Skip to content

refactor: addressing audit 8 and 9#15

Merged
kupermind merged 5 commits into
mainfrom
post-audit
May 14, 2026
Merged

refactor: addressing audit 8 and 9#15
kupermind merged 5 commits into
mainfrom
post-audit

Conversation

@kupermind

Copy link
Copy Markdown
Contributor
  • Addressing audit 8 and 9.

@kupermind kupermind requested a review from 77ph March 23, 2026 19:23
kupermind and others added 4 commits March 23, 2026 19:39
Review of fixes from audits 8 and 9 applied in post-audit branch.
5 contracts, 7 fixes verified. All correct, no new vulnerabilities.

Key fixes:
- Depository: msg.sender → sender refund (Low)
- Distributor: reset dangling approval (Low)
- Treasury: ETH value forwarding to bridge calls (Medium)
- DefaultDepositProcessorL1: drain() removed (Low)
- ExternalStakingDistributor: per-service curating agent access (Medium)

Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
…S.md

Extract the pending re-deployment list out of CLAUDE.md into a dedicated
MODIFIED_CONTRACTS.md, referenced from both CLAUDE.md and the main README.
Also adds the previously-missing Depository.sol refund fix to the list.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
@kupermind kupermind merged commit 019b21e into main May 14, 2026
1 check passed
@kupermind kupermind deleted the post-audit branch May 14, 2026 11:11
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants