Context
There exists a lack of Open Source security tooling that allow for Solana developers to alleviate their programs from a wide range of vulnerabilities. Open Source Formal Verification and Symbolic Analysis tooling, Fuzzing Frameworks and other technologies can better assist program developers in the journey of securing their programs before deployment or upgrades.
Please see the following RFP that outlines a request to create repeatable program analysis tooling. The Solana Foundation lays out a list of proposed solutions, but the technology used to secure programs is at the behest of the applicant.
Logistics
Take note of the application deadline (2/29/2024). The maximum grant amount is not included within the request as different security applications will have varying cost factors. The resulting finalist(s) will work with the Solana Foundation to receive an appropriate grant issued in USD-equivalent locked SOL with approachable, but rigorous milestones.
Ground Rules
This thread can be used for comments, questions, praise, and / or criticism, and is intended to be an open forum for any prospective responders. This thread is also an experiment in increasing the transparency through which RFPs are fielded by the Solana ecosystem too, so please be mindful that we’re all here to learn and grow.
Responses to this RFP are not required to be public (but recommended), but if it is helpful to share notes or combine forces, then please use this thread for such purposes