12
0
Fork 0
mirror of https://github.com/astral-sh/setup-uv.git synced 2026-06-29 01:00:44 +00:00
Commit graph

1 commit

Author SHA1 Message Date
Zsolt Dollenstein
c86fe4ef1f
Add a threat model for setup-uv (#923)
This adds a threat model for `setup-uv` so security scanners can use it
as a baseline in terms of what's in-, and out of scope.

The TM covers credential recipients, executable and cache boundaries,
and release authority. It treats checkout-selected interpreters, paths,
virtual environments, symlinks, and helpers as delegated project
authority unless they override an explicit workflow choice or cross an
independent cache, runner, remote, or publication boundary.
2026-06-27 21:01:45 +02:00