Search code examples
sonarqubeowasp

Which OWASP Top10 and SANS Top 25 for SonarQube 6.7 LTS?


I just downloaded SonarQube 6.7 LTS. I know it'll detect OWASP Top 10 and SANS Top 25...but which versions of those lists?

For instance, does the built-in tag scan for OWASP Top 10 - 2013 or 2017 or 2010?

Does the built-in tag scan for SANS Top 25 - 2009 or 2010 or 2011?


Solution

  • You can find information about OWASP and SANS in the documentation page. The page contains links to the security version-pages used in the latest SonarQube version (6.7 LTS). Based on the links provided:

    • CWE/SANS TOP 25: Version 3.0 Updated June 27, 2011
    • OWASP: 2013-Top 10

    See also this:

    To find rules that relate to any of these standards, you can search rules either by tag or by text. The standards that a rule relates to will be listed in the See section at the bottom of the rule description.

    So it is not the case that all rules can already be detected/analyzed.