OWASP MASVS
Code Quality and Build

OWASP MASVS OWASPMASVS-6: MASVS-CODE: Code Quality, Build Settings, and Updates

Per OWASP MASVS v2 MASVS-CODE: code quality + build settings + secure updates. Requirements include (a) implement secure coding practices including input validation + output encoding + memory safety + (b) use memory-safe languages + APIs where possible + (c) implement secure build settings including code signing + debug flag removal + symbol stripping + obfuscation where appropriate + (d) maintain dependency inventory + scan for vulnerabilities + license issues + malicious packages + (e) implement secure update mechanism including signature verification + rollback prevention + (f) protect against client-side injection (XSS in WebView + SQL in local DB + similar) + (g) integrate static + dynamic + interactive application security testing + maintain test coverage.

Query this from an agent

The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.