Operationalizing OWASP ASVS Level 1 in CI/CD: Reproducible Security Testing Using One Open Source and One Industrial Case Study
Adeel Ahmad · Tampere University Institutional Repository (Tampere University) · 2025
Modern web applications are increasingly dependent on cloud services, containerized deployments, and large ecosystems of third-party libraries. While significant gains in scalability and development efficiency have been realized, the utilization of such technologies contributes to a broader attack surface. The increased scope brings with it certain security risks, such as injection flaws, Cross-Site Scripting (XSS), configuration weaknesses, and software supply chain vulnerabilities. This thesis presents methods to mitigate these challenges by operationalizing the OWASP Application Security Verification Standard (ASVS) Level 1 as a reproducible security assurance layer within Continuous Integration and Continuous Delivery (CI/CD) pipelines. To address this need, a light DevSecOps pipeline was designed that orchestrates several open source security scanners covering SCA, SAST, DAST, and secret detection. The selected tools are OWASP Dependency-Check, Trivy, npm-audit, Semgrep, SonarQube, OWASP ZAP Baseline, and Gitleaks. Their outputs were automatically transformed into a common format and then mapped to the respective ASVS Level 1 verification requirements, thus allowing systematic, repeatable, and verifiable security checks. This pipeline forms the security verification framework developed in this work. The developed framework has been evaluated on two targets: an open source project called Flowise and a major Industrial Case Study (ICS). The assessment covered six ASVS Level 1 verification requirements focused on dependency management, configuration hardening, security headers, encoding and sanitization, business-logic, and secret management. Noise reduction filters reduced non-actionable Semgrep alerts originating from generic rules by 73.6%, while preserving all high severity findings, thereby improving both result precision and reviewer efficiency. The evaluation also showed measurable improvements: a critical dependency vulnerability (sha.js, CVSS 9.1) was found and successfully remediated on the open source target. The pipeline runtimes remained practical for CI/CD use: Dependency-Check completed in 78 seconds, Semgrep took 111 seconds, Trivy-FS completed in 47 seconds, ZAP on Flowise took 56 seconds; all tools took less than 30 seconds on ICS. These results suggest that the pipeline produces repeatable ASVS aligned verification outputs reliably while maintaining confidentiality. In all, this thesis provides a practical, reproducible methodology for the automation of OWASP ASVS Level 1 verification within the CI/CD environment. The proposed pipeline allows for continuous security assurance with just modest tooling and also forms the basis for further development in the future toward higher assurance levels.