Category:OWASP Orizon Project

=Main=



{| style="padding: 0;margin:0;margin-top:10px;text-align:left;" |-
 * valign="top" style="border-right: 1px dotted gray;padding-right:25px;" |

OWASP Orizon
OWASP Orizon is...

Introduction
The quest for secure code is what all developers want to achieve (at least we hope so). Software must be reliable. Software must be strong. Software must be secure.

How secure does my software have to be? The correct answer is hard to find. But security is a problem that even a development team must consider.

Should skilled developers also be security gurus? Not necessarily, but it is important to provide security tools that will augment their development skills. And so our quest for secure code begins...

The OWASP Orizon project was created with the aim of providing a common ground for safe coding and code review methodologies to be applied to software. The project is approaching its first major release and it will be able to be used in a production environment in the near future.

Orizon must give thanks to Findbugs, the OWASP LAPSE Project, RATS, and Flawfinder for ideas and inspiration.

The Orizon project, hosted by Sourceforge, is here.

Description
Owasp Orizon is a code review tool intended to be used from security specialist to perform white box assessment. Orizon exposes also a set of APIs that can be used within a security tool to provide code review services.

Licensing
OWASP XXX is free to use. It is licensed under the GNU General Public License version 3.0 (GPLv3).


 * valign="top" style="padding-left:25px;width:200px;border-right: 1px dotted gray;padding-right:25px;" |

What is Orizon?
OWASP Orizon provides:


 * a tool a security specialist (or a developer with hackish state-of-mind) can use to perform code reviews
 * an engine a developer can embed in his application to provide code review services

Presentation
Link to presentation

Project Leader
Greg Disney-Leugers

Related Projects

 * OWASP_CISO_Survey


 * valign="top" style="padding-left:25px;width:200px;" |

Quick Download

 * http://sourceforge.net/projects/orizon/files/orizon-devel/v1.19/orizon_bin_1.19.tar.gz/download

News and Events

 * February, 2014 - Greg Disney-Leugers adopted the OWASP Orizon project.
 * November 2009 - we started moving from current release to the next major bump (v2.0) that will happen next June 2010 during Owasp AppSEC conference in Stockholm.

In Print
This project can be purchased as a print on demand book from Lulu.com

Classifications

 * }

=FAQs=

Available online is an Orizon presentation given at  OWASP AppSec EU 2008 in Ghent, May 2008.

Owasp Orizon Internals @ Owasp AppSec NY 2008, New York 22-25th September 2008 Orizon@AppSec NY 2008

Owasp Orizon Internals @ Owasp AppSec EU 2008, Ghent 21-22nd May 2008 Orizon@AppSec EU 2008

Owasp Orizon Internals @ Owasp Day Italy 2008, Rome 31st March 2008 Orizon@Owasp Day in Italy

OWASP Orizon Project @ SMAU eAcademy, Milan 4-7th October 2006 I will talk to SMAU eAcademy2006 next Saturday 7th October 2006 about code review and safe coding. Here you can find more information (for now, only in Italian). The last part of the speech will be about introducing the Orizon project and giving a development roadmap.

A slideshare space is available to for the presentations used in Owasp | conferences

= Acknowledgements =

Volunteers
Orizon is developed by a worldwide team of volunteers. The primary contributors to date have been:


 * Paolo Perego - former project leader
 * Steven Evans
 * Andres Riancho
 * Dinis Cruz
 * Mike Duncan
 * prashant k v
 * Alessio Marziali
 * Jason Li
 * Nishi Kumar

Others

 * OWASP Summer of Code 2008

= Road Map and Getting Involved = As of Orizon, the priorities are:
 * xxx
 * xxx
 * xxx

Orizon wants you!

The model we follow is the OpenBSD one. Anyone will be free about sending opinions, criticism and patches. If an user will provide a good number of patches showing us he (or she) really wants to collaborate to the project, than he (or she) will be added to Owasp orizon core team.

If you are a skilled Java developer why don't you consider writing a bunch of code for Orizon? Or, consider joining the project for documentation, advertising, blog maintenance, etc.

We hope you find the OWASP Orizon Project useful. Please contribute to the project by volunteering for one of the tasks, or by sending your comments, questions, and suggestions.

=Project About=