Conversation
…ure (Issue stellar-vortex-protocol#298) - Create docs/bug-bounty-program.md defining security bug bounty program - Map severity tiers (Critical, High, Medium, Low) to Assets at Risk in SECURITY.md - Include in-scope/out-of-scope categories and conflict-of-interest rules - Define submission process and example severity tier mappings - Cross-reference from SECURITY.md
…tellar-vortex-protocol#299) - Create docs/custody-transparency.md for public custody model disclosure - Document current state (pre-mainnet single-key, hardware-wallet-backed) - Include update procedure for key rotations and transitions to multisig - Add cross-references from SECURITY.md and README.md - Include verification commands and revision history table
…cusal rules (Issue stellar-vortex-protocol#300) - Create docs/arbiter-code-of-conduct.md with eligibility criteria - Define mandatory conflict-of-interest disclosure and recusal procedures - Require decision-rationale disclosure for every arbiter ruling - Include escalation path and stalled dispute fallback - Add conflict-of-interest attestation template - Cross-reference from dispute-resolution-design.md - Include FAQ and revision history
… (Issue stellar-vortex-protocol#301) - Create docs/incident-postmortem-template.md with complete postmortem structure - Define 5-business-day publication commitment for P1 incidents - Include sections: executive summary, detection timeline, root cause, impact, remediation, timeline, monitoring effectiveness, lessons learned, communication, and verification checklist - Add comprehensive example throughout template - Update SECURITY.md to reference postmortem process - Update mainnet-deployment-runbook.md to link incident response procedures
|
@emekaabraham666 Great news! 🎉 Based on an automated assessment of this PR, the linked Wave issue(s) no longer count against your application limits. You can now already apply to more issues while waiting for a review of this PR. Keep up the great work! 🚀 |
…299-300-301 # Conflicts: # docs/bug-bounty-program.md
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Security Governance Documentation Suite
Summary
Add four comprehensive governance and security documentation policies covering bug bounty program, admin/fee-recipient custody transparency, arbiter code of conduct, and incident postmortem process.
Changes
Issue #298 - Bug Bounty Program
docs/bug-bounty-program.mdwith severity tiers (Critical, High, Medium, Low) mapped to Assets at RiskSECURITY.mdIssue #299 - Custody Transparency
docs/custody-transparency.mddocumenting admin and fee-recipient key custody modelSECURITY.mdandREADME.mdIssue #300 - Arbiter Code of Conduct
docs/arbiter-code-of-conduct.mdwith governance policy for dispute/appeal arbitersdocs/dispute-resolution-design.mdIssue #301 - Incident Postmortem Template
docs/incident-postmortem-template.mdwith complete postmortem structure and templateSECURITY.mdanddocs/mainnet-deployment-runbook.mdFiles Changed
Created:
docs/bug-bounty-program.md(253 lines)docs/custody-transparency.md(154 lines)docs/arbiter-code-of-conduct.md(287 lines)docs/incident-postmortem-template.md(400 lines)Modified:
SECURITY.md(added cross-references to all four new documents)README.md(added custody transparency link)docs/dispute-resolution-design.md(added arbiter code of conduct reference)docs/mainnet-deployment-runbook.md(added incident postmortem reference)Closes
SECURITY.md's Assets-at-Risk table #298