Google Summer of Code 2026 Summary.md
Google Summer of Code 2026
Over the summer of 2026, I contributed to OWASP/Nest as part of Google Summer of Code. I built a board candidate verification framework, and added board activity tracking with API access. This page is a summary of the problems I worked on and what I shipped.
What is GSoC? Google describes it as:
Google Summer of Code is a global, online program focused on bringing new contributors into open source software development. GSoC Contributors work with an open source organization on a 12+ week programming project under the guidance of mentors.
To understand how it works, read this.
Quick statistics about my project:
- Organization: OWASP
- Project: OWASP/Nest
- Mentors: Arkadii Yakovets, Raja Nagori, Emay, Noland Crane
- Project leaders: Arkadii Yakovets, Kate Golovanova
- Duration: 16 weeks (12 official weeks + 4 extended weeks)
- Pull requests merged: view all PRs
- Project size: Large (~350 hours)
- Proposal:
Context and Problems
Each year, OWASP opens elections for its Global Board of Directors.
According to the OWASP elections page:
The OWASP Foundation Board of Directors currently consists of seven elected volunteers who each serve a two-year term, with a maximum of two terms in any ten-year period. These unpaid volunteers dedicate themselves to the organizational mission, set the strategic direction of the organization, and ensure the financial integrity of the Foundation.
To stand, a candidate has to meet the Board Director's Policy and nominate themselves, setting out their credentials in a biography so the Foundation can validate them.
OWASP Individual Members in good standing are eligible to vote, and voting opens October 15 (tentative).
Nest already had a candidate dashboard at /board//candidates, but it only shows activity from GitHub and Slack.
Everything else a candidate wanted voters to know was limited to their profiles. For example, see Sam Stepanyan's profile.
This is what the dashboard looks like:
There was a second, related problem. The board keeps its own record of meetings, motions, and votes as markdown files in the www-board repository. A person can read them, but nothing can query them and there is no schema.
Work
Goals
My project consisted of two milestones:
- Board Candidate Information Transparency and Fact-Checking
- OWASP Board Activity Standardization and Data Programmatic Access
For the first, I set out to:
- give candidates a profile that showcases their claims
- give candidates a page to submit claims and follow their review status
- require candidates to provide evidence for each claim they submit
- give community reviewers a page to review and annotate those claims
- require a configurable number of reviews before a claim is accepted or rejected
- generate draft claims for candidates automatically with AI from their board election profiles
For the second, I set out to:
- model every kind of board action: meetings, motions, discussions, outcomes, votes
- parse the existing markdown in the www-board repo into those models
- and allow programmatic access through the Nest API and SDK
Implementation
Milestone 1: Board Candidate Information Transparency and Fact-Checking
Candidate Profile
The pages from the OWASP board elections site, for example Sam's, can also be viewed on Nest.
A candidate can highlight some text here and create a claim. They also have the option to create a claim manually if they want. Creating a claim from the profile highlights it on the profile once it gets submitted, approved or rejected.
Related PR: #5371 Add Candidate Page and Claim Highlights Feature
Candidate Claim Dashboard
This dashboard allows candidates to create/edit claims and track their status. The candidate must also upload evidence for each claim as a file or URL.
Initially the claim is created as a draft. To submit it, the candidate needs to attach an evidence.
Once the evidence is attached, the candidate can submit the claim, and it looks like this:
And this is what an approved claim looks like:
Submitted, approved, and rejected claims can be viewed by anyone.
All uploaded files have their EXIF data stripped before storage, to preserve the candidate's privacy.
Related PRs:
- #5006 Add Candidate Claim Management Dashboard
- #4832 Implement GraphQL Queries for Candidate Claim Data
- #4806 Implement GraphQL Mutations for Candidate Claim Data
- #4743 Add Django Models for Candidate Claim Data
- #5057 Add Evidence and Review Management Dashboard
Reviewer Dashboard
All submitted claims appear here. The reviewer can view the claim and its evidence and make a decision: approve or reject. The threshold for required reviews can be configured using the Django admin. Once the reviewer makes a decision, the claim moves to the reviewed phase and, depending on the review threshold, gets approved.
Related PRs:
- #5057 Add Evidence and Review Management Dashboard
- #5069 Update Claim and Evidence GraphQL Queries To Add Reviews
- #5066 Add Django Model for Claim Reviews
Claim Generation
Candidates do not have to create all claims manually. I added a Django command that uses AI to parse their board candidate profiles on the OWASP elections page and create claims automatically. The idea is to run it before each election to give candidates a list of actionable draft claims.
Candidates then only need to review the claims for correctness, attach evidence, and submit. Here is an example output using the --force-preview flag:
> make owasp-generate-board-candidates-claims ARGS="--source-years=2025 --year=2025 --name='Sam Stepanyan' --force-preview"
Generating OWASP board candidates claims
Generating claims for Sam Stepanyan...
Generated Claim:
Name: Active member of OWASP since 2010
Desc: Became an active member of OWASP in 2010.
Generated Claim:
Name: Leader of OWASP London Chapter since 2015
Desc: Led the OWASP London Chapter since 2015.
Generated Claim:
Name: Project Leader for OWASP Nettacker
Desc: Served as Project Leader for the OWASP Nettacker Project.
Generated Claim:
Name: Organised OWASP Global AppSec Europe 2018
Desc: Helped to organise and run the OWASP Global AppSec Europe conference in London in 2018.
Generated Claim:
Name: Chair of the OWASP Chapter Committee since 2020
Desc: Took on the role of Chair of the OWASP Chapter Committee in 2020.
Generated Claim:
Name: Recipient of the OWASP WASPY award in 2023
Desc: Received the OWASP Web Application Security Person of the Year (WASPY) award in 2023.
Generated Claim:
Name: Mentored students in Google Summer of Code
Desc: Served as a mentor in the Google Summer of Code (GSoC) program for OWASP projects.
Generated Claim:
Name: Engaged with UK universities for OWASP
Desc: Conducted guest lectures and presentations at several UK universities to promote OWASP.
Generated Claim:
Name: Represented OWASP at international security conferences
Desc: Regularly represented OWASP at leading security conferences such as Black Hat Europe and AppSec Israel.
Generated Claim:
Name: Active participant in OWASP's outreach
Desc: Staffed the OWASP Booth at several conferences, including NDC Europe.
Generated Claim:
Name: Independent Application Security Consultant
Desc: Works as an independent Application Security Consultant & Architect in the financial services industry in London.
Generated Claim:
Name: Contributed to various OWASP projects
Desc: Contributed to several OWASP projects including OWASP Top 10, OWASP Nettacker, and OWASP ZAP.
Would have saved claims for Sam Stepanyan
Finished processing 1 candidates.
Related PR: #5313 Add Django Comand To Generate Candidate Claims
Milestone 2: OWASP Board Activity Standardization and Data Programmatic Access
Board Activity Models
The board keeps its record as markdown in the www-board repo, readable by a person but not queryable. I added Django models for every kind of board action: meetings, motions, discussions, outcomes, and votes.
Related PR: #5494 Add Django Models to Store Board Activity Data
Board Activity Parsing
I added Django management commands that fetch the markdown from the www-board repo and parse it into the models. The parsers use AI to handle the inconsistent formats across the years.
Related PR: #5503 Add Django Management Commands to Parse Board Activity Data
Board Activity API
With the data in the database, it can be queried like any other Nest data. I added a REST API that exposes board meetings, motions, and votes, so the community can query board activity without reading markdown. The SDKs are generated automatically using Speakeasy: nest-sdk, Python, TypeScript.
Related PR: #5586 Add Board Activity REST API
Pull Requests
A link to all PRs: https://github.com/OWASP/Nest/pulls?q=is%3Apr+label%3Agsoc2026%3Arudransh-shrivastava
| PR | Title | Milestone |
|---|---|---|
| #4743 | Add Django Models for Candidate Claim Data | 1 |
| #4806 | Implement GraphQL Mutations for Candidate Claim Data | 1 |
| #4832 | Implement GraphQL Queries for Candidate Claim Data | 1 |
| #4959 | Candidate Claim Backend Improvements and Changes | 1 |
| #5006 | Add Candidate Claim Management Dashboard | 1 |
| #5057 | Add Evidence and Review Management Dashboard | 1 |
| #5066 | Add Django Model for Claim Reviews | 1 |
| #5069 | Update Claim and Evidence GraphQL Queries To Add Reviews | 1 |
| #5313 | Add Django Comand To Generate Candidate Claims | 1 |
| #5371 | Add Candidate Page and Claim Highlights Feature | 1 |
| #5384 | Board Candidate Transparency Improvements | 1 |
| #5494 | Add Django Models to Store Board Activity Data | 2 |
| #5503 | Add Django Management Commands to Parse Board Activity Data | 2 |
| #5586 | Add Board Activity REST API | 2 |
Acknowledgements
I want to thank Arkadii Yakovets and Kate Golovanova for their guidance, mentorship, and reviews throughout the program.
Loading Sorry, something went wrong. Reload? Sorry, we cannot display this file. Sorry, this file is invalid so it cannot be displayed.