Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Implement Test Case for MSTG-ARCH-1 #1994

Closed
cpholguera opened this issue Dec 1, 2021 · 1 comment
Closed

Implement Test Case for MSTG-ARCH-1 #1994

cpholguera opened this issue Dec 1, 2021 · 1 comment

Comments

@cpholguera
Copy link
Collaborator

#1988 removes this section that doesn't belong there since it's not about privacy or user education on that regard. It's rather about complying to copyright laws stating that the user must be informed regarding 3rd party libraries, their licences, etc.

This could be re-used for MSTG-ARCH-1 (not yet covered in the MSTG).

### Other Information You Have to Share (OSS Information)

Given copyright laws, app developers must make sure that they inform the user on any third party libraries that are used in the app. For each third party library you should consult the license to see if certain information (such as copyright, modifications, original author, ...) should be presented to the user. For this, it is best to request legal advice from a specialist. An example can be found at [a blog post from Big Nerd Ranch](https://www.bignerdranch.com/blog/open-source-licenses-and-android/ "Example on license overview"). Additionally, the website [TL;DR - Legal](https://tldrlegal.com/ "TL;DR - Legal") can help you in figuring out what is necessary for each license.

> Modern software is assembled using third-party and open source components. They are glued together in complex and unique ways and integrated with original code to achieve the desired functionality. An accurate inventory of all components enables organizations to identify risk, allows for greater transparency, and enables rapid impact analysis.
>
> Source: The OWASP CycloneDX project

You can refer to the [OWASP CycloneDX project](https://owasp.org/www-project-cyclonedx/) for more information.
@cpholguera
Copy link
Collaborator Author

MASVS-ARCH removed for MASVS 2.0

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

1 participant