Google Summer of Code 2026 Summary.md

Google Summer of Code 2026

Over the summer of 2026, I contributed to OWASP/Nest as part of Google Summer of Code. I built a board candidate verification framework, and added board activity tracking with API access. This page is a summary of the problems I worked on and what I shipped.

What is GSoC? Google describes it as:

Google Summer of Code is a global, online program focused on bringing new contributors into open source software development. GSoC Contributors work with an open source organization on a 12+ week programming project under the guidance of mentors.

To understand how it works, read this.

Quick statistics about my project:

Context and Problems

Each year, OWASP opens elections for its Global Board of Directors.

According to the OWASP elections page:

The OWASP Foundation Board of Directors currently consists of seven elected volunteers who each serve a two-year term, with a maximum of two terms in any ten-year period. These unpaid volunteers dedicate themselves to the organizational mission, set the strategic direction of the organization, and ensure the financial integrity of the Foundation.

To stand, a candidate has to meet the Board Director's Policy and nominate themselves, setting out their credentials in a biography so the Foundation can validate them.

OWASP Individual Members in good standing are eligible to vote, and voting opens October 15 (tentative).

Nest already had a candidate dashboard at /board//candidates, but it only shows activity from GitHub and Slack.

Everything else a candidate wanted voters to know was limited to their profiles. For example, see Sam Stepanyan's profile.

This is what the dashboard looks like:

There was a second, related problem. The board keeps its own record of meetings, motions, and votes as markdown files in the www-board repository. A person can read them, but nothing can query them and there is no schema.

Work

Goals

My project consisted of two milestones:

  1. Board Candidate Information Transparency and Fact-Checking
  2. OWASP Board Activity Standardization and Data Programmatic Access

For the first, I set out to:

  • give candidates a profile that showcases their claims
  • give candidates a page to submit claims and follow their review status
  • require candidates to provide evidence for each claim they submit
  • give community reviewers a page to review and annotate those claims
  • require a configurable number of reviews before a claim is accepted or rejected
  • generate draft claims for candidates automatically with AI from their board election profiles

For the second, I set out to:

  • model every kind of board action: meetings, motions, discussions, outcomes, votes
  • parse the existing markdown in the www-board repo into those models
  • and allow programmatic access through the Nest API and SDK

Implementation

Milestone 1: Board Candidate Information Transparency and Fact-Checking

Candidate Profile

The pages from the OWASP board elections site, for example Sam's, can also be viewed on Nest.

A candidate can highlight some text here and create a claim. They also have the option to create a claim manually if they want. Creating a claim from the profile highlights it on the profile once it gets submitted, approved or rejected.

Related PR: #5371 Add Candidate Page and Claim Highlights Feature

Candidate Claim Dashboard

This dashboard allows candidates to create/edit claims and track their status. The candidate must also upload evidence for each claim as a file or URL.

Initially the claim is created as a draft. To submit it, the candidate needs to attach an evidence.

Once the evidence is attached, the candidate can submit the claim, and it looks like this:

And this is what an approved claim looks like:

Submitted, approved, and rejected claims can be viewed by anyone.

All uploaded files have their EXIF data stripped before storage, to preserve the candidate's privacy.

Related PRs:

Reviewer Dashboard

All submitted claims appear here. The reviewer can view the claim and its evidence and make a decision: approve or reject. The threshold for required reviews can be configured using the Django admin. Once the reviewer makes a decision, the claim moves to the reviewed phase and, depending on the review threshold, gets approved.

Related PRs:

Claim Generation

Candidates do not have to create all claims manually. I added a Django command that uses AI to parse their board candidate profiles on the OWASP elections page and create claims automatically. The idea is to run it before each election to give candidates a list of actionable draft claims.

Candidates then only need to review the claims for correctness, attach evidence, and submit. Here is an example output using the --force-preview flag:

> make owasp-generate-board-candidates-claims ARGS="--source-years=2025 --year=2025 --name='Sam Stepanyan' --force-preview"

Generating OWASP board candidates claims
Generating claims for Sam Stepanyan...
Generated Claim:
  Name: Active member of OWASP since 2010
  Desc: Became an active member of OWASP in 2010.
Generated Claim:
  Name: Leader of OWASP London Chapter since 2015
  Desc: Led the OWASP London Chapter since 2015.
Generated Claim:
  Name: Project Leader for OWASP Nettacker
  Desc: Served as Project Leader for the OWASP Nettacker Project.
Generated Claim:
  Name: Organised OWASP Global AppSec Europe 2018
  Desc: Helped to organise and run the OWASP Global AppSec Europe conference in London in 2018.
Generated Claim:
  Name: Chair of the OWASP Chapter Committee since 2020
  Desc: Took on the role of Chair of the OWASP Chapter Committee in 2020.
Generated Claim:
  Name: Recipient of the OWASP WASPY award in 2023
  Desc: Received the OWASP Web Application Security Person of the Year (WASPY) award in 2023.
Generated Claim:
  Name: Mentored students in Google Summer of Code
  Desc: Served as a mentor in the Google Summer of Code (GSoC) program for OWASP projects.
Generated Claim:
  Name: Engaged with UK universities for OWASP
  Desc: Conducted guest lectures and presentations at several UK universities to promote OWASP.
Generated Claim:
  Name: Represented OWASP at international security conferences
  Desc: Regularly represented OWASP at leading security conferences such as Black Hat Europe and AppSec Israel.
Generated Claim:
  Name: Active participant in OWASP's outreach
  Desc: Staffed the OWASP Booth at several conferences, including NDC Europe.
Generated Claim:
  Name: Independent Application Security Consultant
  Desc: Works as an independent Application Security Consultant & Architect in the financial services industry in London.
Generated Claim:
  Name: Contributed to various OWASP projects
  Desc: Contributed to several OWASP projects including OWASP Top 10, OWASP Nettacker, and OWASP ZAP.
Would have saved claims for Sam Stepanyan
Finished processing 1 candidates.

Related PR: #5313 Add Django Comand To Generate Candidate Claims

Milestone 2: OWASP Board Activity Standardization and Data Programmatic Access

Board Activity Models

The board keeps its record as markdown in the www-board repo, readable by a person but not queryable. I added Django models for every kind of board action: meetings, motions, discussions, outcomes, and votes.

Related PR: #5494 Add Django Models to Store Board Activity Data

Board Activity Parsing

I added Django management commands that fetch the markdown from the www-board repo and parse it into the models. The parsers use AI to handle the inconsistent formats across the years.

Related PR: #5503 Add Django Management Commands to Parse Board Activity Data

Board Activity API

With the data in the database, it can be queried like any other Nest data. I added a REST API that exposes board meetings, motions, and votes, so the community can query board activity without reading markdown. The SDKs are generated automatically using Speakeasy: nest-sdk, Python, TypeScript.

Related PR: #5586 Add Board Activity REST API

Pull Requests

A link to all PRs: https://github.com/OWASP/Nest/pulls?q=is%3Apr+label%3Agsoc2026%3Arudransh-shrivastava

PR Title Milestone
#4743 Add Django Models for Candidate Claim Data 1
#4806 Implement GraphQL Mutations for Candidate Claim Data 1
#4832 Implement GraphQL Queries for Candidate Claim Data 1
#4959 Candidate Claim Backend Improvements and Changes 1
#5006 Add Candidate Claim Management Dashboard 1
#5057 Add Evidence and Review Management Dashboard 1
#5066 Add Django Model for Claim Reviews 1
#5069 Update Claim and Evidence GraphQL Queries To Add Reviews 1
#5313 Add Django Comand To Generate Candidate Claims 1
#5371 Add Candidate Page and Claim Highlights Feature 1
#5384 Board Candidate Transparency Improvements 1
#5494 Add Django Models to Store Board Activity Data 2
#5503 Add Django Management Commands to Parse Board Activity Data 2
#5586 Add Board Activity REST API 2

Acknowledgements

I want to thank Arkadii Yakovets and Kate Golovanova for their guidance, mentorship, and reviews throughout the program.

Loading Sorry, something went wrong. Reload? Sorry, we cannot display this file. Sorry, this file is invalid so it cannot be displayed.

添加评论
点赞收藏
点踩分享查看原文
评论
?
参与讨论