threat-modeling.sgit.ai / admin / versions

Release history

Every push to dev is a release: CI validates the site, verifies the version bump, tags the commit v{release}.{major}.{minor}, and deploys to GitHub Pages. The version is owned by admin/build/version.txt and must agree with the release commit's subject.

VersionDateWhat shipped
v0.1.0 8 Sep 2026 First release: the pipeline, and the site. The CI pipeline (validate → auto-tag → deploy), copied from pki.sgit.ai and influences.sgit.ai — the same three-stage pattern as every other site in the network. The release gate (admin/build/validate.js) adds two rules specific to this site: a cap on any quotation from a third party or a named framework (STRIDE, MITRE ATT&CK, CAPEC, CWE/CVE, OWASP Top 10, ASVS) at 40 words, and a tripwire against anything shaped like a file-and-line finding location outside the verbatim brief pack — the disclosure boundary made executable rather than only stated. The full site scaffold built from the commissioning pack: the thesis front page, the eleven-layer vault embedded and explained, the validation pair as the signature page, all seven white papers summarised with links to source, the method in full with its three sub-pages, the vault-native graph argument with an explicit real-vs-argued table, the mandatory-disclosure position, and threat-modeling AI systems. The commissioning pack published verbatim under /briefs/ with a reader page per document under /documents/. llms.txt, a generated /llms-full.txt, a generated /sitemap.xml, and /.well-known/security.txt shipped from day one. Deliberately not in this release, and tracked on comms: a fuller findings table on /validated/, blocked on the closure pass (Q1); recomputed vault figures (G2); a confirmed StrideGPT contact (Q5).