← Package directory
Available on winget

Install Threat-Dragon-ng

Threat Dagon is an open source threat modeling tool and is an official OWASP project. It is used to draw threat modeling diagrams and to list threats for elements in the diagram

Install with winget
winget install --id OWASP.ThreatDragon
Upgrade
winget upgrade --id OWASP.ThreatDragon
Uninstall
winget uninstall --id OWASP.ThreatDragon

About Threat-Dragon-ng

OWASP Threat Dragon is a free, open-source, cross-platform threat modeling application. It is used to draw threat modeling diagrams and to list threats for elements in the diagram along with their remediations. Threat Dragon is designed to be accessible for various types of teams, with an emphasis on flexibility and simplicity. It is an OWASP Lab Project and follows the values and principles of the threat modeling manifesto

What's new in 2.6.2

What's Changed This patch release is primarily intended to address #1627 - Bump baseline-browser-mapping from 2.10.19 to 2.10.20 in the root-npm-version group by @dependabot[bot] in #1608 - Bump actions/setup-node from 6.3.0 to 6.4.0 in /.github/workflows in the update-version group by @dependabot[bot] in #1610 - Skip visual regression tests by @lreading in #1614 - Bump the vue-npm-security group across 1 directory with 3 updates by @dependabot[bot] in #1609 - td.vue: Remove unneeded overrides by @lreading in #1616 - td.server: Remove unneeded overrides by @lreading in #1615 - TM-BOM: refactor and debug merge / import by @jgadsden in #1550 - Bump minimatch from 3.1.3 to 3.1.5 in /td.server in the server-npm-security group across 1 directory by @dependabot[bot] in #1619 - Bump the server-npm-security group across 1 directory with 2 updates by @dependabot[bot] in #1628 - Bump aquasecurity/trivy-action from 0.35.0 to 0.36.0 in /.github/workflows in the update-version group by @dependabot[bot] in #1624 - Harden TM-BOM import / merge by @jgadsden in #1626 - Fix inconsistent state between cell data and name for component labels by @lreading in #1630 - add vue key to graph properties to prevent stale cell references by @lreading in #1633 - Release/v2.6.2 by @lreading in #1634 Full Changelog: v2.6.1...v2.6.2 Web application The web application is provided as a .tar.gz file or a .zip file along with SBOMs. Docker containers The docker images are available from Dockerhub: - For X86 platforms pull the image: docker pull --platform linux/x86_64 owasp/threat-dragon:v2.6.2 - Alternativel...

Read release notes

Version history

Version Updated Notes
2.6.2 Unknown What's Changed This patch release is primarily intended to address #1627 - Bump baseline-browser-mapping from 2.10.19 to 2.10.20 in the root-npm-version group by @dependabot[bot] in #1608 - Bump actions/setup-node from 6...
2.6.1 Unknown What's Changed The main changes are two bug fixes: Desktop: CTRL-S in diagram editor does not save changes in spite of UI feedback PDF report generation of version 1.x models freezes the application Web application The w...
2.6.0 Unknown Changes - Integration with OWASP Cornucopia with new Threat Dragon EoP Games diagrams - Threat model templates when using github repositories or the web application local filesystem Web application The web application is...
2.5.0 Unknown What's Changed - Add demo models from Threat Model Cookbook - Add about box for all platforms - Update el.js by @kostasadriano in #1288 - Multiple Diagrams: copy diagrams from edit page by @fparuce in #1285 - Update file...
2.4.1 Unknown What's Changed - Bug fix for unexpected label on Trust Boundary Box - Bug fix for data flows and trust boundary curve labels incorrectly displayed - priority level TBA renamed to TBD Full Changelog: v2.4.0...v2.4.1 Web a...
2.3.0 Unknown Release notes
2.2.0 Unknown Release notes