Skip to content

Feature/lab2#378

Open
alsstarikova wants to merge 3 commits intoinno-devops-labs:mainfrom
alsstarikova:feature/lab2
Open

Feature/lab2#378
alsstarikova wants to merge 3 commits intoinno-devops-labs:mainfrom
alsstarikova:feature/lab2

Conversation

@alsstarikova
Copy link

Goal

Create an automation-first threat model for OWASP Juice Shop (v19.0.0) using Threagile, analyze baseline security risks, and demonstrate how HTTPS and encryption controls impact the threat landscape.

Changes

  • Added labs/submission2.md with comprehensive Threagile threat model analysis
  • Created baseline Threagile model and generated complete threat modeling artifacts (PDF report, diagrams, risk exports)
  • Created secure model variant with HTTPS and encryption controls (threagile-model.secure.yaml)
  • Generated risk comparison between baseline and secure variants using jq analysis
  • Committed full Threagile output artifacts in labs/lab2/baseline/ and labs/lab2/secure/ directories

Testing

  • Verified baseline model generates complete risk reports with diagrams at labs/lab2/baseline/
  • Confirmed secure model variant successfully processes with Threagile at labs/lab2/secure/
  • Validated PDF reports open correctly and diagrams render properly
  • Executed jq risk comparison command and verified category delta calculations

Artifacts & Screenshots

Screenshots, API outputs, and other evidence demonstrating completion attached in labs/submission2.md

Pre-submission Checklist

  • PR title is clear and descriptive
  • Documentation updated
  • No secrets, credentials, or large temp files committed
  • Task 1 done — Threagile baseline model + risk analysis
  • Task 2 done — HTTPS variant + risk comparison

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant