Skip to content

Update Threat Model with Blob Signing scenarios #296

@rgnote

Description

@rgnote

One of the scenario was discussed in #283 (comment)
We need to update the threat model to call out that a signed blob artifact can be transformed as a signed OCI image and an adversary can lower the security of the hashing algorithm selected notation.

Metadata

Metadata

Assignees

Labels

No labels
No labels

Type

No type

Projects

No projects

Relationships

None yet

Development

No branches or pull requests

Issue actions