Skip to content

docs: publish security review and remediation for contract sandbox escape - #154

Merged
SIDDHANTCOOKIE merged 1 commit into
mainfrom
docs/publish-sandbox-escape-security-review
Sep 28, 2026
Merged

SIDDHANTCOOKIE merged 1 commit into
mainfrom
docs/publish-sandbox-escape-security-review

Conversation

@SIDDHANTCOOKIE

Copy link
Copy Markdown
Member

Summary

Test plan

  • Documentation only, no code changes.
  • Confirmed unremediated-security-reviews/ no longer contains either file after the move.

…cape

Finding 1 (sandbox escape via str.format() attribute traversal, Critical)
is fully remediated by commit 3ca9596 / PR #152, now merged into main.
Moving the review and its remediation report out of the private,
gitignored unremediated-security-reviews/ folder into the public,
tracked security-reviews/ folder per the security-remediation workflow.
@github-actions

Copy link
Copy Markdown

Coverage

Coverage Report
FileStmtsMissCoverMissing
minichain
   __init__.py100100% 
   block.py92199%14
   chain.py2273983%182–185, 195–196, 205–206, 209–210, 214–215, 234, 258, 266–274, 283–284, 286–287, 310–313, 316–325, 335–336
   contract.py1713281%39–42, 74–84, 89–93, 105–112, 218–220, 240–241
   identity.py240100% 
   mempool.py65395%32–34, 56
   mpt.py140100% 
   network_config.py100100% 
   node_config.py110100% 
   p2p.py36523436%89, 92, 98, 125–143, 146–147, 150–151, 164–170, 198, 206–208, 211, 214, 221–222, 226–227, 256–257, 271–277, 290, 300, 304–306, 319–320, 333–351, 359–377, 387–403, 408–592
   persistence.py1950100% 
   pow.py430100% 
   receipt.py140100% 
   rpc.py82199%91
   serialization.py80100% 
   state.py2140100% 
   transaction.py590100% 
   validators.py90100% 
TOTAL161331081% 

Tests Skipped Failures Errors Time
230 0 💤 0 ❌ 0 🔥 12.612s ⏱️

@SIDDHANTCOOKIE
SIDDHANTCOOKIE merged commit a01e976 into main Sep 28, 2026
5 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant