Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

content: draft: Add mitigation for malicious source platform admin. #1188

Open
wants to merge 1 commit into
base: main
Choose a base branch
from

Conversation

TomHennen
Copy link
Contributor

Add mitigation for malicious source platform admin.

We didn't have any guidance for this threat. There are a number of ways we may be able to address this in the future via the SLSA Source Track and/or tools like gittuf. However, SLSA doesn't currently address them. This entire section is already labeled as not being handled by SLSA but does still include other mitigations.

I'm using the same language we have for "Compromise build platform admin", which seems like the same sort of threat, and should work 'fine' until we have something better.

Filed #1187 to track

Fixes #1179.

Using the same language we have for "Compromise build platform admin".

Filed slsa-framework#1187 to track

Fixes slsa-framework#1179.

Signed-off-by: Tom Hennen <[email protected]>
Copy link

netlify bot commented Oct 14, 2024

Deploy Preview for slsa ready!

Name Link
🔨 Latest commit ce02c32
🔍 Latest deploy log https://app.netlify.com/sites/slsa/deploys/670d5d907e784a0008a2e9ff
😎 Deploy Preview https://deploy-preview-1188--slsa.netlify.app
📱 Preview on mobile
Toggle QR Code...

QR Code

Use your smartphone camera to open QR code link.

To edit notification comments on pull requests, go to your Netlify site configuration.

@TomHennen TomHennen changed the title content: Add mitigation for malicious source platform admin. content: draft: Add mitigation for malicious source platform admin. Oct 14, 2024
@TomHennen TomHennen requested a review from lehors October 14, 2024 20:25
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
Status: 🆕 New
Development

Successfully merging this pull request may close these issues.

TODO: Need mitigation description for "Platform admin abuses privileges" threat
1 participant