Repository navigation
Releases: plantsweb3/bunker
Release list
Bunker 0.1.0 — public review release
Bunker's public review release combines the updated Bunker identity, responsive website, Wallet Standard connection, interactive demo, and an experimental hash-authorized Solana program supporting SOL and classic SPL assets.
The website at https://bunkermode.io is mainnet read-only. Real-fund custody remains disabled pending independent cryptographic and program review, remediation, and verified deployment. There is no mainnet Bunker program, completed audit, or end-to-end post-quantum security claim.
Review the threat model, cryptographic construction and provenance, and reviewer guide. One-time state rollback, stale backups, multi-device use, browser compromise, and pending-authorization liveness are explicit production blockers.
Validation on this release:
- 32 TypeScript unit tests and 20 upstream Rust tests passed.
- 19 on-chain checks passed against a fresh isolated local validator, covering SOL/classic SPL custody, tampering, replay, failed transfers, and authority rotation.
- 12 local desktop/mobile browser checks passed, including local custody and recovery; 10 read-only live-domain checks passed.
- Both GitHub CI jobs passed. CI's two local custody browser cases skip because its browser job has no validator; separately recorded local evidence covers them.
- Vercel deployed commit
66da5312c3bfc49bcc06f8662ddbd527d559a5e9. HTTPS, redirects, full-genesis pinning, nonce-based browser policy, and the public source manifest were verified.
Runtime npm advisory scan reported zero findings. One underlying high-severity denial-of-service advisory remains in the development-only braces/ESLint chain with no upstream patch at this check; the dependency policy documents its scope. No advisory was suppressed to obtain a clean result.
Tests and public source support independent inspection; they do not establish security or replace an audit. Report vulnerabilities privately through the repository's Security tab.