Skip to content

Feature/lab2#1046

Open
zeitrin wants to merge 2 commits into
inno-devops-labs:mainfrom
zeitrin:feature/lab2
Open

Feature/lab2#1046
zeitrin wants to merge 2 commits into
inno-devops-labs:mainfrom
zeitrin:feature/lab2

Conversation

@zeitrin

@zeitrin zeitrin commented Jun 12, 2026

Copy link
Copy Markdown

Goal

Generate a STRIDE threat model of Juice Shop with Threagile, produce a secure variant, and diff the risk reports.

Changes

  • Added labs/lab2/threagile-model-secure.yaml
  • Added submissions/lab2.md (risk tables + STRIDE mapping + diff analysis)

Testing

  • Ran Threagile v0.9.1 on baseline and secure models
  • Baseline: 23 risks → Secure: 18 risks (−5)

Artifacts & Screenshots

  • Analysis: submissions/lab2.md

  • Task 1 — Baseline risk table + top-5 with STRIDE mapping
  • Task 2 — Secure variant + risk diff table
  • Bonus — Auth-flow model + 3 auth-specific risks

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant