ATALAIA
  1. Home
  2. Resources
  3. Glossary
Glossary

The words on the line.

SBOM, SLSA, provenance, MCP and the rest, in one sentence each.

Abuse case
A user story written from the attacker's side: how a feature could be misused, and what should stop it.
Attestation
A signed statement about an artefact, such as how and where it was built.
Blast radius
Everything an attacker can reach after compromising one component, token or person.
Break-glass access
Emergency access to production that is time-limited, logged and reviewed afterwards.
DAST
Dynamic application security testing: testing a running application from the outside.
Ephemeral runner
A CI runner created for one job and destroyed afterwards, so nothing persists between builds.
IaC scanning
Checking infrastructure-as-code (Terraform, Kubernetes manifests, etc.) for insecure settings before it is applied.
IDOR
Insecure direct object reference: accessing someone else's data by changing an identifier.
MCP
Model Context Protocol: a standard way for AI agents to call tools and read data from external servers.
Pinned action
A CI step referenced by an immutable commit hash instead of a tag that can be moved.
Prompt injection
Instructions hidden in content an AI agent reads, meant to make it act against its user.
Provenance
Verifiable information about where an artefact came from: source, builder and build steps.
SAST
Static application security testing: analysing source code for vulnerabilities without running it.
SBOM
Software bill of materials: the list of components inside a piece of software.
SCA
Software composition analysis: finding known vulnerabilities and licence issues in dependencies.
security.txt
A file at /.well-known/security.txt that tells researchers how to report a vulnerability.
SLSA
Supply-chain Levels for Software Artifacts: a framework of levels for build integrity and provenance.
STRIDE
A threat-modeling prompt: spoofing, tampering, repudiation, information disclosure, denial of service, elevation of privilege.
Threat model
A shared picture of a system, what can go wrong with it, and what you will do about it.
Trust boundary
A line where data or control passes between parts of a system with different levels of trust.
Typosquatting
Publishing a malicious package with a name close to a popular one, hoping it gets installed by mistake.
VDP
Vulnerability disclosure policy: how outsiders can report a vulnerability safely and what they can expect.