Skip to content

Prepare the external security audit scope and readiness checklist #79

Description

@joelpeace48-cell

Problem

No serious counterparty will escrow funds in unaudited contracts, and most
grant programmes ask about audit status. Audits are also expensive and slow, and
arriving unprepared wastes a large fraction of the engagement on things the team
could have supplied.

What to do

  • Write docs/AUDIT_SCOPE.md: which contracts, which commit, what is in and
    out of scope, and the trust assumptions the auditor should take as given.
  • Assemble the readiness package: threat model, invariants, architecture notes,
    known issues, and full test coverage figures.
  • Freeze the interface before the engagement — auditing a moving target wastes
    the budget.
  • Budget for a fix-and-review round; the first report is not the end.
  • Plan to publish the report, including unresolved findings and why they were
    accepted.

Acceptance criteria

  • Audit scope document with an explicit commit
  • Readiness package assembled
  • Interface freeze policy agreed
  • Remediation round budgeted
  • Commitment to publish the report, including accepted risks

Notes

Publishing the report including unfixed findings builds more trust than a clean
summary. Reviewers who have read a few audits know there is no such thing as
zero findings.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    GrantFox OSSIssue tracked in GrantFox OSSThird CampaignCampaign: Third Campaignarea:workspaceWorkspace, build, releasedifficulty:mediumFamiliar patterns; touches a few files or conceptspriority:highNeeded for the next milestonetype:securityAuth, funds, secrets, or abuse surface

    Type

    No type

    Projects

    No projects

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions