Skip to content

docs(future): finalize FUTURE threat model for H3 AWS scenarios; align FUTURE_* metadata#2855

Merged
pethers merged 5 commits into
mainfrom
copilot/update-future-docs
May 31, 2026
Merged

docs(future): finalize FUTURE threat model for H3 AWS scenarios; align FUTURE_* metadata#2855
pethers merged 5 commits into
mainfrom
copilot/update-future-docs

Conversation

Copy link
Copy Markdown
Contributor

Copilot AI commented May 31, 2026

The FUTURE_*.md set had drifted: three docs lagged behind the v3.x/2026-05-31 cohort, and FUTURE_THREAT_MODEL.md (v1.x) predated the new "Three-Horizon" AWS-serverless vision (Bedrock, Neptune, Aurora, Cognito, SageMaker, multi-region, Nordic/EU federation) introduced across the architecture/data-model/workflow docs. This brings every FUTURE doc into a consistent metadata baseline and rebuilds the threat model to pre-model all H3 attack surface.

Threat model expansion (FUTURE_THREAT_MODEL.md, v1.x → v2.0)

  • Three-horizon framing (H1 static baseline / H2 static-deep 2026–2027 / H3 AWS serverless 2027–2037) with cross-links to all sibling FUTURE docs; existing H2 (F1–F4) and IMF STRIDE content preserved.
  • STRIDE-per-component, crown-jewel diagram, and attack-surface inventory extended with 10 H3 AWS components.
  • 8 new scenarios F5–F12 — Bedrock RAG/KB poisoning, Cognito ATO/IDOR, Lambda/IAM exfiltration, Bedrock Agent excessive agency, SageMaker forecast manipulation, AppSync/API abuse, multi-region failover tampering, Nordic/EU federation integrity.
  • 12 new controls (FUT-011..FUT-022) with remapped STRIDE→Control coverage; new H3 cloud-IAM-compromise attack tree; Cloud-Native Attacker threat agent; OWASP-LLM H3 intensification mapping.
  • Per-horizon quantitative risk matrix and H3 monitoring KPIs (RAG provenance, agent scope, MFA enrolment, IAM drift, replication integrity).
  • System classification updated for the first Cognito authenticated tier — saved searches/alerts as GDPR Art. 9 special-category data with a mandatory pre-launch DPIA.

Metadata consistency

  • FUTURE_SECURITY_ARCHITECTURE.md — v2.0 → 2.1, dates → 2026-05-31, Next Review → 2026-08-31 (badge, Document Version, footer).
  • FUTURE_WORKFLOWS.md — reconciled footer (v3.0/2026-03-27) to match header (v6.0/2026-05-02).

Validation

Code-fence parity balanced across all 9 docs, 5 mermaid blocks intact, and FUT-001..022 ↔ F1..F12 ↔ risk-matrix references confirmed internally consistent.

Copilot AI and others added 2 commits May 31, 2026 16:50
Co-authored-by: pethers <1726836+pethers@users.noreply.github.com>
Co-authored-by: pethers <1726836+pethers@users.noreply.github.com>
Copilot AI changed the title docs: complete refresh of FUTURE_* architecture portfolio (v3.0, three-horizon 2026–2037) docs: refresh FUTURE_* architecture portfolio (v3.0, three-horizon 2026–2037) May 31, 2026
Copilot AI requested a review from pethers May 31, 2026 16:55
@github-actions github-actions Bot added documentation Documentation updates size-xl Extra large change (> 1000 lines) labels May 31, 2026
@github-actions
Copy link
Copy Markdown
Contributor

🏷️ Automatic Labeling Summary

This PR has been automatically labeled based on the files changed and PR metadata.

Applied Labels: documentation,size-xl

Label Categories

  • 🗳️ Content: news, dashboard, visualization, intelligence
  • 💻 Technology: html-css, javascript, workflow, security
  • 📊 Data: cia-data, riksdag-data, data-pipeline, schema
  • 🌍 I18n: i18n, translation, rtl
  • 🔒 ISMS: isms, iso-27001, nist-csf, cis-controls
  • 🏗️ Infrastructure: ci-cd, deployment, performance, monitoring
  • 🔄 Quality: testing, accessibility, documentation, refactor
  • 🤖 AI: agent, skill, agentic-workflow

For more information, see .github/labeler.yml.

@github-actions
Copy link
Copy Markdown
Contributor

🔍 Lighthouse Performance Audit

Category Score Status
Performance 85/100 🟡
Accessibility 95/100 🟢
Best Practices 90/100 🟢
SEO 95/100 🟢

📥 Download full Lighthouse report

Budget Compliance: Performance budgets enforced via budget.json

Co-authored-by: pethers <1726836+pethers@users.noreply.github.com>
Copilot AI changed the title docs: refresh FUTURE_* architecture portfolio (v3.0, three-horizon 2026–2037) FUTURE_MINDMAP v3.1: close SWOT gaps and expand the agentic-AI vision May 31, 2026
@github-actions
Copy link
Copy Markdown
Contributor

🔍 Lighthouse Performance Audit

Category Score Status
Performance 85/100 🟡
Accessibility 95/100 🟢
Best Practices 90/100 🟢
SEO 95/100 🟢

📥 Download full Lighthouse report

Budget Compliance: Performance budgets enforced via budget.json

…n FUTURE_* metadata

Co-authored-by: pethers <1726836+pethers@users.noreply.github.com>
Copilot AI changed the title FUTURE_MINDMAP v3.1: close SWOT gaps and expand the agentic-AI vision docs(future): finalize FUTURE threat model for H3 AWS scenarios; align FUTURE_* metadata May 31, 2026
@github-actions github-actions Bot added security Security improvements isms ISMS compliance changes labels May 31, 2026
@github-actions
Copy link
Copy Markdown
Contributor

🔍 Lighthouse Performance Audit

Category Score Status
Performance 85/100 🟡
Accessibility 95/100 🟢
Best Practices 90/100 🟢
SEO 95/100 🟢

📥 Download full Lighthouse report

Budget Compliance: Performance budgets enforced via budget.json

@pethers pethers marked this pull request as ready for review May 31, 2026 17:56
Copilot AI review requested due to automatic review settings May 31, 2026 17:56
Copy link
Copy Markdown
Contributor

Copilot AI left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

This docs-only PR aligns the future-state documentation portfolio around a three-horizon roadmap and expands the future threat model for AWS/serverless H3 scenarios.

