Update threat model scope to include release automation #150

Closed
opened 2026-05-07 15:06:54 -07:00 by jwilger · 0 comments
Owner

PR #126 review noted that the threat model scope should reflect the release process.

docs/THREAT-MODEL.md already contains detailed release automation threats and assets, including binary release artifacts, RELEASE_SIGNING_KEY, checksum signing, release PATs, and the aarch64 remote builder. However, the ## Scope introduction still says the document covers only the deployed self-hosted review bot.

Update the scope paragraph so it explicitly includes release preparation/publishing automation and binary artifact integrity.

Source feedback: PR #126 comment 7475.

PR #126 review noted that the threat model scope should reflect the release process. `docs/THREAT-MODEL.md` already contains detailed release automation threats and assets, including binary release artifacts, `RELEASE_SIGNING_KEY`, checksum signing, release PATs, and the aarch64 remote builder. However, the `## Scope` introduction still says the document covers only the deployed self-hosted review bot. Update the scope paragraph so it explicitly includes release preparation/publishing automation and binary artifact integrity. Source feedback: PR #126 comment 7475.
jwilger added this to the 1.0 milestone 2026-05-08 11:43:27 -07:00
jwilger added this to the (deleted) project 2026-05-10 07:35:54 -07:00
Sign in to join this conversation.
No milestone
No project
No assignees
1 participant
Notifications
Due date
The due date is invalid or out of range. Please use the format "yyyy-mm-dd".

No due date set.

Dependencies

No dependencies set.

Reference
Slipstream/auto_review#150
No description provided.