The OWASP Community Recognition Tool (CRT) is an automated system that verifies GitHub contributions and issues verifiable, tier-based credentials (Bronze, Silver, Gold) to valued OWASP community members.
The OWASP Foundation thrives on the dedication of its global community of volunteers. From code contributions and documentation to chapter leadership and event organization, these efforts are the backbone of our mission.
The OWASP Community Recognition Tool aims to create a streamlined, transparent, and automated system to formally acknowledge these valuable contributions.
Verify: To provide a clear, verifiable link between a credential and the contributions it represents.
Standardize: To create a consistent and fair process for recognizing community efforts.
Empower: To give contributors a tangible and shareable acknowledgment of their work.
Authenticate: A contributor visits crt.owasp.org and authenticates via the official GitHub OAuth application.
Edge Validation: A Cloudflare Worker at the edge intercepts the request, verifies the secure session, and enforces a strict rate limit.
Analyze & Score: A GitHub Action uses the GitHub GraphQL API to scan the requester's direct commits and merged/co-authored pull requests across public OWASP repositories. Contributions are weighted, normalized, and checked against dynamically derived thresholds to assign a Gold, Silver, or Bronze tier.
Issue: The resulting verified data is committed to a data branch. The contributor's certificate is instantly generated.
To recognize different levels of commitment, we issue three distinct tiers of certificates:
Tier 1 (Bronze)
Tier 2 (Silver)
Tier 3 (Gold)