') + ')', 'gi'); if (regex.test(text)) { found = true; var frag = document.createDocumentFragment(); var parts = text.split(regex); parts.forEach(function(part, i) { if (i % 2 === 0) { frag.appendChild(document.createTextNode(part)); } else { var span = document.createElement('span'); span.className = 'userscript-highlight'; span.textContent = part; frag.appendChild(span); } }); node.parentNode.replaceChild(frag, node); } }); } else if (node.nodeType === 1 && node.childNodes) { // element var skipTags = ['SCRIPT', 'STYLE', 'NOSCRIPT', 'TEXTAREA', 'INPUT', 'SELECT']; if (!skipTags.includes(node.tagName)) { Array.from(node.childNodes).forEach(highlight); } } } highlight(document.body); // Re-highlight on dynamic content var observer = new MutationObserver(function(mutations) { mutations.forEach(function(m) { m.addedNodes.forEach(function(node) { if (node.nodeType === 1 || node.nodeType === 3) highlight(node); }); }); }); observer.observe(document.body, { childList: true, subtree: true }); })(); } } catch(__e) { console.warn('[Userscript:Highlight Search Terms]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + ', 'i'); if (__m === '*' || __re.test(location.href)) { // Strip utm_, fbclid, gclid, etc. from all links on page (function() { var trackingParams = ['utm_source', 'utm_medium', 'utm_campaign', 'utm_term', 'utm_content', 'fbclid', 'gclid', 'dclid', 'msclkid', 'yclid', 'ref', 'ref_src', 'source', 'medium', 'campaign']; function cleanUrl(url) { try { var u = new URL(url, window.location.origin); var changed = false; trackingParams.forEach(function(p) { if (u.searchParams.has(p)) { u.searchParams.delete(p); changed = true; } }); return changed ? u.toString() : url; } catch (e) { return url; } } function cleanLinks() { document.querySelectorAll('a[href]').forEach(function(a) { var clean = cleanUrl(a.href); if (clean !== a.href) a.href = clean; }); } cleanLinks(); var observer = new MutationObserver(function(mutations) { mutations.forEach(function(m) { m.addedNodes.forEach(function(node) { if (node.nodeType === 1) { if (node.tagName === 'A') cleanLinks(); node.querySelectorAll('a[href]').forEach(function(a) { var clean = cleanUrl(a.href); if (clean !== a.href) a.href = clean; }); } }); }); }); observer.observe(document.body, { childList: true, subtree: true }); })(); } } catch(__e) { console.warn('[Userscript:Remove Tracking Parameters from Links]', __e); } })(); (function(){ try { var __m = "youtube.com"; var __re = new RegExp('^' + "youtube\\.com" + ', 'i'); if (__m === '*' || __re.test(location.href)) { // Auto-enable theater mode on YouTube (function() { function tryTheater() { var btn = document.querySelector('button[aria-label="Theater mode"], ytd-player #player button[title="Theater mode"]'); if (btn && !btn.classList.contains('activated')) { btn.click(); } } // Try immediately tryTheater(); // Try after navigation (SPA) var lastUrl = location.href; setInterval(function() { if (location.href !== lastUrl) { lastUrl = location.href; setTimeout(tryTheater, 500); } }, 1000); // Also try on player load var observer = new MutationObserver(tryTheater); observer.observe(document.body, { childList: true, subtree: true }); })(); } } catch(__e) { console.warn('[Userscript:YouTube Theater Mode Default]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + ', 'i'); if (__m === '*' || __re.test(location.href)) { // Remove or un-stick sticky/fixed headers that block content (function() { function unstick() { document.querySelectorAll('header, nav, [role="banner"], .header, .navbar, .sticky, .fixed-top, [style*="position: fixed"], [style*="position:sticky"]').forEach(function(el) { if (el.style.position === 'fixed' || el.style.position === 'sticky' || getComputedStyle(el).position === 'fixed' || getComputedStyle(el).position === 'sticky') { el.style.position = 'static'; el.style.top = 'auto'; el.style.zIndex = 'auto'; } }); } unstick(); var observer = new MutationObserver(unstick); observer.observe(document.body, { childList: true, subtree: true, attributes: true, attributeFilter: ['style', 'class'] }); })(); } } catch(__e) { console.warn('[Userscript:Kill Sticky Headers]', __e); } })(); })(); GitHub - ByteGuard-HQ/byteguard-codex: ByteGuard Codex is an application security tool for managing OWASP ASVS-based standards and mapping them to your software projects. · GitHub
Skip to content

