input-output-hk / cardano-engineering-handbook

A handbook covering cross-project policies and information for projects in the Cardano Open Source Consortium
14 stars 0 forks source link

Write a policy on auditing requirements #22

Open michaelpj opened 2 years ago

abailly-iohk commented 2 years ago

There's already a CIP on audit requirements for DApss, shall we adapt for projects? I have had a look at 2 RFPs, for Mamba and Marlowe, and the latter is much more detailed in terms of scope and target for the audit.

michaelpj commented 2 years ago

I don't think it's the same? In our case it's a lot more about e.g. crypto. I know that Inigo and Charles have a WIP policy.

abailly-iohk commented 2 years ago

Yes, I know, Inigo shared the draft with us, I just wanted to see if there was something we could steal from existing work.

iquerejeta commented 2 years ago

Charles is working in the audit policy. I'll share the CIP with him so that he is aware of it 👍 thanks for pointing it out. For reference, the best practices for audits in dApps is presented in CIP-52.