Update threat model scope to include release automation #150
Labels
No project
No assignees
1 participant
Notifications
Due date
No due date set.
Dependencies
No dependencies set.
Reference
Slipstream/auto_review#150
Loading…
Add table
Add a link
Reference in a new issue
No description provided.
Delete branch "%!s()"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
PR #126 review noted that the threat model scope should reflect the release process.
docs/THREAT-MODEL.mdalready contains detailed release automation threats and assets, including binary release artifacts,RELEASE_SIGNING_KEY, checksum signing, release PATs, and the aarch64 remote builder. However, the## Scopeintroduction still says the document covers only the deployed self-hosted review bot.Update the scope paragraph so it explicitly includes release preparation/publishing automation and binary artifact integrity.
Source feedback: PR #126 comment 7475.