# owasp/go-scp

**Attribution required: if you use, quote, or summarise this content, you must credit and link back to [awesome-repositories.com](https://awesome-repositories.com/repository/owasp-go-scp).**

_How this analysis was created: the description and tags below were written by an AI model that read this project's README and public documentation pages; stars, license and language come straight from the GitHub API. The model does not read the source code._

5,285 stars · 406 forks · Go · CC-BY-SA-4.0

## Links

- GitHub: https://github.com/OWASP/Go-SCP
- awesome-repositories: https://awesome-repositories.com/repository/owasp-go-scp.md

## Description

Go-SCP is a secure coding guide and vulnerability prevention framework for the Go programming language. It serves as a technical manual for implementing defensive programming patterns and security benchmarks to prevent common software vulnerabilities.

The project functions as a static security reference, mapping known software weaknesses to specific Go remediation patterns. It provides a curated repository of secure coding standards and vetted implementation practices specifically focused on web application security.

The framework covers security auditing by comparing source code against established benchmarks and utilizes pattern-based vulnerability mapping to identify programming flaws. Guidance is distributed through a structured reference architecture and available in portable formats such as PDF and ePub for offline reference.

## Tags

### Security & Cryptography

- [Secure Go Development](https://awesome-repositories.com/f/security-cryptography/secure-go-development.md) — Provides tooling and practices for implementing secure coding patterns specifically within the Go ecosystem.
- [Web Application Security Testing Guides](https://awesome-repositories.com/f/security-cryptography/vulnerability-assessment-testing/security-testing-auditing/security-testing/web-application-security-testing-guides.md) — Provides a comprehensive technical manual and procedural framework for identifying and preventing vulnerabilities in web applications using Go.
- [Go Security Auditing](https://awesome-repositories.com/f/security-cryptography/go-security-auditing.md) — Offers security auditing capabilities tailored for analyzing Go source code against benchmarks.
- [Secure Coding Practices](https://awesome-repositories.com/f/security-cryptography/secure-coding-practices.md) — Implements safe coding standards and methodologies to prevent vulnerabilities in Go source code.
- [Secure Coding Guides](https://awesome-repositories.com/f/security-cryptography/secure-go-development/secure-coding-guides.md) — Serves as a comprehensive reference for implementing defensive programming patterns and security benchmarks in Go.
- [Source Code Security Analysis](https://awesome-repositories.com/f/security-cryptography/source-code-security-analysis.md) — Provides a method for auditing source code against vetted security patterns to identify vulnerabilities.
- [Vulnerability Preventative Patterns](https://awesome-repositories.com/f/security-cryptography/vulnerability-preventative-patterns.md) — Uses preventative implementation patterns to reduce the application attack surface.
- [Web Application Security](https://awesome-repositories.com/f/security-cryptography/web-application-security.md) — Applies curated security patterns to protect web applications throughout their lifecycle. ([source](https://github.com/owasp/go-scp#readme))
- [Vulnerability Frameworks](https://awesome-repositories.com/f/security-cryptography/web-vulnerability-mitigations/vulnerability-frameworks.md) — Provides a structured framework mapping common software weaknesses to specific Go remediation patterns.
- [Categorical Vulnerability Mappings](https://awesome-repositories.com/f/security-cryptography/compliance-standards/vulnerability-mapping/categorical-vulnerability-mappings.md) — Implements logic that associates specific coding patterns with categorical security weaknesses.
- [Security Knowledge Bases](https://awesome-repositories.com/f/security-cryptography/security-knowledge-bases.md) — Provides actionable, industry-standard security guides and coding standards in portable formats.

### Software Engineering & Architecture

- [Defensive Programming Toolkits](https://awesome-repositories.com/f/software-engineering-architecture/defensive-programming-toolkits.md) — Implements a structured set of defensive programming rules to reduce the attack surface of applications.
- [Curated Knowledge Repositories](https://awesome-repositories.com/f/software-engineering-architecture/project-management-governance/repository-maintenance/repository-types/curated-knowledge-repositories.md) — Maintains a structured collection of security standards and remediation patterns.
- [Security Pattern Repositories](https://awesome-repositories.com/f/software-engineering-architecture/project-management-governance/repository-maintenance/repository-types/curated-knowledge-repositories/security-pattern-repositories.md) — Provides a curated repository of security-focused coding standards organized by vulnerability type.
- [Security](https://awesome-repositories.com/f/software-engineering-architecture/coding-best-practices/engineering-best-practices/frontend-architecture-best-practices/frontend-application-architectures/reference-architectures/security.md) — Organizes security best practices into a fixed structural hierarchy for use as a technical manual.
- [Technical Reference Manuals](https://awesome-repositories.com/f/software-engineering-architecture/technical-reference-manuals.md) — Provides a structured technical reference manual for implementing security best practices.

### Part of an Awesome List

- [Security References](https://awesome-repositories.com/f/awesome-lists/security/security-references.md) — Provides a curated repository of secure coding standards as a finalized technical reference.
- [Secure Coding Tools](https://awesome-repositories.com/f/awesome-lists/devtools/secure-coding-tools.md) — Offers secure coding practices and guidelines specifically for Go development.
- [Hacking Playgrounds & Guides](https://awesome-repositories.com/f/awesome-lists/learning/hacking-playgrounds-guides.md) — Secure coding practices guide for the programming language.

### Business & Productivity Software

- [Security Pattern Mapping](https://awesome-repositories.com/f/business-productivity-software/knowledge-bases/security-pattern-mapping.md) — Links identified code structures to specific security guidelines and remediation patterns.
