Skip to content

docs: add /audits directory and security contact (MEN-46)#717

Closed
mento-val wants to merge 3 commits intodevelopfrom
qa/audits-security-contact-men46
Closed

docs: add /audits directory and security contact (MEN-46)#717
mento-val wants to merge 3 commits intodevelopfrom
qa/audits-security-contact-men46

Conversation

@mento-val
Copy link
Copy Markdown

Summary

Addresses MEN-46 from the mento-core QA audit security posture review (P2-8).

  • Creates /audits/README.md with an audit report index, scope description, and vulnerability reporting instructions
  • Adds a Security section to README.md linking to the audits directory and providing security@mento.org contact

Changes

  • audits/README.md (new): Placeholder audit index with table for future reports, protocol scope, and responsible disclosure instructions
  • README.md: New Security section with audit link, contact email, and bug bounty placeholder

Acceptance Criteria

  • /audits/README.md created
  • README.md has a Security section with contact info
  • PR opened on mento-protocol/mento-core

Closes MEN-46

mento-val and others added 3 commits March 12, 2026 07:25
Covers all 5 required subsections:
1. System overview — multi-currency stablecoin and FX infrastructure
2. Contract subsystems — Broker/Exchange Providers, Oracle/Relayers,
   Tokens, Governance (TimelockController/GovernanceFactory), Reserve
3. Key interaction flows — swap, oracle update, governance proposal
4. Upgradeability notes — Celo Proxy vs OZ Transparent vs non-upgradeable
5. Entry points — where to start reading by focus area

Source: mento-core QA audit P2-9 (MEN-42)

Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
…(MEN-42)

Documents system overview, all 6 contract subsystems (Broker/Exchange Providers,
Oracle/Relayers, Tokens, Governance, Reserve, Liquidity Strategies), key
interaction flows (swap, oracle update, governance proposal), proxy upgradeability
patterns, and recommended code entry points for new contributors and auditors.

Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
@mento-val mento-val requested review from a team, Andrew718PLTS and chapati23 March 12, 2026 09:40
@mento-val
Copy link
Copy Markdown
Author

Closing this PR as part of a workflow change. Going forward, all PRs must be submitted through the fork-based review process: branches are pushed to mento-val's personal forks, reviewed by the Engineering Manager, and then the EM opens the upstream PR. This work is valid and will be re-submitted through the proper workflow once Val's fork remotes are configured. See Paperclip issue MEN-61 for context.

@mento-val mento-val closed this Mar 16, 2026
@bayological bayological deleted the qa/audits-security-contact-men46 branch March 27, 2026 17:49
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant