Skip to content

chore: add OtterSec audit report#39

Merged
dev-jodee merged 1 commit into
mainfrom
chore/add-ottersec-audit-report
Apr 24, 2026
Merged

chore: add OtterSec audit report#39
dev-jodee merged 1 commit into
mainfrom
chore/add-ottersec-audit-report

Conversation

@dev-jodee
Copy link
Copy Markdown
Collaborator

Summary

Findings

All 8 findings resolved and re-reviewed as RESOLVED by OtterSec:

ID Severity PR
OS-SPR-ADV-00 HIGH #33
OS-SPR-ADV-01 MEDIUM #32
OS-SPR-ADV-02 MEDIUM #34
OS-SPR-ADV-03 LOW #32
OS-SPR-ADV-04 LOW #37
OS-SPR-ADV-05 LOW #35
OS-SPR-SUG-00 INFO #32
OS-SPR-SUG-01 INFO #36

Test Plan

  • Open the PDF from the PR to confirm it renders.
  • Click through the links from README.md (audit report + AUDIT_STATUS.md) and confirm they resolve on GitHub.
  • Run git rev-list --count aa1cfd9276375e44e57d1917d110ff095fb6d475..main — equals the post-audit commit count.

Mirrors the escrow precedent: solana-program/escrow@b4f85ed

Add the OtterSec security assessment (2026-04-24) covering the
rewards program at commit d795849. All 8 findings were resolved
in PRs #32-#37 and marked as such in the report.

Track the audited-through commit and unaudited delta in
audits/AUDIT_STATUS.md. Drop the "not audited" notice from the
README and add a Security Audit section linking the report.
@dev-jodee dev-jodee requested a review from amilz April 24, 2026 17:31
@dev-jodee dev-jodee merged commit 13773bf into main Apr 24, 2026
7 checks passed
@dev-jodee dev-jodee deleted the chore/add-ottersec-audit-report branch April 24, 2026 17:38
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants