Joystream / Joystream/joystream

Open Problem: how to securely fix critical runtime issues

Open
#4,329 13 comments 0 reactions 0 assignees View on GitHub
post-mainnet question runtime
Dominant language
Rust
Stars
1.4k
Forks
116
PR merge metrics
No merged PRs in 30d

Description

# Background

Suppose someone identifies a critical security fix and reports to the council. It is determined that its important to fix and deploy, however, in the process of deploying a runtime upgrade must be made where code change must be explained, presumably. How can the community challenge destructive or malicious upgrades if the code change is not justified transparently?

# Question

1. What ways could this be dealt with?
2. How do other major chains, both with and without upgrades, handle this? Doing a deep dive reviewing incidents on how they were identified, reported, resolved, published and communicated, would be key.

Contributor guide

No contributing guide indexed for this repository

Assessment

This issue has not been assessed yet.

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.