Open source · Security & Privacy

Threat Model Change Tracker

Show how code, configuration and infrastructure changes alter threat assumptions.

v0.1.0 · Node.js 22+ · MIT

Browse the public repository · View releases

Offline, read-only comparison of versioned local architecture exports and a supplied change inventory. It produces human-review items, not a generated threat model, attack chain, exploit, or live scan. The exporter owns completeness and correctness of architecture evidence.

This walkthrough uses the tool's public README and checked-in example files. Run the command from a repository checkout with Node.js 22+; inspect the source before using it on your own files.

Run the checked-in example

node bin/threat-model-change-tracker.mjs --root examples --input passing.json
node bin/threat-model-change-tracker.mjs --root examples --input failing.json
node bin/threat-model-change-tracker.mjs --root examples --input needs-review.json
npm run check

Read the result

--root confines reads by real path; --input is relative inside it. Optional --human prints one stderr summary. Stdout is only JSON; no output file is written. Invalid arguments/configuration: exit 2, empty stdout. Missing, partial, stale-to-review or unsupported evidence: incomplete JSON, exit 2. Invented/contradictory change inventory: evaluated fail, exit 1. Unchanged, complete architecture with matching empty inventory: pass, exit 0.

Where this check stops

1,048,576 UTF-8 bytes; 100 records per snapshot collection and 100 inventory rows; JSON depth 5 from root depth 0; 5,000 ms on an injectable library clock. Exact N accepted; N+1 incomplete. Strict UTF-8 and duplicate-key rejection (including escaped spellings) prevent ambiguous evidence. CLI read has a 5-second abort. No network, repository scraping, live cloud lookup, threat inference, exploit generation, remediation or state change.

Before adapting the command to your own workflow, review the accepted inputs, exit codes and safety boundaries in the README.

Compiled with AI assistance from checked-in public documentation and example scripts. Run the example and review the repository's current documentation before relying on its result.