Skip to content

feat(lab2): Threagile threat model and secure variant#1042

Open
karmihkr wants to merge 2 commits into
inno-devops-labs:mainfrom
karmihkr:feature/lab2
Open

feat(lab2): Threagile threat model and secure variant#1042
karmihkr wants to merge 2 commits into
inno-devops-labs:mainfrom
karmihkr:feature/lab2

Conversation

@karmihkr

Copy link
Copy Markdown

Goal

Generate a STRIDE-based threat model of OWASP Juice Shop using Threagile and compare it with a hardened secure variant.

Changes

  • Added submissions/lab2.md
  • Generated baseline Threagile threat model
  • Added STRIDE mapping and trust-boundary analysis
  • Created threagile-model-secure.yaml
  • Compared baseline and secure-variant risk counts

Completed Tasks

  • Task 1 — Baseline risk table + top-5 risks + STRIDE mapping
  • Task 2 — Secure variant + risk diff table
  • Bonus — Auth flow model

Artifacts

  • submissions/lab2.md
  • labs/lab2/threagile-model-secure.yaml

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant