Skip to content

Add STRIDE threat model to security docs#9562

Open
aclark4life wants to merge 6 commits intomainfrom
stride
Open

Add STRIDE threat model to security docs#9562
aclark4life wants to merge 6 commits intomainfrom
stride

Conversation

@aclark4life
Copy link
Copy Markdown
Member

Changes proposed in this pull request:

  • Update .github/SECURITY.md with threat model summary and link to handbook
  • Add docs/handbook/security.rst with full STRIDE analysis (14 threats across Spoofing, Tampering, Repudiation, Information Disclosure, Denial of Service, and Elevation of Privilege categories)
  • Add prioritised mitigation recommendations
  • Link security.rst into the handbook toctree

aclark4life and others added 2 commits April 14, 2026 12:13
- Update .github/SECURITY.md with threat model summary and link to handbook
- Add docs/handbook/security.rst with full STRIDE analysis (14 threats
  across Spoofing, Tampering, Repudiation, Information Disclosure,
  Denial of Service, and Elevation of Privilege categories)
- Add prioritised mitigation recommendations
- Link security.rst into the handbook toctree

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
@aclark4life aclark4life requested a review from Copilot April 14, 2026 23:57
Copy link
Copy Markdown

Copilot AI left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Note

Copilot was unable to run its full agentic suite in this review.

Adds a STRIDE-based threat model to the Pillow security documentation and links it from the handbook and GitHub Security Policy to help downstream integrators assess and mitigate risks when processing untrusted images.

Changes:

  • Introduces a new docs/handbook/security.rst page with STRIDE threats and prioritized mitigations.
  • Adds the security page to the handbook toctree.
  • Updates .github/SECURITY.md with a threat model summary and link to the handbook page.

Reviewed changes

Copilot reviewed 3 out of 3 changed files in this pull request and generated 2 comments.

File Description
docs/handbook/security.rst New STRIDE threat model and prioritized mitigation recommendations.
docs/handbook/index.rst Links the new security page into the handbook navigation.
.github/SECURITY.md Adds a threat model summary and links to the full handbook page.

💡 Add Copilot custom instructions for smarter, more guided reviews. Learn how to get started.

Comment thread docs/handbook/security.rst Outdated
Comment thread docs/handbook/security.rst Outdated
Comment thread .github/SECURITY.md Outdated
Comment thread .github/SECURITY.md Outdated
Comment thread docs/handbook/security.rst Outdated
Comment thread docs/handbook/security.rst Outdated
Comment thread docs/handbook/security.rst Outdated
Comment thread docs/handbook/security.rst Outdated
Comment thread docs/handbook/security.rst Outdated
aclark4life and others added 2 commits April 15, 2026 13:07
Co-authored-by: Copilot <175728472+Copilot@users.noreply.github.com>
- docs/handbook/security.rst
- .github/SECURITY.md

Co-authored-by: Andrew Murray <3112309+radarhere@users.noreply.github.com>
Comment thread docs/handbook/security.rst Outdated
@aclark4life aclark4life marked this pull request as ready for review April 16, 2026 10:48
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants