Skip to content

Repository files navigation

📖 Read-only mirror. treasury is published from the canonical AI-Factory monorepo. Pull requests are not accepted — any commit pushed here is overwritten by scripts/mirror_satellites.sh on the next sync. 🐞 Found a bug or have a request? Please open an issue.

Treasury

CI Landing Pays MOMUS findings Python >=3.11 Docker ready Separation of duties License: MIT

MOMUS Treasury — the separate payer for red-team bounties.

MOMUS finds and Ed25519-signs findings. This service holds the only key that can release a bounty, and only after independent verification. Different container, different volume, different trust boundary.

Role Payout gate for MOMUS findings
Port :9401
Package aimarket-treasury
Landing alexar76.github.io/treasury
Sibling alexar76/momus

Run (monorepo)

# from monorepo root
docker build -f treasury/Dockerfile -t momus-treasury .
docker run --rm -p 9401:9401 -v treasury-keys:/keys momus-treasury

Standalone GitHub mirror vendors vendor/oracle-core and vendor/momus at publish time — see Dockerfile.standalone.

Why separate

If the auditor could pay itself, signed findings would not be a meaningful control. Treasury exists so that finding ≠ payment.

MIT · part of the AICOM / AIMarket ecosystem.

About

MOMUS Treasury — the separate payer role that releases red-team bounties only on independent verification; MOMUS finds and signs, the Treasury (its own key) pays.

Topics

Resources

Code of conduct

Contributing

Security policy

Stars

0 stars

Watchers

0 watching

Forks

Releases

Packages

Contributors

Languages