Write the Threat Modeling of the project
Open
Nobody has claimed this yet.
security
- Dominant language
- Python
- Stars
- 1.9k
- Forks
- 323
- Avg merge
- 1d 12h
- Merged PRs (30d)
- 12
Description
It’s a list of what part we considered as trusted and what we consider insecure.
And also what we feel responsible for to protect our users.
https://github.com/expressjs/security-wg/blob/main/docs/ThreatModel.md
Contributor guide
First steps
- Read the whole issue, then the project's contributing guide.
- Comment on the issue to say you are picking it up — it saves two people doing the same work.
- Fork the repository and make your change on a branch.
- Open a pull request that references the issue number.
Research direction
Start with the linked Express security-wg docs/ThreatModel.md as the example structure. Review CodeCarbon's project boundaries and document which parts are trusted or insecure and what protections the project assumes responsibility for; done means a project-specific threat model is added.
Written by the indexing model from the issue text.
Assessment
- Domain
- security
- Issue type
- Documentation
- Difficulty
- 5/5
- Estimated time
- Over a week
- Activity status
- Stale
- Clarity
- Mostly clear
- Newbie friendliness
- 35/100