/
105
111
-**Reviewers**: Reviewers have consistently provided useful feedback through GitHub issues and pull request comments.
106
112
-**Top Contributors**: Top contributors have consistently contributed quality content and have at least 500 additions logged in the GitHub repository.
107
113
-**Contributors**: Contributors have contributed quality content and have at least 50 additions logged in the GitHub repository.
108
-
-**Mini Contributors**: Many other contributors have committed small amounts of content, such as a single word or sentence (less than 50 additions).
114
+
-**Mini Contributors**: Many other contributors have committed small amounts of content, such as a single word or sentence (fewer than 50 additions).
109
115
110
116
| Authors | Reviewers | Top Contributors | Contributors | Mini Contributors | Editors |
0 commit comments