Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Minimal scope for security audit #20

Closed
ignopeverell opened this issue Nov 15, 2018 · 3 comments
Closed

Minimal scope for security audit #20

ignopeverell opened this issue Nov 15, 2018 · 3 comments
Labels
fixed task An action that needs to be taken

Comments

@ignopeverell
Copy link
Contributor

ignopeverell commented Nov 15, 2018

This is a first pass at detailing what could encompass a minimum but still reasonable audit scope. This would focus on cryptographic and consensus-critical code.

If it helps I can produce the diffs for the first 2 points and count the LoC, but overall this shouldn't be that much code.

/cc @Catheryne

Edit: since the 2 first items have been reviewed by JP Aumasson, a full audit on them has become far less pressing. The last 3 items remain important however.

@Catheryne
Copy link

I'll contact all the audit companies with this reduced scope and get bids.

@lehnberg
Copy link
Collaborator

@ignopeverell can you add wallet crate to this? IIRC we said that would also be included.

@lehnberg lehnberg added task An action that needs to be taken fixed labels Mar 11, 2019
@lehnberg
Copy link
Collaborator

fixed, and audit is underway.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
fixed task An action that needs to be taken
Projects
None yet
Development

No branches or pull requests

3 participants