Skip to content

add audit reports - #28

Open
kaze-cow wants to merge 2 commits into
masterfrom
audits
Open

add audit reports#28
kaze-cow wants to merge 2 commits into
masterfrom
audits

Conversation

@kaze-cow

Copy link
Copy Markdown
Collaborator

Description

Publish the audit reports to the repository.

Testing Instructions

Verify that the PDFs correspond to those shared internally.

@kaze-cow
kaze-cow requested a review from a team April 10, 2026 09:05
@kaze-cow kaze-cow self-assigned this Apr 10, 2026

@fedgiac fedgiac left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

The Spearbit one is still marked as a draft. Can you replace it with the final version?

For the Yaudit audit, it would be nice if they could state that all vulnerability have been addressed by commit bfed0b2, can we ask them to add this? Ideally something similar to what the Spearbit one does in "Security Review Summary" with the commit hashes.

@anxolin anxolin left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Caze spearbit is still a DRAFT. Can you update with the latest?
Also, should it show clearly the commit that has the ✅ check from them?
It shows the commit they audited, and then the commits of fixing the issues. I would think they need to specify the commit they consider audited and good to go?

@kaze-cow

Copy link
Copy Markdown
Collaborator Author

I would think they need to specify the commit they consider audited and good to go?

I have never actually seen this on any report for contracts I have created, and I actually don't think it would make much sense personally. Most serious security people would probably wouldn't consider the exact commit that the changes are comprehensively marked as resolved as kind of irrelevant because new changes could be introduced later/after the (not saying thats the case in our project, but its a thing). Really I think the value in putting commit hashes down is just in showing the way that the particular issue was resolved, and hopefully being able to track that the results of those changes still exist in the production release. Cantina putting a message in the report that says "this is the commit we consider safe to use after audit" would be like saying that commit and anything following gets our stamp of approval.

@kaze-cow

Copy link
Copy Markdown
Collaborator Author

The Spearbit one is still marked as a draft. Can you replace it with the final version?

Resolved

For the Yaudit audit, it would be nice if they could state that all vulnerability have been addressed by commit bfed0b2, can we ask them to add this? Ideally something similar to what the Spearbit one does in "Security Review Summary" with the commit hashes.

I pinged yaudit about this.

@kaze-cow
kaze-cow requested a review from anxolin May 18, 2026 07:27
@anxolin

anxolin commented May 26, 2026

Copy link
Copy Markdown
Contributor

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants