Joystream / Joystream/joystream
Open Problem: how to securely fix critical runtime issues
- Dominant language
- Rust
- Stars
- 1.4k
- Forks
- 116
- PR merge metrics
- No merged PRs in 30d
Description
# Background
Suppose someone identifies a critical security fix and reports to the council. It is determined that its important to fix and deploy, however, in the process of deploying a runtime upgrade must be made where code change must be explained, presumably. How can the community challenge destructive or malicious upgrades if the code change is not justified transparently?
# Question
1. What ways could this be dealt with?
2. How do other major chains, both with and without upgrades, handle this? Doing a deep dive reviewing incidents on how they were identified, reported, resolved, published and communicated, would be key.
Contributor guide
No contributing guide indexed for this repository
Assessment
This issue has not been assessed yet.