Coder Social home page Coder Social logo

audits's People

Contributors

codingshot avatar dongcool avatar giovannifranchi avatar heroes-bounty[bot] avatar nearbuild avatar rajaauditone avatar stephensj2 avatar swaroop-osec avatar timurguvenkaya avatar

Stargazers

 avatar  avatar  avatar  avatar  avatar  avatar  avatar

Watchers

 avatar  avatar

audits's Issues

add electron bridge vulnerabilities

Garvit | Electron
Posting this thread to address the security concerns raised on Electron Bridge.

1/3
Yes, we are aware of the issue, and we had taken necessary precautions to mitigate this before the launch of the bridge itself. This vulnerability is not exploitable on the bridge right now.

https://twitter.com/garvitgoel03/status/1670351793870761985?s=46&t=w1K-2akWm132Lj7mGi5p2g

Maksym Zavershynskyi (nearmax.near) โ‹ˆ
@weikengchen @nearprotocol @labs_electron That's why @NEARDevHub is looking to publicly audit these circuits and determine the next course of actions https://t.co/dhh6K0r4Qw . To clarify, @wormholecrypto 's NEAR<>ETH ZK bridge is based on entirely different circuits developed by @ZpokenWeb3 .

https://twitter.com/mzavershynskyi/status/1670197415994101760?s=46&t=w1K-2akWm132Lj7mGi5p2g

Weikeng Chen
"Electron Labs' bridge between NEAR and Ethereum is vulnerable. Zk circuits used for the NEAR light client are incomplete and severely under-constrained. It is possible to create valid proofs for invalid set of signatures. User funds are at risk!" @nearprotocol? @labs_electron?

https://twitter.com/weikengchen/status/1670163273759735808?s=46&t=w1K-2akWm132Lj7mGi5p2g

https://twitter.com/rahul__ghangas/status/1666366824395739136?s=46&t=w1K-2akWm132Lj7mGi5p2g

added contribution markdown file

example and reference in readme instead of putting in main readme as PR Best Pracice

Contribution Guidelines

We welcome all types of contributions to our project, including but not limited to:

  • Suggesting new reference techniques which prioritize smart contract vulnerability detection.
  • Adding exploits or slips up and firms that slipped up with reference to their initial audit
  • Adding active or (marking old bug programs as deactive)
  • Adding additional audits (make sure to reference original audit in table but also upload the pdf of the audit to the Audit folder with the following naming convention YEAR-MONTH-DAY-FIRM-SCOPE-OF-AUDIT.pdf
    Adding additional security firms (note only add the firm from now on if you have also provided an audit firm in the same PR
    Fixing typos and streamlining the categorization process
  • Adding additional NEAR Security resources
    -Add more projects that you are asking for audits to
  • End to End testing and Appsec reports
    Suggesting improvements to the classification standard
    Correcting mislabeled bug and exploits or descrbing an audit more cleary (For ex; HERE Wallet -> HERE Wallet liquid staking)
  • Improvements to contribution guidelines

Format

  • Make a PR and make sure to # the close the issue number if relevant

Thank you for your contributions!

add a folder of audits

with naming convention
year-month-day-firmname-nameofcontractedit.pdf

add this to readme

Recommend Projects

  • React photo React

    A declarative, efficient, and flexible JavaScript library for building user interfaces.

  • Vue.js photo Vue.js

    ๐Ÿ–– Vue.js is a progressive, incrementally-adoptable JavaScript framework for building UI on the web.

  • Typescript photo Typescript

    TypeScript is a superset of JavaScript that compiles to clean JavaScript output.

  • TensorFlow photo TensorFlow

    An Open Source Machine Learning Framework for Everyone

  • Django photo Django

    The Web framework for perfectionists with deadlines.

  • D3 photo D3

    Bring data to life with SVG, Canvas and HTML. ๐Ÿ“Š๐Ÿ“ˆ๐ŸŽ‰

Recommend Topics

  • javascript

    JavaScript (JS) is a lightweight interpreted programming language with first-class functions.

  • web

    Some thing interesting about web. New door for the world.

  • server

    A server is a program made to process requests and deliver data to clients.

  • Machine learning

    Machine learning is a way of modeling and interpreting data that allows a piece of software to respond intelligently.

  • Game

    Some thing interesting about game, make everyone happy.

Recommend Org

  • Facebook photo Facebook

    We are working to build community through open source technology. NB: members must have two-factor auth.

  • Microsoft photo Microsoft

    Open source projects and samples from Microsoft.

  • Google photo Google

    Google โค๏ธ Open Source for everyone.

  • D3 photo D3

    Data-Driven Documents codes.