add into LLM03 1, risk ,1 mitigation point i.e.11 and few references#2
Conversation
Mechanical fixes only, no content change: - ref GenAI-Security-Project#11/GenAI-Security-Project#12: add space after numbering, repair broken markdown link in GenAI-Security-Project#12, normalize separator to ': **Publisher**' - Related Frameworks bullet: restore bold publisher (regression introduced by this PR), normalize separator - add EOF newline
|
Warning Edit 2026-05-02: This comment described an admin-merge that was made without entry-lead approval. The merge has been reverted in #19, and the original content has been reopened in #20 for proper review by @jsotiro and @stefanoamorelli. The original comment text is preserved below for transparency, but the actions it describes are no longer in effect.
|
These two PRs were admin-merged without first routing them through the LLM03 and LLM08 entry leads, which the project owner had wanted done before any merge. This commit restores both 2026/LLM03_*.md and 2026/LLM08_*.md to their state immediately before those merges landed (pre-PR#2 = 7350d2a, pre-PR#13 = beb58df). Once this revert is in, the original PR #2 and PR #13 content will be reopened as fresh PRs targeting main and the entry leads will be tagged for review. PR #17 and PR #11 are not affected — those merges were authorized in a separate decision.
|
@syedDS — apologies. This PR was admin-merged on 2026-05-02 without first routing through the LLM03 entry leads (@jsotiro and @stefanoamorelli), which the project owner @rocklambros had wanted before any merge. That merge has been reverted in #19, and your content has been carried forward verbatim into #20 for proper review. The cherry-pick preserves you as the original commit author. No action required on your end — the entry leads are tagged in #20 and @rocklambros will merge once they sign off. Thank you for your contribution and for the patience while we sort the workflow. |
Added 1 risk
Implement verifiable root-of-trust controls across the full lifecycle, including signed artifacts, provenance tracking, tool/skill allowlisting, and continuous validation of agent permissions and upstream model integrity.
1 mitigation point
"Implement verifiable root-of-trust controls across the full lifecycle, including signed artifacts, provenance tracking, tool/skill allowlisting, and continuous validation of agent permissions and upstream model integrity."