Latest commit

History

21 Commits

Folders and files

NameName
Last commit message
Last commit date

Repository files navigation

ByteGuard Codex

ByteGuard Codex is an application security tool for managing OWASP ASVS-based and custom organizational ASVS standards and mapping them to your software projects.

🚧 ByteGuard Codex is currently under active development and not yet production-ready.
API schema, UI and data model may change between releases.

🔎 What is Codex?

ByteGuard Codex helps you:

  • Manage one or more ASVS versions in a single place
  • Construct your own custom orgnizational ASVS version
  • Organize your applications / projects and link them to specific ASVS versions
  • Track which requirements are in scope for each project
  • Record implementation / verification status for each requirement
  • Prepare ASVS-based reports for stakeholders

🧱 Architecture

Codex is a classic SPA + API web application:

  • Backend

    • ASP.NET Core Web API
    • Exposes endpoints for ASVS versions, requirements, and projects
    • Uses a relational database (e.g. SQL Server / PostgreSQL) via EF Core or similar ORM
  • Frontend

    • Vue 3 + Vite
    • TypeScript
    • Pinia for state management
    • Vue Router
    • Sass (SCSS) for styling

Project layout (simplified)

/src
/backend # .NET API
/frontend # Vue 3 webapp

🚀 Getting Started

Prerequisites

Make sure you have:

  • .NET SDK (10.0 or later)
  • Node.js (LTS recommended)
  • A package manager: npm, yarn, or pnpm

At the moment ByteGuard Codex is set up to use a local SQLite database.

1. Clone the repository

git clone https://github.com/ByteGuard-HQ/byteguard-codex.git
cd byteguard-codex

2. Backend setup

From the repo root:

# Build the solutioncd src/backend/
dotnet build
# Update/create the databasecd ByteGuard.Codex.Infrastructure.Sqlite
dotnet ef database update --startup-project ../ByteGuard.Codex.Api/ByteGuard.Codex.Api.csproj
# Start the APIcd ..
dotnet run --project ByteGuard.Codex.Api/ByteGuard.Codex.Api.csproj

The API will be hosted at https://localhost:7258.
API documentation is availavble with Scalar at https://localhost:7258/scalar

3. Frontend setup

From the repo root:

# Install packagescd src/frontend/
npm install
# Run the webapp
npm run dev

The webapp will be hosted at http://localhost:8080.

🤝 Contributing

Contributions are very welcome!

  • Want to become a collaborator? Give me a shout!
  • Have a feature idea? Join the Discord community server.
  • Want to contribute code? Fork the repo, create a feature branch, and open pull request.

Please try to:

  • Follow existing coding style and conventions.
  • Add or update unit tests where relevant.
  • Keep commits reasonably scoped and well-described.

👀 Looking for frontend contributors

ByteGuard Codex is built with Vue 3, TypeScript, Pinia and Sass.

If you enjoy frontend architecture, design systems, or just building clean UIs and want to help shape Codex, I’d love to collaborate.

  • Give me a shout
  • Or join the ByteGuard HQ Discord and say hi

⚠️ Disclaimer

ByteGuard Codex is an independent open-source project maintained by the ByteGuard community.
It is not affiliated with, endorsed by, or sponsored by OWASP or the OWASP Foundation.

OWASP® and OWASP ASVS® are trademarks or registered trademarks of the OWASP Foundation.
Any references to OWASP or OWASP ASVS in this project are for interoperability and informational purposes only.

📄 License

ByteGuard Codex is Copyright © ByteGuard Contributors - Provided under the MIT license.

About

ByteGuard Codex is an application security tool for managing OWASP ASVS-based standards and mapping them to your software projects.

Topics

Resources

Stars

2 stars

Watchers

0 watching

Forks

Releases

Used by

Contributors

Languages