Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Epic: Improvements from Zebra Audit #6277

Closed
36 tasks done
mpguerra opened this issue Mar 9, 2023 · 3 comments
Closed
36 tasks done

Epic: Improvements from Zebra Audit #6277

mpguerra opened this issue Mar 9, 2023 · 3 comments
Labels
C-audit Category: Issues arising from audit findings Epic Zenhub Label. Denotes a theme of work under which related issues will be grouped

Comments

@mpguerra
Copy link
Contributor

mpguerra commented Mar 9, 2023

Motivation

We want to ensure that we track and act upon findings from the audit.

Scope

zebra

ed25519-zebra

librustzcash

Optional Tasks

Other miscellaneous remarks that are not considered security vulnerabilities. Fixing these could increase code quality.

Out of Scope

Other tasks

  • Write short "Client Summary Responses" for issues where we've accepted the risk and won't be making any changes:
    • [NCC-E005955-6AN]: Power-of-Two-Choices Load Balancing May Deprioritize Honest Peers - assigned to @teor2345
    • [NCC-E005955-GCR]: Cargo Audit and RustSec Advisories - assigned to @dconnolly
    • [NCC-E005955-MU2]: Redundant Computation in Sapling and Orchard Note Validation - assigned to @upbqdn
    • [NCC-E005955-GHX]: Incorrectly Disabled Consistency Check - assigned to @teor2345
@mpguerra mpguerra added the Epic Zenhub Label. Denotes a theme of work under which related issues will be grouped label Mar 9, 2023
@mpguerra mpguerra added this to Zebra Mar 9, 2023
@github-project-automation github-project-automation bot moved this to 🆕 New in Zebra Mar 9, 2023
@mpguerra mpguerra changed the title Epic: Improvements from Audit Findings Epic: Improvements from Zebra Audit Mar 9, 2023
@mpguerra mpguerra added the C-audit Category: Issues arising from audit findings label Mar 9, 2023
@mpguerra
Copy link
Contributor Author

mpguerra commented May 8, 2023

We should probably write a summary response for #6617 . I have added a task to do this.

Who can take this one on?

@teor2345
Copy link
Contributor

teor2345 commented May 8, 2023

We should probably write a summary response for #6617 . I have added a task to do this.

Who can take this one on?

I did that PR, and it's very quick to copy my comments from the PR into the doc. So I'm happy to do it now.

@mpguerra
Copy link
Contributor Author

All done 🎉

@github-project-automation github-project-automation bot moved this from 🆕 New to ✅ Done in Zebra Jul 11, 2023
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
C-audit Category: Issues arising from audit findings Epic Zenhub Label. Denotes a theme of work under which related issues will be grouped
Projects
Archived in project
Development

No branches or pull requests

2 participants