Skip to content

Upstream work

Where our code went. Every line links upstream.

Not a portfolio of things we built for ourselves. These are contributions into projects other people maintain, which is the only kind that has to survive somebody else's review.

Running now

Build day projects. Turn up and pick one.

These are the projects people are actually working on in build days. Every card names the person to talk to and links an issue sized for somebody who has never done this before.

Nothing listed for this cycle yet.

A card only goes up once its good-first-issue link resolves to genuinely open, genuinely beginner-sized issues. A promise that leads to an empty issue list is worse than an empty section.

Ours, all year

The repositories the club owns. Including this website.

Longer-lived than a build-day project and maintained by the club rather than by one person. If you want a first merged pull request with the shortest possible feedback loop, start here — the maintainer reviewing it is somebody you can find in the lab.

In the wild

Merged into somebody else's repo. Which is the only claim that counts.

1 org · 1 member

Nobody here can award these to themselves. A maintainer with no reason to be kind to us read the diff and agreed to it. Every card links the repository — open it and check the commit history.

Contributor rank

#2of 40

By commits on the default branch of OWASP/OpenCRE

Pull requests merged

46 of 74

62% merged. The rest were closed or superseded, which is a normal ratio and the reason we publish it rather than rounding it up.

Opened
74
Language
Python
OWASP's Common Requirement Enumeration — the open catalogue that maps security standards to each other. Counted from the public repository — open the link and check.

Contributor counts and merge ratios were read from the GitHub API on 2026-07-29. They move — open the repository if you want today's number.

Your turn

Want your name in this list? It starts with one small pull request.

Bring a laptop and a GitHub account. You do not need to be good yet — a first contribution is mostly about learning how the process works.