-
Notifications
You must be signed in to change notification settings - Fork 74
certs: add Smart Contract Development Lifecycle to DevOps & Infrastructure #522
Copy link
Copy link
Open
Labels
certificationsThis issue or PR relates to the SEAL Certification Initiative: content, process, and tooling.This issue or PR relates to the SEAL Certification Initiative: content, process, and tooling.content:addThis issue or PR adds content or suggests toThis issue or PR adds content or suggests toenhancementUpdates that improve or refine existing features, user experience, or system performance.Updates that improve or refine existing features, user experience, or system performance.
Description
Activity
Metadata
Metadata
Assignees
Labels
certificationsThis issue or PR relates to the SEAL Certification Initiative: content, process, and tooling.This issue or PR relates to the SEAL Certification Initiative: content, process, and tooling.content:addThis issue or PR adds content or suggests toThis issue or PR adds content or suggests toenhancementUpdates that improve or refine existing features, user experience, or system performance.Updates that improve or refine existing features, user experience, or system performance.
Summary
Smart contract code is intentionally out of scope for SEAL Certifications, but the operational process around smart contract security is not currently covered anywhere in the framework. A protocol's smart contract development lifecycle (audits, testing, change controls, bug bounty, vulnerability monitoring) is core operational security and belongs in scope.
Gap
A review of the current certs shows no controls covering security audits, formal testing, or bug bounties. Only Incident Response monitoring (
ir-2.x) touches deployed smart contracts.Proposal
Add a new section to DevOps & Infrastructure (
sfc-devops-infrastructure), e.g. di-5: Smart Contract Development Lifecycle, with:Deployed-contract vulnerability monitoring is already partly covered by Incident Response (
ir-2.x); di-5 should reference it rather than duplicate it.Scope note to preserve: this assesses the process and assurance around smart contracts, not the contract code itself, which remains out of scope.
Open questions
Raised by @zS-SFC.
TODO (housekeeping): create a
certificationslabel for the repo and apply it to certs issues like this one. The certs contribution guide (#521) directs contributors to open issues with thecertificationstag, but that label does not exist yet. This issue currently uses the closest existing labels instead.