docs: record the pre-1.0 security review in TODO.md #497
@@ -23,28 +23,48 @@
|
||||
|
||||
pre-1.0, working towards the 1.0.0 milestone. Tagged v0.1.0 on 2026-02-27. The
|
||||
milestone is in flight on `next`; its `next` -> `main` PR is
|
||||
[#190](https://git.eeqj.de/sneak/AutistMask/pulls/190). `make check` verified
|
||||
green on `next` at `e9fa8be` on 2026-08-10, and `make build` produces
|
||||
`dist/chrome/` and `dist/firefox/`, verified against the build's own receipt to
|
||||
hold exactly the regular files and symlinks that build emitted, with `DEBUG`
|
||||
compiled off.
|
||||
[#388](https://git.eeqj.de/sneak/AutistMask/pulls/388). `make build` produces
|
||||
`dist/chrome/` and `dist/firefox/` with `DEBUG` compiled off, and checks them
|
||||
against the build's own receipt to hold exactly the regular files and symlinks
|
||||
that build emitted.
|
||||
|
||||
The backlog lives on the
|
||||
[Gitea tracker](https://git.eeqj.de/sneak/AutistMask/issues), which is
|
||||
authoritative; this file does not duplicate it. Full policy file set present.
|
||||
Real-browser end-to-end suites (`make test-e2e` for Chrome,
|
||||
`make test-e2e-firefox` for Firefox) sit alongside `make check`, which now does
|
||||
static analysis as well as formatting, and `.gitea/workflows/e2e.yml` runs both
|
||||
of them on every push.
|
||||
`make test-e2e-firefox` for Firefox) sit alongside `make check`, which runs the
|
||||
tests, static analysis and the formatting check, and `.gitea/workflows/e2e.yml`
|
||||
runs both of them on every push.
|
||||
|
||||
# Next Step
|
||||
|
||||
Pre-1.0 security review of the extension (key handling, DEBUG mode policy, RPC
|
||||
input validation) before any 1.0rc tag. Individual filed issues are parts of it,
|
||||
but the review is broader than any of them.
|
||||
Cut 1.0.0 once the
|
||||
[1.0.0 milestone](https://git.eeqj.de/sneak/AutistMask/milestone/6) is empty,
|
||||
then continue tagging as milestones land.
|
||||
|
||||
# Completed Steps
|
||||
|
||||
- 2026-10-07: Pre-1.0 security review of the extension
|
||||
([#383](https://git.eeqj.de/sneak/AutistMask/issues/383)), reading the tree at
|
||||
`99292b9` for key handling, the DEBUG mode policy, and what the background
|
||||
accepts from pages, the configured RPC endpoint and the explorer, with what
|
||||
the approval screens show from it; the site permission model and storage were
|
||||
read as well. Its summary on that issue lists ten findings, each filed as its
|
||||
own issue, and all ten are fixed on `next`; one,
|
||||
[#399](https://git.eeqj.de/sneak/AutistMask/issues/399), put funds at risk.
|
||||
Three decisions it raised are still open with the owner: the Argon2id cost for
|
||||
the vault key ([#401](https://git.eeqj.de/sneak/AutistMask/issues/401)), a
|
||||
connected site switching the network with no prompt
|
||||
([#408](https://git.eeqj.de/sneak/AutistMask/issues/408)), and `eth_sign`
|
||||
signing as a personal message
|
||||
([#409](https://git.eeqj.de/sneak/AutistMask/issues/409)). Not covered: the
|
||||
end-to-end suites were not run, the bundled phishing blocklist and token list
|
||||
were not checked entry by entry, `ethers` and `libsodium-wrappers-sumo` were
|
||||
taken as audited, and nothing was tried against a real network with real funds
|
||||
([#385](https://git.eeqj.de/sneak/AutistMask/issues/385)). The planned
|
||||
independent second check of each finding did not run; the findings rest on the
|
||||
reviewer's own reading of the code.
|
||||
|
||||
- 2026-10-07: Stale branches pruned from `origin`
|
||||
([#167](https://git.eeqj.de/sneak/AutistMask/issues/167)). The issue
|
||||
classifies each branch it lists, with the evidence. The eighteen still on
|
||||
@@ -1887,6 +1907,3 @@ but the review is broader than any of them.
|
||||
|
||||
Only work that has no issue of its own belongs here; everything else is on the
|
||||
tracker.
|
||||
|
||||
- Cut 1.0.0 once the milestone is empty, then continue tagging as milestones
|
||||
land.
|
||||
|
||||
Reference in New Issue
Block a user