Security deep dives¶
Companion documents to the security spec (§7).
- Fgentic Threat Model - STRIDE evidence map: Implemented / Configured / Deferred per control
- Prompt-Injection Controls and Limits - controls and their honest limits for untrusted room content (§7.2)
- Bridge Supply-Chain Verification - independently verifying the signed image, SBOM, and provenance chain
- Security Release Process - private report, signed patch, GHSA/CVE publication, and adopter-notification workflow
- OpenSSF Best Practices & Scorecard Self-Assessment - passing-level criteria mapped to evidence, plus accepted Scorecard deviations for foundation and adopter review
- External Security Audit Readiness Package - scope, trust boundaries, evidence, known limits, engagement options, and remediation workflow for the G3 third-party audit