summaryrefslogtreecommitdiff
path: root/PlantUML-ModelingTrust/GnuPG-WoT-Download/README.adoc
diff options
context:
space:
mode:
authorstefan <stefan@i3mint.local>2026-02-23 18:59:25 +0100
committerstefan <stefan@i3mint.local>2026-02-23 18:59:25 +0100
commit130b63ade620f4a2619233feb3e5e4ea56d58983 (patch)
treeb8c17aacb9cb2118f377d70f65ff33a0a4623143 /PlantUML-ModelingTrust/GnuPG-WoT-Download/README.adoc
parenteb4668408ceac440972213053ab0d97f6fa7ae89 (diff)
Readme vergessen
Diffstat (limited to 'PlantUML-ModelingTrust/GnuPG-WoT-Download/README.adoc')
-rw-r--r--PlantUML-ModelingTrust/GnuPG-WoT-Download/README.adoc14
1 files changed, 14 insertions, 0 deletions
diff --git a/PlantUML-ModelingTrust/GnuPG-WoT-Download/README.adoc b/PlantUML-ModelingTrust/GnuPG-WoT-Download/README.adoc
index 59e3da1..fe1010a 100644
--- a/PlantUML-ModelingTrust/GnuPG-WoT-Download/README.adoc
+++ b/PlantUML-ModelingTrust/GnuPG-WoT-Download/README.adoc
@@ -23,3 +23,17 @@ Evil Black Hat hacks the webserver, and swaps the ISO image for a manipulated on
The manipulated Signature verifies the fake-integrity of the manipulated ISO image, but not the authenticity.
image::300-NetBSD-RelEng-STRIDE.png[]
+
+
+
+
+== Supply-chain Levels for Software Artifacts
+
+A simple threat model for SLSA Level 1 and Leve 4 build and distribution pipelines.
+
+image::200-ThreatModel-SLSA1-DownloadSig.png[]
+
+
+
+image::201-ThreatModel-SLSA4-ReproducibleBuilds.png[]
+