Audit firms and contests — who signs off, and what a signature means
Trail of Bits, OpenZeppelin and competitive-audit platforms all produce a report, but a passed audit is a snapshot under a scope, not a proof of safety — the same preview-means-no-promise reading.
Not yet scoped.
Why
The PoC compares a firm audit and a contest audit on scope, incentives and what each actually guarantees, treating 'audited' as a claim to be read, not a badge.
How it works
Not yet built.
Where it lands in Jayverse
Auditor: record every Jayverse audit as a scoped snapshot — firm or contest, scope, date, and exact commit hash — not a badge. An "audited" claim without those four fields is not checkable, and this row is exactly where the fields belong before any contract carries real value.
Bridge/CI: pin the audited commit in CI so a passing audit stays tied to a frozen state. OpenZeppelin is already pinned as submodules; extend that discipline to the bridge's own lock-and-mint contracts so a later dependency bump can't silently invalidate what was actually reviewed.
Key expressions
Words and phrases from this page worth keeping, with the Korean meaning and the sentence they come from.
Expression
뜻 · 쓰이는 자리
sign off
승인 서명을 하다, 최종 확인하다 · 감사 보고서에 누가 도장을 찍는지 말할 때. "who signs off, and what a signature means"
snapshot under a scope
특정 범위 안에서만 찍은 스냅샷 · 감사가 전체 안전을 보장하지 않는다는 뜻. "a snapshot under a scope, not a proof of safety"
badge
실질적 보증 없는 장식적 인증 표시 · '감사 완료'를 그대로 믿지 말라는 뜻. "as a claim to be read, not a badge"
guarantee
보장하다, 보증하다 · 각 감사 방식이 실제로 무엇을 확실히 해주는지. "what each actually guarantees"
Trail of Bits
스마트컨트랙트 보안 감사 전문 회사(Trail of Bits) · 이 카드에서 비교 대상인 대표적 감사 펌. "Trail of Bits, OpenZeppelin and competitive-audit platforms all produce a report"
OpenZeppelin
스마트컨트랙트 라이브러리·보안 감사로 유명한 회사(OpenZeppelin) · 감사 보고서를 발행하는 대표 펌으로 언급. "Trail of Bits, OpenZeppelin and competitive-audit platforms all produce a report"
Trail of Bits, OpenZeppelin, 경쟁 감사 플랫폼은 모두 리포트를 내지만, 통과한 감사는 범위 아래의 스냅샷이지 안전의 증명이 아닙니다 — 같은 preview-means-no-promise 독법입니다.
아직 범위 미정.
왜
이 PoC는 회사 감사와 대회 감사를 범위·인센티브·각자가 실제로 보장하는 것으로 비교하여, '감사됨'을 배지가 아니라 읽어야 할 주장으로 다룹니다.
동작 방식
아직 만들지 않음.
Jayverse에서의 위치
Auditor: Jayverse의 모든 감사를 배지가 아니라 범위가 정해진 스냅샷으로 기록한다 — 수행 기관/콘테스트, 범위, 날짜, 정확한 커밋 해시. 이 네 항목 없는 "감사됨" 주장은 검증할 수 없다. 어떤 컨트랙트든 실제 가치를 담기 전에 이 필드들이 있어야 할 곳이 바로 이 행이다.
Bridge/CI: 감사받은 커밋을 CI에 고정해 통과한 감사가 동결된 상태에 묶이게 한다. OpenZeppelin은 이미 서브모듈로 고정돼 있다. 이후 의존성 업데이트가 실제로 검토된 내용을 조용히 무효화하지 않도록 브릿지 자체의 lock-and-mint 컨트랙트에도 같은 규율을 확장한다.
핵심 표현
이 페이지의 영어 본문에서 배울 만한 단어와 표현, 뜻과 나온 자리.
Expression
뜻 · 쓰이는 자리
sign off
승인 서명을 하다, 최종 확인하다 · 감사 보고서에 누가 도장을 찍는지 말할 때. "who signs off, and what a signature means"
snapshot under a scope
특정 범위 안에서만 찍은 스냅샷 · 감사가 전체 안전을 보장하지 않는다는 뜻. "a snapshot under a scope, not a proof of safety"
badge
실질적 보증 없는 장식적 인증 표시 · '감사 완료'를 그대로 믿지 말라는 뜻. "as a claim to be read, not a badge"
guarantee
보장하다, 보증하다 · 각 감사 방식이 실제로 무엇을 확실히 해주는지. "what each actually guarantees"
Trail of Bits
스마트컨트랙트 보안 감사 전문 회사(Trail of Bits) · 이 카드에서 비교 대상인 대표적 감사 펌. "Trail of Bits, OpenZeppelin and competitive-audit platforms all produce a report"
OpenZeppelin
스마트컨트랙트 라이브러리·보안 감사로 유명한 회사(OpenZeppelin) · 감사 보고서를 발행하는 대표 펌으로 언급. "Trail of Bits, OpenZeppelin and competitive-audit platforms all produce a report"