Skip to content

Commit

Permalink
moved TODO about a vs b
Browse files Browse the repository at this point in the history
Signed-off-by: Mark Lodato <lodato@google.com>
  • Loading branch information
MarkLodato committed Jun 5, 2024
1 parent 5fadb0f commit 8a0d8f8
Showing 1 changed file with 4 additions and 2 deletions.
6 changes: 4 additions & 2 deletions docs/spec/v1.1/threats.md
Original file line number Diff line number Diff line change
Expand Up @@ -77,6 +77,10 @@ consumer's trust.
Threats in this category likely *cannot* be mitigated through controls placed
during the authoring/reviewing process, in contrast with (B).

**TODO:** The difference between (A) and (B) is still a bit fuzzy, which would
be nice to resolve. For example, compromised developer credentials - is that (A)
or (B)?

<details><summary>Software producer intentionally submits bad code</summary>

*Threat:* Software producer intentionally submits "bad" code, following all
Expand All @@ -103,8 +107,6 @@ Threats in this category *can* be mitigated by code review or some other
controls during the authoring/reviewing process, at least in theory. Contrast
this with (A), where such controls are likely ineffective.

**TODO:** Is the split between (A) and (B) clear and valuable?

#### (B1) Submit change without review

<details><summary>Directly submit without review</summary>
Expand Down

0 comments on commit 8a0d8f8

Please sign in to comment.