Conversation
fedgiac
left a comment
There was a problem hiding this comment.
The Spearbit one is still marked as a draft. Can you replace it with the final version?
For the Yaudit audit, it would be nice if they could state that all vulnerability have been addressed by commit bfed0b2, can we ask them to add this? Ideally something similar to what the Spearbit one does in "Security Review Summary" with the commit hashes.
anxolin
left a comment
There was a problem hiding this comment.
Caze spearbit is still a DRAFT. Can you update with the latest?
Also, should it show clearly the commit that has the ✅ check from them?
It shows the commit they audited, and then the commits of fixing the issues. I would think they need to specify the commit they consider audited and good to go?
I have never actually seen this on any report for contracts I have created, and I actually don't think it would make much sense personally. Most serious security people would probably wouldn't consider the exact commit that the changes are comprehensively marked as resolved as kind of irrelevant because new changes could be introduced later/after the (not saying thats the case in our project, but its a thing). Really I think the value in putting commit hashes down is just in showing the way that the particular issue was resolved, and hopefully being able to track that the results of those changes still exist in the production release. Cantina putting a message in the report that says "this is the commit we consider safe to use after audit" would be like saying that commit and anything following gets our stamp of approval. |
Resolved
I pinged yaudit about this. |
|
@kaze-cow I believe u got the response. Should we merge this? https://nomevlabs.slack.com/archives/C09NJE3DXMW/p1779470407966289?thread_ts=1779089202.522989&cid=C09NJE3DXMW |
Description
Publish the audit reports to the repository.
Testing Instructions
Verify that the PDFs correspond to those shared internally.