Skip to content

Commit

Permalink
Build Environment Track isn't perfect
Browse files Browse the repository at this point in the history
Signed-off-by: Tom Hennen <tomhennen@google.com>
  • Loading branch information
TomHennen committed Dec 10, 2024
1 parent 3f4a8a0 commit 539d114
Showing 1 changed file with 2 additions and 1 deletion.
3 changes: 2 additions & 1 deletion docs/spec/draft/threats.md
Original file line number Diff line number Diff line change
Expand Up @@ -871,7 +871,8 @@ including OS images, as any other artifact to be verified prior to use.
The threats described in this document apply recursively to build tooling
as do the mitigations and examples. A future
[Build Environment track](future-directions#build-environment-track) may
provide more comprehensive guidance on how to address this threat.
provide more comprehensive guidance on how to address more specfiic
aspects this threat.

*Example:* MyPackage is a tarball containing an ELF executable, created by
running `/usr/bin/tar` during its build process. An adversary compromises the
Expand Down

0 comments on commit 539d114

Please sign in to comment.