Skip to content

Threat model + security hardening #70

Description

@AKogut

Context

A platform that ingests from CI and stores failure data is a target. Model the threats and close the gaps.

Scope

  • Threat model (STRIDE) of ingestion, tokens, dashboard, AI path
  • Ingest-token rotation + scoping + leak detection
  • Secret scanning in CI + dependency audit (SCA) + SBOM
  • Rate-limit / abuse protection on public endpoints
  • Security policy + responsible disclosure

Acceptance criteria

  • Documented threat model with mitigations tracked; automated dep + secret scanning in CI

Metadata

Metadata

Assignees

No one assigned

    Labels

    Projects

    Status
    Todo

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions