# Threat Model Thursday: Github's Approach

DevFeed: [Threat Model Thursday: Github's Approach](<https://devfeed.tech/articles/threat-model-thursday-github-s-approach-37077.md>)

Original publisher: [Read original article](<https://shostack.org/blog/tmt-githubs-approach/>)

Author: Adam

Published: 2021-04-16T00:00:00Z

Content type: opinion

Language: en

Sources: [Shostack & Friends Blog](<https://devfeed.tech/sources/shostack-friends-blog.md>)

Topics: [GitHub](<https://devfeed.tech/topics/github.md>), [Security](<https://devfeed.tech/topics/security.md>), [Agile](<https://devfeed.tech/topics/agile.md>)

Tags: [agile](<https://devfeed.tech/tags/agile.md>), [github](<https://devfeed.tech/tags/github.md>), [meetings](<https://devfeed.tech/tags/meetings.md>), [process](<https://devfeed.tech/tags/process.md>), [reviews](<https://devfeed.tech/tags/reviews.md>), [security](<https://devfeed.tech/tags/security.md>)

## AI overview

This commentary examines GitHub's threat-modeling approach, focusing on its use of review meetings, process, broad system-surface evaluation, and the lack of specific procedural steps. It also questions whether the approach may place threat modeling too late in development and contrasts it with agile practices such as modeling every story.

## Source excerpt

A bunch of people recently asked me about Robert Reichel's post 'How We Threat Model,' and I wanted to use it to pick up on Threat Model Thursdays.