-
Notifications
You must be signed in to change notification settings - Fork 8
Audit Registry | Bounty: $14,000 in NEAR #13
Comments
@ilblackdragon I can start with this bounty. Details and functionality are clear. The plan is to build a web app with 3 kinds of users in mind, Auditor, Developer and Contract-User. The functionality is pretty clear from the contract and the blog-post. Besides the app, I'll include a cli-tool to operate on the contract, I guess the cli-tool could become the preferred choice for developers and auditors. Can you assign me to this issue please? |
@luciotato, work is already in progress for this one. |
Related, given Apple's recent debacle - this same registry can be leveraged to also track relationship of both software source code and binary to developers when running it. External verifications (challenge) is possible to confirm that for open source software indeed this binary is compiled from given source code. |
Hi. I'm the initial creator of https://github.com/crev-dev/crev/ which is exactly what you describe here (I think?). It uses a self-generated cryptographic identities and a flexible (and swappable and customizable) Web of Trust to establish trust, and arbitrary review distribution mechanisms. It also has an already implemented Rust programming language integration, that you can test by installing It also has real active users (though not that many yet), and according to my knowledge is the most practical and wholesome attempt at solving distributed open source trust and code auditing problem. Feel free to ask any questions, either here or on user Matrix channel https://matrix.to/#/!uBhYhtcoNlyEbzfYAW:matrix.org |
Hey @ilblackdragon, this bounty looks completed but I want to double check before closing it. Has it been paid? If so, can I close it? |
Yep, it's complete in the current form. |
Description
Audit Registry is designed to increase transparency and security in the blockchain and general software space. It provides a ledger of
Context
[TODO: update after blog post is published]
See draft of the blog post here - https://docs.google.com/document/d/1OX4Nv0Sta70f_1Py-Xs7iDyNHB-SGv_ygc8K2hVJ8CA/
Details
Contract
User Experience
Important note is that user flow will allow developers (or community member) to request the certificate from auditors. Because auditors usually are operating under contract with developer / community member - it's up to them to decide if they want to publish such information.
Acceptance
Bounty
$14,000 in NEAR
The text was updated successfully, but these errors were encountered: