Files
AWatch-rus/docs/public-issues/006-external-security-code-review-checklist.md
T

66 lines
1.8 KiB
Markdown

# Public issue template 006
## Title
[security] Prepare external security/code review checklist
## Labels
`security`, `review`, `governance`
## Purpose
Prepare a public checklist for future visible external security/code review.
## Background
Review checklist and CODEOWNERS exist, but active external peer review is not
claimed until public reviewed pull requests or equivalent evidence exist.
## Scope
- Extend review evidence expectations from `docs/REVIEW_CHECKLIST_RU.md`.
- Define security review scope and artifacts.
- Define how reviewed PRs will be referenced.
- Define forbidden data for public review comments.
## Non-goals
- No claim that external review is already active.
- No publication of sensitive findings before triage.
- Forbidden claim: automatic remediation is not claimed.
## Acceptance criteria
- External/security review checklist is documented.
- Evidence format for reviewed PRs is defined.
- Sensitive disclosure handling is documented.
- First review remains pending until public evidence exists.
## Evidence required
- Checklist document.
- Link to review policy.
- Future reviewed PR URL or placeholder status.
- Security disclosure guardrails.
## Safety/privacy guardrails
- Do not publish exploit details before coordinated handling.
- Do not publish customer data, employee data or secrets.
- Keep vulnerability handling aligned with `SECURITY.md`.
## Registry-positioning guardrails
- Do not claim active external peer review until public reviewed PRs exist.
- Security review evidence is governance evidence, not certification.
- Do not claim FSTEC/FSB certification.
## Checklist
- [ ] Draft external review checklist.
- [ ] Define evidence requirements.
- [ ] Define sensitive disclosure rules.
- [ ] Link to `docs/REVIEW_CHECKLIST_RU.md`.
- [ ] Record first reviewed PR only after it exists.