Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Add directories and files for keys, canaries, CVEs, audits #1

Merged
merged 7 commits into from
Oct 5, 2019

Conversation

j01tz
Copy link
Member

@j01tz j01tz commented Sep 19, 2019

TODO:

  • Review format for storing audit/ data
  • Review keys/ to make sure all keys are accurate, no keys are missing and no unnecessary keys are provided
  • Add and verify signatures for canary-001 for @lehnberg and @hashmap
  • Review to ensure clarity regarding security/responsible disclosure policy
  • Update SECURITY.md to reflect new grin-security repo data

Work in progress to populate grin-security with necessary pieces. Feedback is appreciated regarding clarity, sufficiency, formatting, accuracy etc.

@j01tz
Copy link
Member Author

j01tz commented Sep 23, 2019

The PGP keys in keys/ should be committed by the key holder (ideally with a signed commit using that key). For now the minimum keys are the security disclosure contacts but it might be nice to have PGP keys for other core developers in one auditable place.

@lehnberg do you mind taking a look at the audits/ and canaries/ directories to make sure we are on the same page wrt formatting?

Once the structure looks good we need @lehnberg and @hashmap to add PGP keys to keys/ and canary signatures in canaries/. Feel free to ping me on keybase with any questions on signatures etc.

Once this is complete and this PR is merged to master I can update mimblewimble/grin#3009, completing the implementation for RFC-003.

@j01tz j01tz changed the title [WIP] Add directories and files for keys, canaries, CVEs, audits Add directories and files for keys, canaries, CVEs, audits Oct 5, 2019
@j01tz j01tz marked this pull request as ready for review October 5, 2019 07:41
@lehnberg lehnberg merged commit dc60304 into mimblewimble:master Oct 5, 2019
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

3 participants