| Top 10 | Year-named editions; identifiers carry the year (A01:2025); the repository labels each edition RELEASED, SUPERSEDED or HISTORIC | An old citation never silently changes meaning. Every ABP release gets a status label, and none is deleted |
| ASVS | Version-pinned requirement ids (v5.0.0-1.2.5); CONTRIBUTING.md says what a major, minor and patch release may change; CSV and JSON per release | A version-pinned id for every primitive and every template row, and a written rule for what each release type may change |
| SAMM | The core repository holds the raw model data that the website and toolbox are generated from; footer line “This is an OWASP project.” | One raw source, everything generated. The vaults already work this way; the project says so and publishes the source |
| Cheat Sheet Series | Cross-indexes to ASVS, MASVS, Proactive Controls and the Top 10; sheets on AI Agent Security, MCP Security and agent execution evidence | Cross-indexes make a project useful to people arriving from elsewhere. The AI Agent Security sheet is the first place to link to and from |
| Juice Shop | Added a second co-leader on 29 January 2025, which its post describes as closing a requirement of the 2021 policy; publishes a fortnightly developer meeting on the OWASP calendar | Two leaders, or more, from day one. Publish the meeting |
| ZAP | Left OWASP for the Linux Foundation’s Software Security Project on 1 August 2023; joined Checkmarx on 24 September 2024; each move announced with the reasons, what stayed (licence, core-team control) and what changed | Write the exit path before it is needed: what the sponsor may influence, and what it may not |
| CycloneDX | JSON, XML and Protobuf schemas with a media type and file-name convention; About pages for governance, guiding principles (including vendor neutrality), supporters, history and branding; an Industry Working Group for vendors; ratified as ECMA-424 in June 2024. Its Blueprints working group is developing a “Bill of Behaviors” for expected against actual behaviour | A schema with a media type, a complete About set, a separate group where vendors advise, and a conversation with the Blueprints group before either of us defines behaviour twice |
| Dependency-Track | A tool and its data format are two OWASP projects pointing at each other (with CycloneDX); the founder’s tenth-anniversary post names the original employer’s use case | The format and the tools that read it can be separate. Start as one project; keep the seam visible |
| GenAI Security Project | Mission and charter, governance (a meritocratic model with lazy consensus, 72 hours), leadership, sponsorship and branding pages; monthly open meeting; took in the Agent Control Standard on 1 September 2026; sponsors’ logos appear in each project asset | The page set is complete and worth following. Sponsor logos inside an ABP are not: a project that describes vendors’ agents keeps vendors’ logos out of its documents |
| AI Exchange | Names, in one sentence on its people page, the company that donated the initial framework; lists contributors with their organisations; linked into OpenCRE | The originating company named once, plainly, with what it donated and when |
| Threat Dragon | A numbered “try it” walk-through to a demo and a sample threat model; threat models saved as JSON; a published roadmap and community manifesto | A sixty-second path: open one template ABP, live, from the project page |
| CRS | Copyright history kept in the README (a company to 2020, then the project); a sponsor post states what the sponsor’s product uses CRS for, what it contributes back and what the money pays for; an LTS line beside the latest release | Keep the origin in the README; say what sponsorship buys and that it does not buy governance; tell adopters which version to build on |