Skip to content

Fix 0.24 audit blockers - #6

Closed
a19q3 wants to merge 1 commit into
nightly-0.24from
codex/0.24-audit-fixes
Closed

Fix 0.24 audit blockers#6
a19q3 wants to merge 1 commit into
nightly-0.24from
codex/0.24-audit-fixes

Conversation

@a19q3

@a19q3 a19q3 commented Aug 17, 2026

Copy link
Copy Markdown
Collaborator

Summary

  • close all six validated security findings from the 0.24 branch audit: Git ref option injection, transitive resolver command execution, Registry snapshot SSRF, Type-hash LS-IDL ambiguity, unbounded Registry metadata, and internal error disclosure
  • align the workspace, Registry contract/artifact identity, NovaSeal pin, and VS Code extension with the 0.24 release line
  • propagate explicit CKB checkout selection through backend/release tooling and restore the warnings-denied Clippy gate

Verification

  • ./scripts/cellscript_gate.sh dev
  • ./scripts/cellscript_gate.sh ci
  • CELLSCRIPT_CKB_REPO=<pinned-ckb> ./scripts/cellscript_gate.sh backend
  • focused package exploit regressions and Registry API tests
  • VS Code npm run validate
  • tooling release-boundary validator

The clean-tree backend run includes the full strict backend audit and stateful CKB production scenarios. release / release-quick were not run and remain required before production claims.

@a19q3 a19q3 closed this Aug 24, 2026
@a19q3
a19q3 deleted the codex/0.24-audit-fixes branch August 24, 2026 03:03
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant