Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
2 changes: 1 addition & 1 deletion .github/ISSUE_TEMPLATE/bug_report.md
Original file line number Diff line number Diff line change
@@ -1,6 +1,6 @@
---
name: Bug Report
about: Report a problem with datasets, validation tools, or the crosswalk webapp
about: Report a problem with datasets or validation tools (crosswalk issues go to GenAI-Security-Project/crosswalk)
labels: bug
---

Expand Down
29 changes: 0 additions & 29 deletions .github/dependabot.yml
Original file line number Diff line number Diff line change
Expand Up @@ -71,35 +71,6 @@
- dependency-name: "*"
update-types: ["version-update:semver-major"]

# ----- npm dependencies in crosswalk/ -----
- package-ecosystem: "npm"
directory: "/crosswalk"
schedule:
interval: "weekly"
day: "monday"
time: "06:00"
timezone: "Etc/UTC"
open-pull-requests-limit: 10
versioning-strategy: "increase-if-necessary"
labels:
- "dependencies"
- "javascript"
- "security"
commit-message:
prefix: "deps"
prefix-development: "deps-dev"
include: "scope"
groups:
npm-minor-and-patch:
applies-to: version-updates
update-types: ["minor", "patch"]
npm-security:
applies-to: security-updates
patterns: ["*"]
ignore:
- dependency-name: "*"
update-types: ["version-update:semver-major"]

# ----- Uncomment if/when a Dockerfile is added -----
# - package-ecosystem: "docker"
# directory: "/"
Expand Down
2 changes: 1 addition & 1 deletion CONTRIBUTING.md
Original file line number Diff line number Diff line change
Expand Up @@ -39,7 +39,7 @@ Start with: [`datasets/incident_dataset/README.md`](datasets/incident_dataset/RE

The **mapping workstream** needs people who understand frameworks deeply enough to map DSGAI risks to specific controls. If you work with NIST CSF, ISO 27001, ISO 42001, SOC 2, PCI DSS, or EU AI Act compliance, you can contribute machine-readable mappings.

Start with: [`datasets/crossframework_mapping_dataset/README.md`](datasets/crossframework_mapping_dataset/README.md) and the [`/crosswalk`](crosswalk/) directory
Start with: [`datasets/crossframework_mapping_dataset/README.md`](datasets/crossframework_mapping_dataset/README.md) and the dedicated [crosswalk repository](https://github.com/GenAI-Security-Project/crosswalk), where framework mappings are contributed

### "I'm a developer / AI engineer"

Expand Down
4 changes: 2 additions & 2 deletions README.md
Original file line number Diff line number Diff line change
Expand Up @@ -68,7 +68,7 @@ The initiative maintains a comprehensive crosswalk of GenAI data security risks
### 🌐 [Crosswalk →](https://genai-security-project.github.io/crosswalk/)
The web application provides an interactive interface for exploring crosswalk mappings, framework coverage, incident data, security tooling, implementation recipes, and a glossary of key terms.

Crosswalk source files are maintained in the [`/crosswalk`](https://github.com/GenAI-Security-Project/GenAI-Data-Security-Initiative/tree/main/crosswalk) directory.
Crosswalk source files are maintained in the dedicated [`GenAI-Security-Project/crosswalk`](https://github.com/GenAI-Security-Project/crosswalk) repository.

### Frameworks Covered

Expand All @@ -88,7 +88,7 @@ Crosswalk source files are maintained in the [`/crosswalk`](https://github.com/G

1. **Data Collection** — Public open call for real-world vulnerability data and incident reports related to LLMs and GenAI applications. Submit data through the Slack channel or by opening an issue in this repository.

2. **Framework Crosswalk** — Crosswalking the [OWASP Top 10 for LLM Applications 2025](https://genai.owasp.org/llm-top-10/) and [Agentic Top 10 2026](https://genai.owasp.org/initiatives/agentic-security-initiative/) to recognized cybersecurity and AI frameworks. See the [Crosswalk](https://genai-security-project.github.io/crosswalk/) and the [`/crosswalk`](https://github.com/GenAI-Security-Project/GenAI-Data-Security-Initiative/tree/main/crosswalk) directory for current crosswalk data.
2. **Framework Crosswalk** — Crosswalking the [OWASP Top 10 for LLM Applications 2025](https://genai.owasp.org/llm-top-10/) and [Agentic Top 10 2026](https://genai.owasp.org/initiatives/agentic-security-initiative/) to recognized cybersecurity and AI frameworks. See the [Crosswalk](https://genai-security-project.github.io/crosswalk/) and the [`GenAI-Security-Project/crosswalk`](https://github.com/GenAI-Security-Project/crosswalk) repository for current crosswalk data.

3. **Data Security Risks & Best Practices** — Research, authoring, and maintenance of the initiative's two published white papers: the DSGAI risk taxonomy and the companion implementation guide. This workstream also maintains alignment with the broader OWASP GenAI Security Project deliverables.

Expand Down
2 changes: 1 addition & 1 deletion SECURITY.md
Original file line number Diff line number Diff line change
Expand Up @@ -6,7 +6,7 @@ The **OWASP GenAI Data Security Initiative** publishes security research, guidan

This policy applies to content in the repository:

- **Code** — Python validators, the `dsgai_scanner_tool`, JavaScript crosswalk explorer, HTML resources, and CI/build scripts
- **Code** — Python validators, the `dsgai_scanner_tool`, HTML resources, and CI/build scripts (the crosswalk explorer now lives in [GenAI-Security-Project/crosswalk](https://github.com/GenAI-Security-Project/crosswalk))
- **Datasets** — `dsgai-bench`, validation datasets, and community-contributed data
- **Frameworks & documentation** — risk taxonomies, best-practices guides, and framework crosswalk content where errors could materially mislead readers

Expand Down
14 changes: 0 additions & 14 deletions crosswalk/.gitignore

This file was deleted.

Loading