docs: record the pre-1.0 security review in TODO.md (closes #383)
check / check (push) Waiting to run
e2e / e2e-chrome (push) Waiting to run
e2e / e2e-firefox (push) Waiting to run

The security review moves from Next Step to Completed Steps, saying what it
read (the tree at 99292b9), that its ten findings are filed and fixed on next,
which owner decisions it raised are still open, and what it did not cover.
Next Step takes the one Future Steps item, cutting 1.0.0 once the milestone is
empty. Status drops a dated gate result and links the current milestone PR.

Model: opus-5-5
This commit was merged in pull request #497.
This commit is contained in:
2026-10-07 09:43:07 +02:00
parent e3dd0e44da
commit 29ba54d5b6
+31 -14
View File
@@ -23,28 +23,48 @@
pre-1.0, working towards the 1.0.0 milestone. Tagged v0.1.0 on 2026-02-27. The pre-1.0, working towards the 1.0.0 milestone. Tagged v0.1.0 on 2026-02-27. The
milestone is in flight on `next`; its `next` -> `main` PR is milestone is in flight on `next`; its `next` -> `main` PR is
[#190](https://git.eeqj.de/sneak/AutistMask/pulls/190). `make check` verified [#388](https://git.eeqj.de/sneak/AutistMask/pulls/388). `make build` produces
green on `next` at `e9fa8be` on 2026-08-10, and `make build` produces `dist/chrome/` and `dist/firefox/` with `DEBUG` compiled off, and checks them
`dist/chrome/` and `dist/firefox/`, verified against the build's own receipt to against the build's own receipt to hold exactly the regular files and symlinks
hold exactly the regular files and symlinks that build emitted, with `DEBUG` that build emitted.
compiled off.
The backlog lives on the The backlog lives on the
[Gitea tracker](https://git.eeqj.de/sneak/AutistMask/issues), which is [Gitea tracker](https://git.eeqj.de/sneak/AutistMask/issues), which is
authoritative; this file does not duplicate it. Full policy file set present. authoritative; this file does not duplicate it. Full policy file set present.
Real-browser end-to-end suites (`make test-e2e` for Chrome, Real-browser end-to-end suites (`make test-e2e` for Chrome,
`make test-e2e-firefox` for Firefox) sit alongside `make check`, which now does `make test-e2e-firefox` for Firefox) sit alongside `make check`, which runs the
static analysis as well as formatting, and `.gitea/workflows/e2e.yml` runs both tests, static analysis and the formatting check, and `.gitea/workflows/e2e.yml`
of them on every push. runs both of them on every push.
# Next Step # Next Step
Pre-1.0 security review of the extension (key handling, DEBUG mode policy, RPC Cut 1.0.0 once the
input validation) before any 1.0rc tag. Individual filed issues are parts of it, [1.0.0 milestone](https://git.eeqj.de/sneak/AutistMask/milestone/6) is empty,
but the review is broader than any of them. then continue tagging as milestones land.
# Completed Steps # Completed Steps
- 2026-10-07: Pre-1.0 security review of the extension
([#383](https://git.eeqj.de/sneak/AutistMask/issues/383)), reading the tree at
`99292b9` for key handling, the DEBUG mode policy, and what the background
accepts from pages, the configured RPC endpoint and the explorer, with what
the approval screens show from it; the site permission model and storage were
read as well. Its summary on that issue lists ten findings, each filed as its
own issue, and all ten are fixed on `next`; one,
[#399](https://git.eeqj.de/sneak/AutistMask/issues/399), put funds at risk.
Three decisions it raised are still open with the owner: the Argon2id cost for
the vault key ([#401](https://git.eeqj.de/sneak/AutistMask/issues/401)), a
connected site switching the network with no prompt
([#408](https://git.eeqj.de/sneak/AutistMask/issues/408)), and `eth_sign`
signing as a personal message
([#409](https://git.eeqj.de/sneak/AutistMask/issues/409)). Not covered: the
end-to-end suites were not run, the bundled phishing blocklist and token list
were not checked entry by entry, `ethers` and `libsodium-wrappers-sumo` were
taken as audited, and nothing was tried against a real network with real funds
([#385](https://git.eeqj.de/sneak/AutistMask/issues/385)). The planned
independent second check of each finding did not run; the findings rest on the
reviewer's own reading of the code.
- 2026-10-07: Stale branches pruned from `origin` - 2026-10-07: Stale branches pruned from `origin`
([#167](https://git.eeqj.de/sneak/AutistMask/issues/167)). The issue ([#167](https://git.eeqj.de/sneak/AutistMask/issues/167)). The issue
classifies each branch it lists, with the evidence. The eighteen still on classifies each branch it lists, with the evidence. The eighteen still on
@@ -1887,6 +1907,3 @@ but the review is broader than any of them.
Only work that has no issue of its own belongs here; everything else is on the Only work that has no issue of its own belongs here; everything else is on the
tracker. tracker.
- Cut 1.0.0 once the milestone is empty, then continue tagging as milestones
land.