Skip to content

馃摑 docs(security): sync threat model with merged fixes - #3312

Merged
gaborbernat merged 1 commit into
pypa:mainfrom
gaborbernat:docs/threat-model-sync
Sep 23, 2026
Merged

gaborbernat merged 1 commit into
pypa:mainfrom
gaborbernat:docs/threat-model-sync

Conversation

@gaborbernat

Copy link
Copy Markdown
Contributor

The threat model merged in #3294 while #3301 and #3306 were still open, so it lists both as pending work. 馃摑 It also names GH_RELEASE_TOKEN as the credential that pushes the release commit, the tag and the get-virtualenv update, which the release GitHub App now does with short-lived tokens.

The assets list, the release data-flow diagram, the S1 discussion and the accepted risks now name the App and its place as a ruleset bypass actor. The T5 mitigation records that the zipapp bundles versions a PEP 751 lock pins by SHA-256, refreshed after the seven-day cooldown. One open item stays for the old personal access token: it remains in the release environment until a release built with App tokens succeeds, and then a maintainer revokes it. The reproducibility item links #3311.

pypa#3301 and pypa#3306 merged, but the threat model still listed both as
open work and named GH_RELEASE_TOKEN as the credential that pushes the
release commit, tag and get-virtualenv update.

Name the release GitHub App as that credential and as a ruleset bypass
actor, record the PEP 751 lock as the zipapp's dependency control, keep
one open item for revoking the old personal access token after the
first App-based release, and link pypa#3311 from the reproducibility item.
@gaborbernat gaborbernat added documentation security Fixes a vulnerability or hardens the supply chain, CI or release labels Sep 23, 2026
@gaborbernat
gaborbernat merged commit bcb0fa6 into pypa:main Sep 23, 2026
65 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

documentation security Fixes a vulnerability or hardens the supply chain, CI or release

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant