security_review/security_review_evidence_template.json

4323 bytes
{
  "artifacts": [
    {
      "exists": true,
      "path": "docs/spacecash/SECURITY_AUDIT_SCOPE.md",
      "sha256": "3BC3CAF657A57C49229933301BDD1FC9C2133A78F89BF4DF9D7E067478B0D8D3"
    },
    {
      "exists": true,
      "path": "docs/spacecash/THREAT_MODEL.md",
      "sha256": "AFD89190A4C0B763387E6358A242BBC047E2032568B64D6B792FD8715F77A46A"
    },
    {
      "exists": true,
      "path": "docs/spacecash/MAINNET_GATE.md",
      "sha256": "C41DAD804A8461829733E15722B1939123E3E4F3D4BC18E2080D5E397C0DEAB0"
    }
  ],
  "auditor": {
    "contact": "",
    "firm": "",
    "independence_statement": "",
    "name": "",
    "signed_scope_path": "",
    "signed_scope_sha256": ""
  },
  "chain_id": "spacecash-devnet-1",
  "closure": {
    "accepted_risks": [],
    "approved_for_release": false,
    "auditor_statement": "",
    "closed_at": "",
    "status": "not_started"
  },
  "findings": [],
  "manual_gate": {
    "id": "external_security_review_complete",
    "reason": "External auditor findings, remediation evidence, accepted-risk record, and final closure are required.",
    "status": "not_complete"
  },
  "mode": "spacecash-external-security-review-evidence-v1",
  "protocol_hashes": {
    "consensus_spec_hash": "02FC7BE0A5DDE8D5D95EDA14BD8D1F195BB680D1D853123ABD89F8BBDAF85E5B",
    "genesis_allocation_hash": "131ED3AD0536152AB3D6590D7804DCF614206617DEAE41D238905913E36944E1",
    "genesis_plan_hash": "55D62969DFEE8460989A8A36D59F37D78CFB8BAF48DE44BF7B991FE61DFEEC27",
    "monetary_policy_hash": "5C4C51D443B91EF950B0E3FCC2A653F14C650E2316CACF2D93740CE180496B64",
    "wallet_policy_hash": "239750DE7AC4374A298EED8124925E8193B8D16FA966E0D6FBB256B873F422C8"
  },
  "remediation": {
    "all_critical_high_closed": false,
    "evidence_paths": [],
    "notes": "",
    "reviewed_remediation_hash": ""
  },
  "reviewed_source_hash": "",
  "scope": {
    "topics": [
      {
        "evidence": "",
        "id": "signature_payload_binding",
        "notes": "",
        "reviewer": "",
        "severity_if_failed": "critical",
        "status": "not_reviewed"
      },
      {
        "evidence": "",
        "id": "nonce_and_mempool_replay",
        "notes": "",
        "reviewer": "",
        "severity_if_failed": "critical",
        "status": "not_reviewed"
      },
      {
        "evidence": "",
        "id": "ledger_supply_and_blocks",
        "notes": "",
        "reviewer": "",
        "severity_if_failed": "critical",
        "status": "not_reviewed"
      },
      {
        "evidence": "",
        "id": "snapshot_sync_import",
        "notes": "",
        "reviewer": "",
        "severity_if_failed": "high",
        "status": "not_reviewed"
      },
      {
        "evidence": "",
        "id": "consensus_spec_integrity",
        "notes": "",
        "reviewer": "",
        "severity_if_failed": "high",
        "status": "not_reviewed"
      },
      {
        "evidence": "",
        "id": "monetary_policy_integrity",
        "notes": "",
        "reviewer": "",
        "severity_if_failed": "high",
        "status": "not_reviewed"
      },
      {
        "evidence": "",
        "id": "genesis_allocation_boundary",
        "notes": "",
        "reviewer": "",
        "severity_if_failed": "high",
        "status": "not_reviewed"
      },
      {
        "evidence": "",
        "id": "genesis_allocation_schema",
        "notes": "",
        "reviewer": "",
        "severity_if_failed": "high",
        "status": "not_reviewed"
      },
      {
        "evidence": "",
        "id": "wallet_recovery_custody_boundary",
        "notes": "",
        "reviewer": "",
        "severity_if_failed": "high",
        "status": "not_reviewed"
      },
      {
        "evidence": "",
        "id": "checkpoint_quorum",
        "notes": "",
        "reviewer": "",
        "severity_if_failed": "high",
        "status": "not_reviewed"
      },
      {
        "evidence": "",
        "id": "daemon_exposure",
        "notes": "",
        "reviewer": "",
        "severity_if_failed": "high",
        "status": "not_reviewed"
      }
    ]
  },
  "security_packet_sha256": "",
  "status": "not_started",
  "version": 1
}