- Home
- Resources
- Glossary
Glossary
The words on the line.
SBOM, SLSA, provenance, MCP and the rest, in one sentence each.
- Abuse case
- A user story written from the attacker's side: how a feature could be misused, and what should stop it.
- Attestation
- A signed statement about an artefact, such as how and where it was built.
- Blast radius
- Everything an attacker can reach after compromising one component, token or person.
- Break-glass access
- Emergency access to production that is time-limited, logged and reviewed afterwards.
- DAST
- Dynamic application security testing: testing a running application from the outside.
- Ephemeral runner
- A CI runner created for one job and destroyed afterwards, so nothing persists between builds.
- IaC scanning
- Checking infrastructure-as-code (Terraform, Kubernetes manifests, etc.) for insecure settings before it is applied.
- IDOR
- Insecure direct object reference: accessing someone else's data by changing an identifier.
- MCP
- Model Context Protocol: a standard way for AI agents to call tools and read data from external servers.
- Pinned action
- A CI step referenced by an immutable commit hash instead of a tag that can be moved.
- Prompt injection
- Instructions hidden in content an AI agent reads, meant to make it act against its user.
- Provenance
- Verifiable information about where an artefact came from: source, builder and build steps.
- SAST
- Static application security testing: analysing source code for vulnerabilities without running it.
- SBOM
- Software bill of materials: the list of components inside a piece of software.
- SCA
- Software composition analysis: finding known vulnerabilities and licence issues in dependencies.
- security.txt
- A file at /.well-known/security.txt that tells researchers how to report a vulnerability.
- SLSA
- Supply-chain Levels for Software Artifacts: a framework of levels for build integrity and provenance.
- STRIDE
- A threat-modeling prompt: spoofing, tampering, repudiation, information disclosure, denial of service, elevation of privilege.
- Threat model
- A shared picture of a system, what can go wrong with it, and what you will do about it.
- Trust boundary
- A line where data or control passes between parts of a system with different levels of trust.
- Typosquatting
- Publishing a malicious package with a name close to a popular one, hoping it gets installed by mistake.
- VDP
- Vulnerability disclosure policy: how outsiders can report a vulnerability safely and what they can expect.