Skip to content

Third-party audit engagement kick-off + in-audit change-freeze CI #158

Description

@truthixify

Tier: L (5-7 days) | Type: ops + docs

Context. contracts/audit-prep/ is thorough (SCOPE, THREAT_MODEL, INTERNAL_AUDITS, TEST_COVERAGE, REPRODUCIBLE_BUILD, DEPLOYMENT_MANIFEST, AUDIT_FIRMS). AUDIT_FIRMS.md already carries substantive tier tables, but audit-prep/README.md still has coordinator + technical-contact as [TBD] (lines 125-126), no SOW has been signed, no ENGAGEMENT.md exists, no audit-freeze.yml workflow exists, and stellar/MAINNET_READINESS.md still has zero of the four audit items checked. Wave 8 turns this from prep into an engagement, with a CI-enforced change-freeze on audit-scoped crates once the SOW starts.

Scope.

  • Fill every [TBD] in audit-prep/README.md and audit-prep/AUDIT_FIRMS.md (coordinator, technical contact, firm shortlist ranked with quotes / timelines).
  • Publish audit-prep/ENGAGEMENT.md documenting the signed SOW: scope crates, out-of-scope crates, kickoff date, delivery milestones, escalation contacts, disclosure policy.
  • Add .github/workflows/audit-freeze.yml: reads audit-prep/ENGAGEMENT.md for freeze_paths: and freeze_until: YAML front-matter; fails any PR that touches a listed path while the freeze is active unless the PR carries the audit-approved label.
  • Update stellar/MAINNET_READINESS.md to reflect engagement status and check off Audit Security audit of stealth-announcer Soroban contract #1 kick-off row.

Acceptance.

  • No [TBD] left in audit-prep/README.md or audit-prep/AUDIT_FIRMS.md
  • audit-prep/ENGAGEMENT.md contains signed-SOW summary (firm, scope crates, dates) with front-matter parsed by the workflow
  • audit-freeze.yml fails a test PR that touches an in-scope crate without the audit-approved label (verified with a dry-run)
  • stellar/MAINNET_READINESS.md reflects the engagement state and links the ENGAGEMENT doc

Files. contracts/audit-prep/README.md, contracts/audit-prep/AUDIT_FIRMS.md, contracts/audit-prep/ENGAGEMENT.md (new), .github/workflows/audit-freeze.yml (new), stellar/MAINNET_READINESS.md.

Metadata

Metadata

Assignees

No one assigned

    Labels

    Stellar WaveIssues in the Stellar wave programauditProduces a written report as primary deliverabledripsFunded via Drips Networkhelp wantedExtra attention is neededopssecuritySecurity-sensitive workstellarTouches Stellar / Soroban codestellar-waveAuto-created for Wave 8wave-8Auto-created for Wave 8

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions