Policies / Operational Policies

Conflict Resolution

Conflict Resolution

This document aims to outline the process and expectations to be followed when raising a concern or conflict within OWASP. This document strives to create a usable system where concerns can be voiced, responded to, and resolved. In addition, this process is intended to ensure the system of discussion does not overwhelm individuals who are not interested or necessary in the conflict discussion.

Assume Positive Intent First

  1. Information and intent can be lost within electronic communication.
  2. Before raising any issue it is strongly recommended to consult with the specific individual(s) related to the issue and openly clarify the issue.
  3. After clarifying the situation if a conflict is still present then the situation should be addressed.

Raising a Conflict

To clarify OWASP policy and receive other opinions on the situation the issue should be directed to the OWASP Compliance Committee

Use of Leaders List

  1. It is appropriate, if necessary, to send a single email to the leaders list to advise them of the situation and ask for involvement/comments within the governance thread.
  2. However, the leaders list is specifically NOT to be used for discussion of the conflict. The leaders list contains many people, many of whom will not be related to the specific incident. Conflict related threads on the leaders list will be refocused to the Governance list.
Corporate Supporters
OWASP Logo
OWASP is a nonprofit foundation improving software security through open-source projects, global communities, and education. All resources are free and open to everyone.
OWASP, the OWASP logo, and Global AppSec are registered trademarks and AppSec Days, AppSec California, AppSec Cali, SnowFROC, OWASP Boston Application Security Conference, and LASCON are trademarks of the OWASP Foundation, Inc.
© 2026, OWASP Foundation Inc. All rights reserved.