Skip to content

Lab 2 — Threat Modeling with Threagile#390

Open
andiazdi wants to merge 3 commits intoinno-devops-labs:mainfrom
andiazdi:feature/lab2
Open

Lab 2 — Threat Modeling with Threagile#390
andiazdi wants to merge 3 commits intoinno-devops-labs:mainfrom
andiazdi:feature/lab2

Conversation

@andiazdi
Copy link

Goal

Model OWASP Juice Shop (bkimminich/juice-shop:v19.0.0) deployment and generate an automation-first threat model with Threagile.

Changes

Added:

  • labs/lab2/baseline with security analysis of Juice Shop
  • labs/lab2/baseline with security analysis of secured Juice Shop

Testing

Running secured Juice Shop showed that updated version become more secure than inital version

Artifacts & Screenshots

labs/lab2/baseline/data-asset-diagram.png
labs/lab2/baseline/data-flow-diagram.png
labs/lab2/secure/data-asset-diagram.png
labs/lab2/secure/data-flow-diagram.png

Checklist

  • PR title is clear

  • Documentation has been updated

  • No secrets or large temporary files included

  • Task 1 done — Threagile baseline model + risk analysis

  • Task 2 done — HTTPS variant + risk comparison

@andiazdi andiazdi changed the title Feature/lab2 Lab 2 - Threat Modeling with Threagile Feb 16, 2026
@andiazdi andiazdi changed the title Lab 2 - Threat Modeling with Threagile Lab 2 — Threat Modeling with Threagile Feb 16, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant