The document discusses provenance-based security audits applied to COVID-19 contact tracing apps, particularly the German 'Corona Warn App'. It details the methodology for extracting and analyzing provenance information from Git-based projects using various tools, and highlights the importance of external contributions in improving app security. The authors advocate for the application of their audit methodologies to similar public apps for enhanced security and insights.