Skip to content

Feature/lab4#496

Open
Rash1d1 wants to merge 12 commits intoinno-devops-labs:mainfrom
Rash1d1:feature/lab4
Open

Feature/lab4#496
Rash1d1 wants to merge 12 commits intoinno-devops-labs:mainfrom
Rash1d1:feature/lab4

Conversation

@Rash1d1
Copy link

@Rash1d1 Rash1d1 commented Mar 2, 2026

  • Task 1 done β€” SBOM Generation with Syft and Trivy
  • Task 2 done β€” SCA with Grype and Trivy
  • Task 3 done β€” Comprehensive Toolchain Comparison

Rashid Badamshin and others added 12 commits February 8, 2026 17:17
- Update threagile-model.secure.yaml with security improvements:
  * Direct to App: protocol http β†’ https
  * Proxy to App: protocol http β†’ https
  * Persistent Storage: encryption none β†’ transparent
- Regenerate secure/ outputs showing correct risk delta
- unencrypted-communication: 2 β†’ 0 (-2 risks)
- unencrypted-asset: 2 β†’ 1 (-1 risk)
- Regenerate with actual baseline risk data (15 risks across 15 categories)
- Include accurate top 5 risks table with severity levels
- Add detailed explanations of each security concern
- Update delta table with correct counts:
  * unencrypted-communication: 2 β†’ 0 (-2)
  * unencrypted-asset: 2 β†’ 1 (-1)
- Explain why infrastructure fixes don't resolve app-level vulnerabilities
- Add architecture comparison and key learning points
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant