Files
AWatch-rus/docs/public-issues/006-external-security-code-review-checklist.md
T

1.8 KiB

Public issue template 006

Title

[security] Prepare external security/code review checklist

Labels

security, review, governance

Purpose

Prepare a public checklist for future visible external security/code review.

Background

Review checklist and CODEOWNERS exist, but active external peer review is not claimed until public reviewed pull requests or equivalent evidence exist.

Scope

  • Extend review evidence expectations from docs/REVIEW_CHECKLIST_RU.md.
  • Define security review scope and artifacts.
  • Define how reviewed PRs will be referenced.
  • Define forbidden data for public review comments.

Non-goals

  • No claim that external review is already active.
  • No publication of sensitive findings before triage.
  • Forbidden claim: automatic remediation is not claimed.

Acceptance criteria

  • External/security review checklist is documented.
  • Evidence format for reviewed PRs is defined.
  • Sensitive disclosure handling is documented.
  • First review remains pending until public evidence exists.

Evidence required

  • Checklist document.
  • Link to review policy.
  • Future reviewed PR URL or placeholder status.
  • Security disclosure guardrails.

Safety/privacy guardrails

  • Do not publish exploit details before coordinated handling.
  • Do not publish customer data, employee data or secrets.
  • Keep vulnerability handling aligned with SECURITY.md.

Registry-positioning guardrails

  • Do not claim active external peer review until public reviewed PRs exist.
  • Security review evidence is governance evidence, not certification.
  • Do not claim FSTEC/FSB certification.

Checklist

  • Draft external review checklist.
  • Define evidence requirements.
  • Define sensitive disclosure rules.
  • Link to docs/REVIEW_CHECKLIST_RU.md.
  • Record first reviewed PR only after it exists.