06 · The repository
Proposed tree, created only after acceptance.
From the initiation brief, with what the other projects taught us added: a project.owasp.yaml for OWASP’s project index (ACS carries one), a history file, and a governance file that names the sponsor and the exit path. No staging repository has been created; when one is, it will not be called an OWASP project.
README.md what it is, try it in sixty seconds, status of every edition
LICENSE LICENSING.md Apache-2.0 for code and schemas; CC BY 4.0 (or BY-SA) for documents
CONTRIBUTING.md the DCO; the house rules: no score, no verdict, no conformity language
GOVERNANCE.md leaders, decisions, the sponsor, what it may and may not do, the exit path
SECURITY.md a reviewed draft until the leads approve the channel
HISTORY.md one dated origin sentence: what RiskMandate contributed, when, under which licence
project.owasp.yaml name, pitch, level 2 (Incubator), type documentation, audience builder, leaders, licence
specification/ overview, terminology, deployment, capability, mandate, delta, barriers and evidence,
lifecycle, limitations
schemas/ grant, mandate, delta (JSON Schema, versioned)
vocabulary/ the primitives, barriers, undo classes, evidence tiers (version-pinned ids)
examples/ template ABPs: inputs, derived outputs, sources, open questions
tools/ the reference build and validator
tests/ fixtures; every example's delta must equal its recomputation
mappings/ agentic-top-10, llm-top-10, aisvs, acs, cyclonedx, opencre (ids and titles only)
roadmap/first-year.md