forked from microsoft/hve-core
-
Notifications
You must be signed in to change notification settings - Fork 0
Expand file tree
/
Copy pathTHIRD-PARTY-NOTICES
More file actions
156 lines (127 loc) · 7.16 KB
/
Copy pathTHIRD-PARTY-NOTICES
File metadata and controls
156 lines (127 loc) · 7.16 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
125
126
127
128
129
130
131
132
133
134
135
136
137
138
139
140
141
142
143
144
145
146
147
148
149
150
151
152
153
154
155
156
THIRD-PARTY-NOTICES
This file contains third-party attribution notices for content embedded in hve-core
instruction and skill files. These notices supplement inline attribution blocks within
individual files.
---
OWASP Top 10 (2025), OWASP Top 10 for LLM Applications (2025), and OWASP Top 10 for Agentic Applications (2026)
Copyright: © OWASP Foundation
License: Creative Commons Attribution-ShareAlike 4.0 International (CC BY-SA 4.0)
License URI: <https://creativecommons.org/licenses/by-sa/4.0/>
Source: <https://owasp.org/Top10/2025/>
Source: <https://genai.owasp.org/resource/owasp-top-10-for-llm-applications-2025/>
Source: <https://genai.owasp.org/resource/owasp-top-10-for-agentic-applications-for-2026/>
Usage: Category names, IDs, and condensed descriptions in security instruction files.
Vulnerability reference documents in skill files restructured into agent-consumable
format with added detection and remediation guidance.
OWASP® is a registered trademark of the OWASP Foundation.
---
NIST SP 800-53 Rev. 5 and NIST AI RMF 1.0
License: Public Domain (17 U.S.C. § 105 — U.S. Government Work)
Source: <https://csrc.nist.gov/publications/detail/sp/800-53/rev-5/final>
Source: <https://www.nist.gov/artificial-intelligence/ai-risk-management-framework>
Usage: Control family names, IDs, and condensed descriptions embedded in security
instruction files.
---
OpenSSF Scorecard
License: Apache License 2.0
Source: <https://github.com/ossf/scorecard>
Usage: Check names, risk levels, and score ranges embedded in supply chain security
instruction files.
---
SLSA (Supply-chain Levels for Software Artifacts)
License: Community Specification License 1.0
Source: <https://slsa.dev/spec/>
Usage: Build track level definitions embedded in supply chain security instruction files.
---
Microsoft Code With Engineering Playbook
Copyright: © Microsoft Corporation
License: Creative Commons Attribution 4.0 International (CC BY 4.0)
License URI: <https://github.com/microsoft/code-with-engineering-playbook/blob/main/LICENSE>
Source: <https://microsoft.github.io/code-with-engineering-playbook/design/design-patterns/data-heavy-design-guidance/>
Source: <https://microsoft.github.io/code-with-engineering-playbook/ml-and-ai-projects/testing-data-science-and-mlops-code/>
Source: <https://microsoft.github.io/code-with-engineering-playbook/ml-and-ai-projects/ml-model-checklist/>
Source: <https://microsoft.github.io/code-with-engineering-playbook/ml-and-ai-projects/ml-fundamentals-checklist/>
Source: <https://microsoft.github.io/code-with-engineering-playbook/ml-and-ai-projects/model-experimentation/>
Source: <https://microsoft.github.io/code-with-engineering-playbook/observability/ml-observability/>
Source: https://microsoft.github.io/code-with-engineering-playbook/design/design-reviews/recipes/engineering-feasibility-spikes/
Source: https://microsoft.github.io/code-with-engineering-playbook/design/design-reviews/trade-studies/
Usage: Data-tiering, pipeline-invariant, DS/MLOps testing, validation-versus-drift,
model-experimentation, ML checklist, experiment-candidate selection, and option-comparison
guidance embedded in data-science skill files.
Every page cited above is playbook documentation and is therefore covered by CC BY 4.0.
The upstream project carries a separate LICENSE-CODE file applying the MIT License to code
samples only; no code sample from that project is reproduced here. Content is derived from
the documentation pages and has been changed, and in many passages stays close to or matches
upstream wording, with section headings, tier names, checklist item labels, and API names
retained as identifiers.
---
C4 Model
Creator: Simon Brown
License: Creative Commons Attribution 4.0 International (CC BY 4.0)
License URI: <https://creativecommons.org/licenses/by/4.0/>
Source: <https://c4model.com/>
Usage: C4 concepts, abstractions, and modelling guidance adapted for the
c4-architecture skill. The source material has been paraphrased and changed.
---
OpenSSF Best Practices Badge (CII Best Practices)
License: MIT License (criteria), Creative Commons Attribution 3.0+ (documentation)
Source: <https://www.bestpractices.dev/>
Usage: Badge tier names and requirement summaries embedded in supply chain security
instruction files.
---
Sigstore
License: Apache License 2.0
Source: <https://www.sigstore.dev/>
Usage: Component maturity levels embedded in supply chain security instruction files.
---
SPDX (Software Package Data Exchange)
License: Community Specification License 1.0
Source: <https://spdx.dev/>
Usage: Format comparison data embedded in supply chain security instruction files.
---
CycloneDX
License: Apache License 2.0
Source: <https://cyclonedx.org/>
Usage: Format comparison data embedded in supply chain security instruction files.
---
NTIA Minimum Elements for Software Bill of Materials
License: Public Domain (17 U.S.C. § 105 — U.S. Government Work)
Source: <https://www.ntia.gov/page/software-bill-materials>
Usage: Minimum element names referenced in supply chain security instruction files.
---
Microsoft threat-modeling templates (default.tb7 and default-kb.xml)
License: MIT License
Source: <https://github.com/microsoft/threat-modeling-templates>
Usage: Redistributed in this repository as template and knowledge-base assets for
the TM7 generation extension. The knowledge base is additionally embedded into
each generated .tm7 model, so generated output carries this content.
Redistributed files and SHA-256 digests. Each digest is over the bytes as
committed, which is what `git cat-file blob <rev>:<path> | sha256sum` returns.
Do not compute these from a working-tree copy: both files are stored with LF
and a checkout with `core.autocrlf=true` rewrites them to CRLF, which changes
the digest without changing the redistributed content.
.github/skills/project-planning/security-planning/assets/templates/default.tb7
06a0d76397c8fcbf032cb05cf832c593b626806c3cfd6f10cdd8a5176d3686e5
.github/skills/project-planning/security-planning/assets/templates/default-kb.xml
fa0eda2ad258ccaaf4ba84a030d366be14b6161b31ae301002f532bef0a32174
The MIT license text is retained at
.github/skills/project-planning/security-planning/assets/templates/LICENSE.
---
tm7-cli sample threat model (test fixture)
License: MIT License
Source: <https://github.com/gholliday/tm7-cli>
Upstream file: samples/demo.tm7
Upstream revision: 715954acc5b0a42386d3c0a3a42cdf35c5f41cfc
Usage: Read-only reference fixture for TM7 serializer-order and structure tests.
It is never modified by, or shipped as output of, the generation runtime.
Local file: .github/skills/project-planning/security-planning/tests/fixtures/tmt-reference.tm7
SHA-256: 8c01c931b70388915113bc1b814424ea3400913088af01ce26e62d945b784dc3
The digest is over the bytes as committed, which is what
`git cat-file blob <rev>:<path> | sha256sum` returns. The committed copy is
1212739 bytes, matching the upstream file size. A checkout with
`core.autocrlf=true` rewrites three LF line breaks inside <b:string> elements to
CRLF, giving a 1212742-byte working-tree copy whose digest differs; that is a
checkout artifact and not a difference in the redistributed bytes.
---
OpenSSF® is a registered trademark of the Linux Foundation.
OWASP® is a registered trademark of the OWASP Foundation.