Skip to content

Add current OWASP Nest project metadata - #42

Merged
rocklambros merged 1 commit into
mainfrom
chore/owasp-nest-metadata
Sep 5, 2026
Merged

rocklambros merged 1 commit into
mainfrom
chore/owasp-nest-metadata

Conversation

@rocklambros

Copy link
Copy Markdown
Contributor

Why

OWASP Nest indexes projects from a project.owasp.yaml in the project repo. This repo has never had one on main, so the OWASP index holds no current metadata for ACS and the retired Agent Observability Standard page stands as the canonical public listing.

An owasp-nest[bot] push on 2025-10-02 created nest/owasp-agent-observability-standard-metadata with a generated draft. No PR was ever opened from it, so it went unreviewed, and the AOS → ACS rebrand landed six months later without it. That branch is now 1 ahead / 23 behind.

Why the draft wasn't salvageable

pitch: A very brief, one-line description of your project
tags: [custom-tag, custom-tag-1, custom-tag-2]

Untouched generator placeholders. It also used the retired project name, pointed website at the retired owasp.org page, listed both superseded OWASP repos including www-project-agent-observability-standard-2, and carried a leader email address.

This file is written fresh against the current project.

What changed versus the draft

Field Draft Now
name OWASP Agent Observability Standard OWASP Agent Control Standard
website retired owasp.org page agentcontrolstandard.org
repositories 2 superseded OWASP repos current repo, with CoC + contributing links
leaders included an email GitHub handles only
license Apache-2.0 Apache-2.0 + CC-BY-SA-4.0
community stale Slack, aos.owasp.org GitHub Discussions
pitch / tags placeholders real values
audience builder builder + defender

person requires only name in the schema, so leaders carry no email — consistent with #41.

Verification

  • Validates against owasp/nest-schema project.json + common.json
  • All 5 URLs return 200
  • 0 emails, 0 AOS references
  • actions/checkout pinned to the same SHA as the other workflows, explicit read-only permissions, per 81b02b1

Two things to confirm

  1. Leadership is carried over from the draft unchanged. Naming OWASP project leaders is a governance decision, not a repo one, so this PR does not alter it. Worth confirming against current leadership.
  2. level: 2 is also carried over unchanged.

The stale bot branch is deleted separately.

OWASP Nest indexes projects from a project.owasp.yaml file in the project
repository. This repository has never had one on main, so the OWASP index
carries no current metadata for ACS and the retired Agent Observability
Standard page remains the canonical public listing.

An owasp-nest[bot] push on 2025-10-02 created the branch
nest/owasp-agent-observability-standard-metadata with a generated draft.
No pull request was opened from it, so nobody reviewed it, and the rebrand
from AOS to ACS landed six months later without it. The branch is now one
commit ahead and twenty-three behind. Its draft was unusable as written:

  pitch: A very brief, one-line description of your project
  tags: custom-tag, custom-tag-1, custom-tag-2

Both were untouched generator placeholders. The draft also named the
project Agent Observability Standard, pointed website at the retired
owasp.org page, listed both superseded OWASP repositories including
www-project-agent-observability-standard-2, and carried a leader email
address.

This file is written fresh against the current project rather than
salvaged from that draft. Leaders carry GitHub handles and no email
address, which the schema allows since person requires only name. The
community channel is GitHub Discussions, matching CONTRIBUTING.md and
README.md. License records the dual Apache-2.0 and CC-BY-SA-4.0 split
rather than the draft's Apache-2.0 alone. The audience gains defender
alongside builder, since Guardian Agents are a defender-side role.

Leadership is carried over from the draft unchanged. Naming OWASP project
leaders is a governance decision rather than a repository one, so this
commit does not alter the list. It should be confirmed against the current
project leadership.

Validated against owasp/nest-schema project.json and common.json. Every
URL in the file returns 200. The validation workflow is the bot's, with
actions/checkout pinned to the same commit the other workflows use and an
explicit read-only permissions block, matching the hardening in 81b02b1.

Signed-off-by: rocklambros <rock@rockcyber.com>
@rocklambros
rocklambros merged commit 83f5632 into main Sep 5, 2026
2 checks passed
@rocklambros
rocklambros deleted the chore/owasp-nest-metadata branch September 5, 2026 14:43
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant