I’m on a phone so please forgive me if I missed it, but is the intended threat model for gittuf documented anywhere? I see a reference (in the linked paper) to a vulnerability that’s been submitted to CERT that gittuf is expected to remediate, but it wasn’t immediately clear to me whether using an authenticated transport (e.g. SSH) would solve that particular issue as well.