Skip to content

feat(spec): Trust Manifest threat modeling review - suggested updates.#47

Open
muscariello wants to merge 1 commit into
mainfrom
analysis/trust-manifest
Open

feat(spec): Trust Manifest threat modeling review - suggested updates.#47
muscariello wants to merge 1 commit into
mainfrom
analysis/trust-manifest

Conversation

@muscariello

Copy link
Copy Markdown
Member
  • Require a present Trust Manifest to carry a substantive member (signature, attestations, provenance, or trustSchema); ADR-0015.
  • Add a substrate-neutral distribution-mapping contract with OCI and xRegistry bindings; ADR-0014.

…pings

- Require a present Trust Manifest to carry a substantive member
  (signature, attestations, provenance, or trustSchema); ADR-0015.
- Add a substrate-neutral distribution-mapping contract with OCI and
  xRegistry bindings; record ADR-0014.

Signed-off-by: Luca Muscariello <muscariello@ieee.org>
@muscariello muscariello requested a review from a team as a code owner June 21, 2026 11:28
github-actions Bot added a commit that referenced this pull request Jun 21, 2026
@github-actions

Copy link
Copy Markdown
Contributor

Preview: https://agent-card.github.io/ai-catalog/pr/47/

This comment is updated automatically while the pull request preview is available.

@muscariello muscariello linked an issue Jun 21, 2026 that may be closed by this pull request
@muscariello

Copy link
Copy Markdown
Member Author

@darrelmiller @mindpower I went through a threat modeling session on the trust manifest. This is the set of modifications that I suggest to address some of the comments by Pamela and others.

I did not do an accurate analysis since quite some time and if we want to get to v1 this is necessary.

@muscariello muscariello changed the title feat(spec): require substantive trust manifest; add OCI/xRegistry mappings feat(spec): Trust Manifest threat modeling review - suggested updates. Jun 21, 2026

@ramizpolic ramizpolic left a comment

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

This PR can also resolve the issue (Support multiple identities per catalog entry #52) depending if we have a decision. It may be useful extend this PR to include multiple trustmanifests, which would address both the concerns around identity and threat modelling in one go.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Review Trust Manifest Proposal

2 participants