forked from anza-xyz/agave
-
Notifications
You must be signed in to change notification settings - Fork 0
Commit
This commit does not belong to any branch on this repository, and may belong to a fork outside of the repository.
Update names and repos to x1 and tacyhon
- Loading branch information
Showing
29 changed files
with
103 additions
and
107 deletions.
There are no files selected for viewing
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Original file line number | Diff line number | Diff line change |
---|---|---|
@@ -1 +1 @@ | ||
* @anza-xyz/backport-reviewers | ||
* @x1-xyz/backport-reviewers |
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Original file line number | Diff line number | Diff line change |
---|---|---|
|
@@ -5,11 +5,11 @@ | |
2. [Incident Response Process](#process) | ||
|
||
<a name="reporting"></a> | ||
## Reporting security problems in the Agave Validator | ||
## Reporting security problems in the Tachyon Validator | ||
|
||
**DO NOT CREATE A GITHUB ISSUE** to report a security problem. | ||
|
||
Instead please use this [Report a Vulnerability](https://github.com/anza-xyz/agave/security/advisories/new) link. | ||
Instead please use this [Report a Vulnerability](https://github.com/x1-labs/tachyon/security/advisories/new) link. | ||
Provide a helpful title, detailed description of the vulnerability and an exploit | ||
proof-of-concept. Speculative submissions without proof-of-concept will be closed | ||
with no further consideration. | ||
|
@@ -25,15 +25,10 @@ Expect a response as fast as possible in the advisory, typically within 72 hours | |
-- | ||
|
||
If you do not receive a response in the advisory, send an email to | ||
security@anza.xyz with the full URL of the advisory you have created. DO NOT | ||
security@x1.xyz with the full URL of the advisory you have created. DO NOT | ||
include attachments or provide detail sufficient for exploitation regarding the | ||
security issue in this email. **Only provide such details in the advisory**. | ||
|
||
If you do not receive a response from [email protected] please followup with | ||
the team directly. You can do this in the `#core-technology` channel of the | ||
[Solana Tech discord server](https://solana.com/discord), by pinging the `Anza` | ||
role in the channel and referencing the fact that you submitted a security problem. | ||
|
||
<a name="process"></a> | ||
## Incident Response Process | ||
|
||
|
@@ -42,18 +37,18 @@ followed to contain, respond and remediate: | |
|
||
### 1. Accept the new report | ||
In response a newly reported security problem, a member of the | ||
`anza-xyz/admins` group will accept the report to turn it into a draft | ||
advisory. The `anza-xyz/security-incident-response` group should be added to | ||
`x1-xyz/admins` group will accept the report to turn it into a draft | ||
advisory. The `x1-xyz/security-incident-response` group should be added to | ||
the draft security advisory, and create a private fork of the repository (grey | ||
button towards the bottom of the page) if necessary. | ||
|
||
If the advisory is the result of an audit finding, follow the same process as above but add the auditor's github user(s) and begin the title with "[Audit]". | ||
|
||
If the report is out of scope, a member of the `anza-xyz/admins` group will | ||
If the report is out of scope, a member of the `x1-xyz/admins` group will | ||
comment as such and then close the report. | ||
|
||
### 2. Triage | ||
Within the draft security advisory, discuss and determine the severity of the issue. If necessary, members of the anza-xyz/security-incident-response group may add other github users to the advisory to assist. | ||
Within the draft security advisory, discuss and determine the severity of the issue. If necessary, members of the x1-xyz/security-incident-response group may add other github users to the advisory to assist. | ||
If it is determined that this is not a critical network issue then the advisory should be closed and if more follow-up is required a normal Solana public github issue should be created. | ||
|
||
### 3. Prepare Fixes | ||
|
@@ -62,7 +57,7 @@ There is no CI available in the private repository so you must build from source | |
Code review from the reporter is ideal, as well as from multiple members of the core development team. | ||
|
||
### 4. Notify Security Group Validators | ||
Once an ETA is available for the fix, a member of the anza-xyz/security-incident-response group should notify the validators so they can prepare for an update using the "Solana Red Alert" notification system. | ||
Once an ETA is available for the fix, a member of the x1-xyz/security-incident-response group should notify the validators so they can prepare for an update using the "Solana Red Alert" notification system. | ||
The teams are all over the world and it's critical to provide actionable information at the right time. Don't be the person that wakes everybody up at 2am when a fix won't be available for hours. | ||
|
||
### 5. Ship the patch | ||
|
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Oops, something went wrong.