You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
A threat model covers argv/environment/config/log/history secrets, filesystem/symlink/permissions, plugins, concurrency, inherited runs, and telemetry.
Trust boundaries, safe defaults, non-goals, and consumer responsibilities are explicit.
A release/security review checklist maps threats to tests and controls.
Parent: #50
Train position: 20 of 22
Phase: P3 — Ecosystem trust
Problem
A lifecycle framework that handles argv, configuration, logs, filesystem state, plugins, and telemetry needs a published security contract.
Acceptance criteria
SECURITY.mddocuments private reporting, supported versions, response expectations, and coordinated disclosure.Dependencies