Ravindra BagaleCourses & study guides मराठी

Chapter 3: Threat Modeling on Paper

3.6 Names you will meet later, not in this volume

Volume 1 ends at the paper model. A later book can teach the repairs and the scanners in depth. Those chapters are not on this site as a second DevSecOps volume. They are not hiding after the recap. You only need to recognise the names so the signpost is honest.

  1. OWASP Top 10 fixes. A well-known list of common web risks, and the habit of fixing them. Not taught here.
  2. SAST, SonarQube and Semgrep. Static checks that read code for risky patterns. SonarQube and Semgrep are tool names. This volume does not include scan commands or rule files.
  3. SCA and SBOM, CycloneDX and SPDX. SCA looks at third-party pieces you did not write. An SBOM is a list of those pieces. CycloneDX and SPDX are formats for that list. Not taught here.

Raju asks to install one of them tonight. Guru-ji shakes his head. "You can name a danger and a fix with a pencil. That is the graduation from this room. Tools on a belt you do not understand will only print fear."

If your job already uses those tools, good. Still do not paste their commands into this course's notes as if Volume 1 taught them. Come back to the picture when a report is noisy. Ask which STRIDE word the finding belongs to, and which fix on the payment sheet would have mattered.