Skip to content

Feature/lab2#357

Open
ArthurBabkin wants to merge 5 commits intoinno-devops-labs:mainfrom
ArthurBabkin:feature/lab2
Open

Feature/lab2#357
ArthurBabkin wants to merge 5 commits intoinno-devops-labs:mainfrom
ArthurBabkin:feature/lab2

Conversation

@ArthurBabkin
Copy link

Goal

Model the local OWASP Juice Shop deployment with Threagile, analyze baseline risks, and show how HTTPS + encrypted storage change the risk landscape.

Changes

  • Added Threagile baseline model outputs for Lab 2 under labs/lab2/baseline/ (report, diagrams, risks, stats, technical assets).
  • Created secure model variant labs/lab2/threagile-model.secure.yaml with HTTPS links and encrypted persistent storage.
  • Added secure Threagile outputs under labs/lab2/secure/.
  • Documented risk analysis and risk category deltas in labs/submission2.md.

Testing

  • Ran Threagile for the baseline model and verified baseline/report.pdf and diagrams render correctly.
  • Ran Threagile for the secure model and verified secure/report.pdf and diagrams render correctly.
  • Used the provided jq script to compare baseline/risks.json vs secure/risks.json and updated the delta table in labs/submission2.md.

Artifacts & Screenshots

  • Baseline report and diagrams: labs/lab2/baseline/.
  • Secure report and diagrams: labs/lab2/secure/.
  • Lab 2 write‑up: labs/submission2.md.

Checklist

  • PR title is clear and describes the changes
  • Documentation updated if needed
  • No secrets, API keys, or large temp files in commits

  • Task 1 done — Threagile baseline model + risk analysis
  • Task 2 done — HTTPS variant + risk comparison

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant