Skip to content

[Story]: Decide independent security-review strategy (security_review) #728

Description

@michaeldcanady

[Story] Decide independent security-review strategy (security_review)

Description

As a project lead
I want to have Gold's independent security review either performed or its absence consciously accepted
So that the hardest Gold MUST has an explicit, documented outcome instead of silent non-compliance

Gold requires code/design review by someone other than original authors. Realistic options: recruit Jefferson Lab collaborators, request OpenSSF/community audit, sponsor commercial review, or accept documented gap. Timebox the investigation; record decision in an ADR per repo conventions (website/docs/contributing/adrs/).

Acceptance Criteria

  • Options investigated with cost/feasibility notes in this issue.
  • Decision recorded as an ADR (index + sidebars updated per CLAUDE.md conventions).
  • If review happens: findings triaged and security_review answered. If deferred: gap documented as accepted risk.

Technical Tasks

  • Scope review surface (credentials/, core/, oauth2)
  • Get cost/commitments from candidate reviewers
  • ADR the decision

Related

Part of #699

Metadata

Metadata

Assignees

No one assigned

    Labels

    status: newNewly filed, not yet triaged by a maintainertype: spikeTime-boxed research or investigation

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions