Security fixes V3 — 71 findings (10 Critical, 20 High, 23 Medium, 18 Low) #39
No reviewers
Labels
No labels
prio_critical
prio_low
type_bug
type_contact
type_issue
type_lead
type_question
type_story
type_task
urgent
No milestone
No project
No assignees
1 participant
Notifications
Due date
No due date set.
Dependencies
No dependencies set.
Reference
lhumina_code/hero_ledger!39
Loading…
Add table
Add a link
Reference in a new issue
No description provided.
Delete branch "development_security_fixes_v3"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
Implements all security fixes from the SECURITY_AUDIT_V3.md full-codebase audit against development HEAD.
Changes
Testing
cargo checkpassescargo check --target wasm32-unknown-unknownpasses for all modified contractscargo test— 95 tests passCloses #38
CI Status ✅
build-and-testis green on both the branch and the PR.Implementation summary
All 71 findings from SECURITY_AUDIT_V3.md addressed across 6 commits:
d306236ccbc06aae4c31b75d59bb4a3ccf1Deferred items
Three items were attempted and reverted due to runner constraints or require separate migration work:
image@sha256:digestoraction@sharefs; digest values are preserved as comments in the workflow files for manual verificationX-Gateway-Nonceheader only (backward-compatible)Ready for review once WIP is removed.
WIP: Security fixes V3 — 71 findings (10 Critical, 20 High, 23 Medium, 18 Low)to Security fixes V3 — 71 findings (10 Critical, 20 High, 23 Medium, 18 Low)View command line instructions
Checkout
From your project repository, check out a new branch and test the changes.Merge
Merge the changes and update on Forgejo.Warning: The "Autodetect manual merge" setting is not enabled for this repository, you will have to mark this pull request as manually merged afterwards.