ossf / wg-securing-software-repos

OpenSSF Working Group on Securing Software Repositories
Other
84 stars 15 forks source link

Homebrew: add threat modeling #25

Closed woodruffw closed 1 year ago

woodruffw commented 1 year ago

This adds models for 4 attacker scenarios, including their postures, mitigations, and outcomes.

CC @di and @haydentherapper for review 🙂

di commented 1 year ago

@woodruffw OK to merge here?

woodruffw commented 1 year ago

@woodruffw OK to merge here?

OK by me, I think @trishankatdatadog may have some feedback coming. But if you want to merge first, I can address his feedback in a follow-up.

trishankatdatadog commented 1 year ago

@woodruffw OK to merge here?

OK by me, I think @trishankatdatadog may have some feedback coming. But if you want to merge first, I can address his feedback in a follow-up.

LGTM, thanks, and yes, we can address other feedback later

woodruffw commented 1 year ago

Good to go now, @di!

trevrosen commented 1 year ago

Love it - thanks, @woodruffw!