Skip to content

[Quarterly Threat Model] 2026-Q3 — 2026-07-01 #47

Description

@github-actions

Automated quarterly reminder issued by .github/workflows/quarterly-threat-model.yml.

2026-Q3 Threat Model Exercise

Cadence governance per docs/security_cadence.md requires a quarterly threat model exercise.
This issue is the trigger; the actual exercise artifact is produced by following the runbook.

Action Items

  • Read docs/red_team_runbook.md for the exercise procedure.
  • Read docs/red_team_scorecard.md for the scoring matrix.
  • Run the static workflow-integrity phase: python artifacts/scripts/run_red_team_suite.py --phase static.
  • Run the generative discovery engine: invoke the security-audit skill (.github/skills/security-audit/) to hunt exploitable vulnerabilities; validate its findings.json with python .github/skills/security-audit/scripts/validate_findings.py --findings <run>/findings.json.
  • Stage confirmed findings into artifacts/governance/threat-findings-pending-update.*.json per SKILL.md Phase 7 (do NOT edit the frozen inventory snapshot).
  • File any follow-up backlog items per docs/red_team_backlog.md.
  • Close this issue with a link to the produced artifact.

Deadline

Complete by end of 2026-Q3 (within 30 days of this issue).

References

  • Cadence spec: docs/security_cadence.md
  • Runbook: docs/red_team_runbook.md
  • Scorecard: docs/red_team_scorecard.md
  • Backlog: docs/red_team_backlog.md
  • Discovery engine: .github/skills/security-audit/SKILL.md (adapted from cloudflare/security-audit-skill, MIT)

If this issue was created in error or already addressed for this quarter, close it with a brief note.

Metadata

Metadata

Assignees

No one assigned

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions