[Story] Decide independent security-review strategy (security_review)
Description
As a project lead
I want to have Gold's independent security review either performed or its absence consciously accepted
So that the hardest Gold MUST has an explicit, documented outcome instead of silent non-compliance
Gold requires code/design review by someone other than original authors. Realistic options: recruit Jefferson Lab collaborators, request OpenSSF/community audit, sponsor commercial review, or accept documented gap. Timebox the investigation; record decision in an ADR per repo conventions (website/docs/contributing/adrs/).
Acceptance Criteria
Technical Tasks
Related
Part of #699
[Story] Decide independent security-review strategy (security_review)
Description
As a project lead
I want to have Gold's independent security review either performed or its absence consciously accepted
So that the hardest Gold MUST has an explicit, documented outcome instead of silent non-compliance
Gold requires code/design review by someone other than original authors. Realistic options: recruit Jefferson Lab collaborators, request OpenSSF/community audit, sponsor commercial review, or accept documented gap. Timebox the investigation; record decision in an ADR per repo conventions (website/docs/contributing/adrs/).
Acceptance Criteria
security_reviewanswered. If deferred: gap documented as accepted risk.Technical Tasks
Related
Part of #699