Chapter 3: Threat Modeling on Paper
3.6 Names you will meet later, not in this volume
Volume 1 ends at the paper model. A later book can teach the repairs and the scanners in depth. Those chapters are not on this site as a second DevSecOps volume. They are not hiding after the recap. You only need to recognise the names so the signpost is honest.
- OWASP Top 10 fixes. A well-known list of common web risks, and the habit of fixing them. Not taught here.
- SAST, SonarQube and Semgrep. Static checks that read code for risky patterns. SonarQube and Semgrep are tool names. This volume does not include scan commands or rule files.
- SCA and SBOM, CycloneDX and SPDX. SCA looks at third-party pieces you did not write. An SBOM is a list of those pieces. CycloneDX and SPDX are formats for that list. Not taught here.
Raju asks to install one of them tonight. Guru-ji shakes his head. "You can name a danger and a fix with a pencil. That is the graduation from this room. Tools on a belt you do not understand will only print fear."
If your job already uses those tools, good. Still do not paste their commands into this course's notes as if Volume 1 taught them. Come back to the picture when a report is noisy. Ask which STRIDE word the finding belongs to, and which fix on the payment sheet would have mattered.