cachet

security

cachet assumes the author is an untrusted, possibly-hijacked program and the build environment is hostile. Every control flows from that. This is the opposite of GitHub's model, which was built for trusted human authors.

Five leapfrog moves

Full threat model and control map: docs → SECURITY. Responsible disclosure: security.txt.