notaryproject / specifications

Cross tooling and interoperability specifications
https://notaryproject.dev/
Apache License 2.0
159 stars 44 forks source link

Update Threat Model with Blob Signing scenarios #296

Open rgnote opened 9 months ago

rgnote commented 9 months ago

One of the scenario was discussed in https://github.com/notaryproject/specifications/pull/283#discussion_r1479399825 We need to update the threat model to call out that a signed blob artifact can be transformed as a signed OCI image and an adversary can lower the security of the hashing algorithm selected notation.