Replies: 1 comment 2 replies
-
Considering to change the default language to "Any risk is acceptable unless it's High severity" as it unlikely protocols are okay with High severity. We don't want to introduce a foot gun. |
Beta Was this translation helpful? Give feedback.
2 replies
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Uh oh!
There was an error while loading. Please reload this page.
-
Description
Update: force protocols to define risks of known issues
Judging Guidelines PR
sherlock-protocol/sherlock-v2-docs#22
Rationale
A protocol team can acknowledge a specific issue but be unaware of all the risks.
For this reason, I propose to update the QA to let the protocol state the acceptable risks explicitly.
When risks are stated in the QA, and someone identifies a different risk. The report will be judged normally; it will not be discarded as a known issue.
If "Any risk is acceptable" or similar language is used, any reported risks regarding the known issue will be discarded.
Relevant Issue Discussions
sherlock-audit/2024-02-perpetual-judging#64
Beta Was this translation helpful? Give feedback.
All reactions