Skip to content

Releases: plantsweb3/bunker

Bunker 0.1.0 — public review release

Pre-release

Choose a tag to compare

@plantsweb3 plantsweb3 released this 07 Oct 20:21

Bunker's public review release combines the updated Bunker identity, responsive website, Wallet Standard connection, interactive demo, and an experimental hash-authorized Solana program supporting SOL and classic SPL assets.

The website at https://bunkermode.io is mainnet read-only. Real-fund custody remains disabled pending independent cryptographic and program review, remediation, and verified deployment. There is no mainnet Bunker program, completed audit, or end-to-end post-quantum security claim.

Review the threat model, cryptographic construction and provenance, and reviewer guide. One-time state rollback, stale backups, multi-device use, browser compromise, and pending-authorization liveness are explicit production blockers.

Validation on this release:

  • 32 TypeScript unit tests and 20 upstream Rust tests passed.
  • 19 on-chain checks passed against a fresh isolated local validator, covering SOL/classic SPL custody, tampering, replay, failed transfers, and authority rotation.
  • 12 local desktop/mobile browser checks passed, including local custody and recovery; 10 read-only live-domain checks passed.
  • Both GitHub CI jobs passed. CI's two local custody browser cases skip because its browser job has no validator; separately recorded local evidence covers them.
  • Vercel deployed commit 66da5312c3bfc49bcc06f8662ddbd527d559a5e9. HTTPS, redirects, full-genesis pinning, nonce-based browser policy, and the public source manifest were verified.

Runtime npm advisory scan reported zero findings. One underlying high-severity denial-of-service advisory remains in the development-only braces/ESLint chain with no upstream patch at this check; the dependency policy documents its scope. No advisory was suppressed to obtain a clean result.

Tests and public source support independent inspection; they do not establish security or replace an audit. Report vulnerabilities privately through the repository's Security tab.