Changes:

  • Reworks future architecture, state, and mindmap docs around H1 static, H2 static-deepening, and H3 AWS serverless evolution.
  • Expands FUTURE_THREAT_MODEL.md with H3 AWS threat scenarios, controls, STRIDE mappings, and risk/KPI coverage.
  • Refreshes metadata/version/footer consistency across future security and workflow docs.

Reviewed changes

Copilot reviewed 8 out of 9 changed files in this pull request and generated 4 comments.

Show a summary per file
File Description
FUTURE_ARCHITECTURE.md Adds three-horizon roadmap framing and H2 static-deepening architecture detail.
FUTURE_THREAT_MODEL.md Expands future threat model with H3 AWS/serverless scenarios, controls, and risk mappings.
FUTURE_STATEDIAGRAM.md Reorganizes future state machines by horizon and adds H3 lifecycle models.
FUTURE_MINDMAP.md Rebuilds future capability mindmaps around horizon, AI, sustainability, and SWOT coverage themes.
FUTURE_SECURITY_ARCHITECTURE.md Updates metadata version/effective/review dates.
FUTURE_WORKFLOWS.md Reconciles stale footer metadata with current header version/date.

Comment thread FUTURE_MINDMAP.md Outdated
root((🦾 Agentic AI<br/>Autonomous Operations))
🟢 v1.x Seed Agents Today
14 gh-aw newsroom workflows
Single-pass analysis aggregate render PR
Comment thread FUTURE_THREAT_MODEL.md Outdated
|----------------|---------|-------------|--------------------|--------------------|
| **CIA Data Pipeline Integration** | H2 | Q2 2026 | Automated nightly fetch of 19 CIA visualization products | External API dependency, data validation, cache poisoning |
| **Advanced AI Content Pipelines** | H2 | Q2-Q3 2026 | Additional agentic workflows (committee reports, motion analysis, week-ahead) | Expanded prompt injection surface, multi-workflow orchestration risks |
| **Real-Time Voting Dashboard** | H2 | Q3 2026 | WebSocket/SSE for live parliamentary voting data | Real-time data manipulation, WebSocket security, connection state attacks |
Comment thread FUTURE_ARCHITECTURE.md Outdated
## 4. 🤖 AI Enhancement Roadmap (Amazon Bedrock)

### 3.1 Phase 1: Enhanced Journalism (2026 Q2-Q3)
### 4.1 Phase 1: Enhanced Journalism (2026 Q2-Q3)
Comment thread FUTURE_THREAT_MODEL.md Outdated
| **Enhanced Chart.js/D3.js Dashboards** | H2 | Q2-Q3 2026 | 5 placeholder dashboards activated (Budget, Voting Patterns, Committee, Regional, Historical) | Dashboard data injection, chart rendering exploits, large dataset DoS |
| **Automated Content Translation** | H2 | Q3 2026 | Machine translation pipeline for 14 languages | Translation manipulation, cultural sensitivity attacks, LLM hallucination in non-English |
| **EU Parliament Cross-Reference** | H2 | Q4 2026 | Integration with European Parliament MCP Server | Cross-platform data integrity, new external API dependency |
| **Bedrock AI Content Engine** | H3 | 2026 Q2–2027 | Step-Functions-orchestrated Lambda + Bedrock (Claude Opus, Nova Premier, Polly) article/image/audio generation | Managed-LLM prompt injection, insecure output handling, excessive agency, model supply chain |
… review

- FUTURE_MINDMAP.md: Change "Single-pass" to "Multi-pass" to match
  gh-aw prompt contract (minimum two complete passes)
- FUTURE_THREAT_MODEL.md: Move Real-Time Voting Dashboard from H2 to H3
  (WebSocket/SSE requires Kinesis streaming backend, not static)
- FUTURE_THREAT_MODEL.md: Align Bedrock/SageMaker/Neptune dates to H3
  window (2028+) instead of conflicting 2026-2027
- FUTURE_ARCHITECTURE.md: Shift AI Enhancement Roadmap phases to H3
  timeframe (2028+) to match horizon boundary definitions

Co-authored-by: pethers <1726836+pethers@users.noreply.github.com>
@github-actions
Copy link
Copy Markdown
Contributor

🔍 Lighthouse Performance Audit

Category Score Status
Performance 85/100 🟡
Accessibility 95/100 🟢
Best Practices 90/100 🟢
SEO 95/100 🟢

📥 Download full Lighthouse report

Budget Compliance: Performance budgets enforced via budget.json

@pethers pethers merged commit 54715ed into main May 31, 2026
12 checks passed
@pethers pethers deleted the copilot/update-future-docs branch May 31, 2026 18:39
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

documentation Documentation updates isms ISMS compliance changes security Security improvements size-xl Extra large change (> 1000 lines)

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants