archway-network / archway-network/cli
Add Security.md Security Policy for Reporting Vulnerabilities Appropriately
- Dominant language
- TypeScript
- Stars
- 42
- Forks
- 19
- PR merge metrics
- No merged PRs in 30d
Description
It is important to create a policy for reporting security vulnerabilities for smart contract and blockchain projects outside of github issues. This can often be a security.md or SECURITY.md file that is referenced in the readme.md
Example:
see https://github.com/CosmosContracts/juno/blob/main/SECURITY.md as an example from the cosmos ecosystem.
Full Disclosure:
I am a part of SecurityDAO https://secdao.xyz/ and our DAO does security audits and security consulting for cosmos projects and cosmwasm smart contracts
┆Issue is synchronized with this [Jira Task](https://phi-labs.atlassian.net/browse/ACLI-53) by [Unito](https://www.unito.io)
Contributor guide
No contributing guide indexed for this repository
Research direction
Review the linked Cosmos SECURITY.md example and the repository README to determine where the policy should be referenced. Add a SECURITY.md policy describing an appropriate vulnerability-reporting route outside GitHub issues, then verify that the README points readers to it.
Written by the indexing model from the issue text.
Assessment
- Tech stack
- blockchain
- Domain
- documentation, security
- Issue type
- Documentation
- Difficulty
- 1/5
- Estimated time
- 1-3 hours
- Activity status
- Stale
- Clarity
- Clearly specified
- Newbie friendliness
- 35/100