threat-modeling.sgit.ai / shipped
What's shipped
What is built and live, in order — the changelog this site's own thesis requires it to keep, since a site arguing that claims should be checkable cannot leave its own progress implicit. Full release-by-release detail lives at /admin/versions.html; this page is the summary.
v0.1.0 — first release
- The CI pipeline: validate → auto-tag → deploy to GitHub Pages, the same three-stage pattern as every other site in the network
- The release gate (
admin/build/validate.js): version agreement, internal links and fragments, canonical-host agreement, no script loaded twice, the framework-reproduction cap on quotations, the file-and-line disclosure-location tripwire, and the credential-leak tripwire - The full site scaffold: the thesis front page, /eleven-layers/, /validated/, all seven /papers/ pages, /practice/ and its three sub-pages, /graph/, /disclosure/, /agentic/
- The commissioning pack published in full under /documents/, verbatim under
/briefs/ llms.txt, generated/llms-full.txt, generated/sitemap.xml,/robots.txt,/.well-known/security.txt- This site's own additions to the shared network stylesheet: verdict pills, the claim/check two-column block, the eleven-layer ladder, and the disclosure held-count and boundary components
Deliberately not in this release
- A fuller findings table on /validated/ — blocked on the closure pass (comms Q1): nothing may be published as open or closed until re-checked against current code
- Recomputed vault figures on /eleven-layers/ — currently quoted from the vault's own published page rather than computed from its JSON (gap G2)
- A confirmed StrideGPT integration — the intention is stated on /graph/, no contact is confirmed (comms Q5)
- Content pages for threat models 4 and 5 (token consumption flow; office document viewers and print) beyond their catalogue entry — a read-and-publish pass has not happened yet (gap G5)