Docs: Add hint about (upcoming) CycloneDX TMBOM (Threat Model Bill of Materials) support
Nobody has claimed this yet.
- Dominant language
- Python
- Stars
- 1.2k
- Forks
- 229
- PR merge metrics
- No merged PRs in 30d
Description
Threat Dragon and pyTM are both participating in the CycloneDX TMBOM (Threat Model Bill of Materials) effort. The goal? A common format so models can move between tools, instead of getting locked into one.
https://threatmodeling.dev/dragpyt/
Why is this important?
This has the potential of resolving a rather overall, organizational threat modeling adoption challenge:
- Product managers, ... (high level) cannot code or do not like to code -> Threat Dragon
- SW Architects (high level <-> low level) prefer "threat models as code" over "threat models as diagram" due to scalability reasons -> pytm
- SW Engineers, Security Engineers, Pentesters, ... (low level) can code and like to code -> pytm
Contributor guide
First steps
- Read the whole issue, then the project's contributing guide.
- Comment on the issue to say you are picking it up — it saves two people doing the same work.
- Fork the repository and make your change on a branch.
- Open a pull request that references the issue number.
Research direction
Start by locating pytm’s documentation entry point and read the linked CycloneDX TMBOM effort for the relevant context. Add a concise hint about the upcoming support and link to the referenced effort; done means readers can understand the planned interoperability without treating it as current functionality.
Written by the indexing model from the issue text.
Assessment
- Tech stack
- python
- Domain
- documentation, security
- Issue type
- Documentation
- Difficulty
- 2/5
- Estimated time
- 1-3 hours
- Activity status
- Quiet
- Clarity
- Mostly clear
- Newbie friendliness
- 58/100