[prev in list] [next in list] [prev in thread] [next in thread] 

List:       owasp-webgoat
Subject:    Re: [Owasp-webgoat] New Contributor
From:       Jason White <jason.white () owasp ! org>
Date:       2015-07-27 13:41:47
Message-ID: CAL1HEEC0Q0wEL4DfrrKvN1q6sZxp-RJ0wQLzYQ_gk6Yo3Y9=EQ () mail ! gmail ! com
[Download RAW message or body]

Hey Mitchell,

I'm Jason ... the primary UI contributor currently .. and the road block to
our next release. :)  My momentum is picking back up. I'm working at
re-implementing the 'helps' for each lesson currently, sorting out an
async. issue currently for solution/plans/source. Next up is to re-enable
the hints, then the Cookies/parameters.  I've had some folks say they're
ready to help, but no pull requests yet (we have our FT jobs and our issue
tracking is lacking a bit ... I accept a bit of the blame there).

BTW, I work on Linux for development, so I welcome some Windows/Mac users
for testing purposes. E.g. someone caught a legacy file (same name, diff.
case in file name) that was creating an issue on Windows.

As to schedule, I definitely want to have my part wrapped up in time to
have 6.1 out around AppSecUSA (mid-late September) although I don't think
I'll be there this year. For me that means the next 2-3 weeks to allow
burn-in and fix time after the initial Backbone implementation.

As noted, there have been a number of side conversations. I'll make it a
point to be more active here on the list while respecting the work email
issue.

Cheers,
Jason

On Thu, Jul 23, 2015 at 10:26 AM, webgoat webgoat <webgoat@owasp.org> wrote:

> Hi Mitchell
>
> The project is fairly active and we communicate using email and have a
> bi-weekly call and screen share to touch bases with each other.  There is a
> core team of about 5-6 people and an extended team of a few more that pop
> in and out when life allows them time to contribute.
>
> This mailing list is fairly quiet as most people send email to
> webgoat@owasp.org and that forwards to my work email.  I reply from that
> email which is not on the WebGoat mail list so the mail list is very
> inactive.
>
> We get a few requests to contribute per month but a small percentage of
> those folks actually contribute.  We encourage contributions at any level.
>
> To answer your questions:
>
> Who is currently developing on WebGoat?
>   - The about page in WebGoat is fairly accurate.  Nanne and Jason are
> probably the most active contributors right now
>   -
>
> https://github.com/WebGoat/WebGoat/blob/master/src/main/webapp/WEB-INF/pages/about.jsp
>
> Since the mailing list is quiet, are there side discussions going on?
>   - Yes, I will bring up the topic of using the mailing list again.  A lot
> of use our work emails to communicate and don;t wish our work emails to be
> in the archive.
>
> What are the current priorities for fixes and improvements?
>   - We are finishing the new plugin architecture in the WebGoat and
> WebGoat-Lessons Repos
>   - We are changing the UI to backbone
>   - We are looking for new lessons
>   - We have had lots of volunteers to test but no active output from those
> efforts
>   - We are working on getting better documentation and cleaning up of the
> various websites
>
> Is there a schedule in mind for when there might be the next release?
>   - As soon as we get the UI working again
>
> Is anyone else using Windows to run and develop WebGoat on?
>   - Windows and Mac are the two big dev platforms
>
> Should I just start fixing things, anywhere and all over?  Is anyone
> working on certain areas I should hold off touching or coordinate with?
> This is the first time I have used Git and worked with a group like this,
> all separately located.
>   - If you are working in the WebGoat or WebGoat-Lessons repos you may want
> to coordinate.  We use jira but right now it is more of a free-for-all as
> we get the 6.1 release stable
>   - Once you create Pull Request it will get reviewed by the team.  It is
> safe to work on any lessons in the WebGoat-Lessons repo.
>   - It is better to file a Jira ticket, but not needed
>
> Would someone please reply to this post just so I know someone has seen
> it?  Maybe say hello?
>   - HELLO :)
>
>
> On Wed, Jul 22, 2015 at 8:43 PM, Mitchell Fisher <mlfisher_56@hotmail.com>
> wrote:
>
> > Hi, I am just about ready to be a Contributor to WebGoat.  I am running
> on
> > Windows 7 and have GitHub set up, the source cloned to my desktop, the
> > project loaded into Eclipse, and a bat file that runs maven to build and
> > starts WebGoat.  This is all probably not a big deal for everyone else,
> but
> > this is all new to me!
> >
> > I have run through all of the examples in WebGoat except for the final
> > Challenge.  About a quarter of the way through I saw problems and posted
> > them to this list, and Bruce asked me to contribute.  Kept notes on the
> > rest of the examples, some of which I could not get to work and of those
> > some might be my misunderstanding.
> >
> > Questions:
> >
> > Who is currently developing on WebGoat?
> >
> > Since the mailing list is quiet, are there side discussions going on?
> >
> > What are the current priorities for fixes and improvements?
> >
> > Is there a schedule in mind for when there might be the next release?
> >
> > Is anyone else using Windows to run and develop WebGoat on?
> >
> > Should I just start fixing things, anywhere and all over?  Is anyone
> > working on certain areas I should hold off touching or coordinate with?
> > This is the first time I have used Git and worked with a group like this,
> > all separately located.
> >
> > Would someone please reply to this post just so I know someone has seen
> > it?  Maybe say hello?
> >
> > -Mitchell Fisher
> >
> > _______________________________________________
> > Owasp-webgoat mailing list
> > Owasp-webgoat@lists.owasp.org
> > https://lists.owasp.org/mailman/listinfo/owasp-webgoat
> >
>
>
>
> --
> Bruce Mayhew
> OWASP WebGoat Project Lead
> _______________________________________________
> Owasp-webgoat mailing list
> Owasp-webgoat@lists.owasp.org
> https://lists.owasp.org/mailman/listinfo/owasp-webgoat
>
_______________________________________________
Owasp-webgoat mailing list
Owasp-webgoat@lists.owasp.org
https://lists.owasp.org/mailman/listinfo/owasp-webgoat
[prev in list] [next in list] [prev in thread] [next in thread] 

Configure | About | News | Add a list | Sponsored by KoreLogic