OpenBSD don't even have security advisories like most other distros have. [1]
So I'd argue it's impossible to build a correct threat model if all your vulnerabilities are expressed on code-level, rather than on "what software" or "what packages" are affected by it.
So I'd argue it's impossible to build a correct threat model if all your vulnerabilities are expressed on code-level, rather than on "what software" or "what packages" are affected by it.
[1] https://www.openbsd.org/errata73.html