oss_threatmodel threat model for a free software developer Links: https://wiki.debian.org/UntrustedDebs https://reproducible-builds.org/