Skip to content

docs: rewrite the security review against v0.1.1 - #23

Merged
Zena-park merged 1 commit into
mainfrom
docs/security-review-v0.1.1
Aug 21, 2026
Merged

docs: rewrite the security review against v0.1.1#23
Zena-park merged 1 commit into
mainfrom
docs/security-review-v0.1.1

Conversation

@Zena-park

Copy link
Copy Markdown
Owner

Why

docs/security-review.md had grown by amendment since the pre-release review: fixes spliced into the paragraphs they touched, counts edited in place, and the 2026-08-21 audit and 2026-08-22 re-audit visible only as parentheticals. A reader could not tell what the current revision guarantees without reconstructing the history.

What

One record written against v0.1.1:

  • Header states the revision, verdict, and that this is an internal review, not an audit (matches SECURITY.md).
  • Findings by attack vector describe the v0.1.1 code only — including the EIP-3009 two-form surface, PendingAppointment, ValueNotAccepted, the typed deploy-script refusal, and a new Supply chain section (pins, lock:check, advisory canary, OZ 5.6.1 review).
  • Residual risks 1–5 kept; 6 added: the contract cannot see two addresses held by one organisation — that separation is operational (ADR-003).
  • Review history table replaces the scattered "a later pass found…" notes: pre-v0.1.0, 4f4b5c8 audit, a0bcad0 re-audit, v0.1.1.
  • Methodology updated (two passes, three adversarial lenses, dependency review).

No code changes. CHANGELOG Unreleased notes the rewrite.

🤖 Generated with Claude Code

The record had grown by amendment: a pre-release review with each later
fix spliced into the paragraph it touched, counts updated in place, and
the two audits visible only as parentheticals. Rewritten as one
description of what v0.1.1 guarantees, by attack vector, with a supply
chain section, a sixth residual risk (two keys in one custody is
operational, not enforceable), and the review history as a dated table.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Copilot AI lite review requested due to automatic review settings August 21, 2026 16:21

Copilot AI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot was unable to review this pull request because the user who requested the review has reached their quota limit.

@Zena-park
Zena-park merged commit c0bfbb2 into main Aug 21, 2026
3 checks passed
@Zena-park
Zena-park deleted the docs/security-review-v0.1.1 branch August 21, 2026 16:26
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants