yearn / budget

yearn budget requests and audits
MIT License
36 stars 26 forks source link

Security Team - Budget Request #115

Open rareweasel opened 1 year ago

rareweasel commented 1 year ago

Scope

This budget request is for the security team comprised currently of two core contributors and one internship slots to continue contributing with security related work in the yearn ecosystem. It will cover one quarter (3 months) and continue the team's work on security reviews for all contracts under development in the yearn teams as capability allows. Over the following period, these budget requests should develop and provide a detail of work attempted and achieved.

This request also will detail an overview of the team's goals and objectives for the period.

Note that this budget request includes no revenue share.

Plan

Note that there are no clawbacks based on the below performance targets. But performance should impact future budget requests.

Security Reviews

The security team will continue to work on the following:

External Security Reviews & Audits Coordination

The security team will guide and coordinate all the external security reviews and audits when requested by yteams.

The process for coordinating audits and external security reviews is the following:

  1. The yTeam that needs an audit/external security review will request coordination/help.
  2. The security team will coordinate the slot/s with the audit firms or external reviewers.
  3. Once and agreement with audit firm is reached, security team will create a group so yTeam and auditors can ask/answer questions. Coordination of payment and budget is managed by each yTeam.
  4. Once the audit/review finishes, the security team will review the report and coordinate with yTeam to help review issues to ensure they are fixed or acknowledge.

Note that this process might change based on the team's needs.

Ad hoc

The security team will also continue working with existing Yearn teams (or new ones) to provide ad-hoc support. Including but not limited to offering:

Reporting weekly in the telegram group and monthly in the issue.

Goals

The security team plans to:

Deadline

2023-04-01

People

Money

This budget request includes the following concepts:

Funds to be streamed over three months, starting 1 April 2023.

Total:

7.5 YFI 62,000.00 DAI

Any funds not spent at the end of the period will be transferred back to the yBudget team or considered for the next period.

Funds Details

Funds Details

Wallet address

0x4851C7C7163bdF04A22C9e12Ab77e184a5dB8F0E

Reporting

Monthly

0xValJohn commented 1 year ago

Fully support this! I've been working with Weasel and Storm for about a year now. They have been instrumental in finding hard-to-spot vulnerabilities and are always happy to help and share their knowledge. Funding security reviews is paramount in keeping user deposits safe and maintaining Yearn's reputation. These are the right people for the job and are worth every penny!

rareweasel commented 1 year ago

Security Team April Updates

NOTE: some of the links for internal gh repos are access restricted for security purposes.

rareweasel commented 1 year ago

Security Team May Updates

NOTE: some of the links for internal gh repos are access restricted for security purposes.

rareweasel commented 1 year ago

Security Team June Updates

NOTE: some of the links for internal gh repos are access restricted for security purposes.

rareweasel commented 1 year ago

Security Team July Updates

NOTE: some of the links for internal gh repos are access restricted for security purposes.