Skip to content

Prepare the external security audit scope and readiness checklist #79

Description

@joelpeace48-cell

Problem

No serious counterparty will escrow funds in unaudited contracts, and most
grant programmes ask about audit status. Audits are also expensive and slow, and
arriving unprepared wastes a large fraction of the engagement on things the team
could have supplied.

What to do

  • Write docs/AUDIT_SCOPE.md: which contracts, which commit, what is in and
    out of scope, and the trust assumptions the auditor should take as given.
  • Assemble the readiness package: threat model, invariants, architecture notes,
    known issues, and full test coverage figures.
  • Freeze the interface before the engagement — auditing a moving target wastes
    the budget.
  • Budget for a fix-and-review round; the first report is not the end.
  • Plan to publish the report, including unresolved findings and why they were
    accepted.

Acceptance criteria

  • Audit scope document with an explicit commit
  • Readiness package assembled
  • Interface freeze policy agreed
  • Remediation round budgeted
  • Commitment to publish the report, including accepted risks

Notes

Publishing the report including unfixed findings builds more trust than a clean
summary. Reviewers who have read a few audits know there is no such thing as
zero findings.

Metadata

Metadata

Assignees

No one assigned

    Labels

    GrantFox OSSIssue tracked in GrantFox OSSThird CampaignCampaign: Third Campaignarea:workspaceWorkspace, build, releasedifficulty:mediumFamiliar patterns; touches a few files or conceptspriority:highNeeded for the next milestonetype:securityAuth, funds, secrets, or abuse surface

    Type

    No type

    Projects

    No projects

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions