2026-04-28 - 2026-07-28

Overview

9 Active Pull Requests
17 Active Issues
Excluding merges, 2 authors have pushed 3 commits to main and 60 commits to all branches. On main, 12 files have changed and there have been 418 additions and 489 deletions.

5 Pull requests merged by 2 users

Merged #95 security: batch of fixes 2026-06-29 18:00:14 +00:00

Merged #94 fix(user-agent): zombie sessions #74 2026-06-19 14:04:57 +00:00

Merged #83 security(server): bind grant revocation state (revoked_at) to integrity hash 2026-06-11 09:44:29 +00:00

Merged #93 fix(smlang::statemachine): macro invocation requires inner types to be public 2026-06-09 18:19:33 +00:00

Merged #92 housekeeping(server): deps upgrade + diesel migration to AsyncFnOnce 2026-05-01 11:25:42 +00:00

4 Pull requests proposed by 2 users

Proposed #91 WIP: feat-shamir 2026-05-01 08:20:50 +00:00

Proposed #98 deps(server): version bump 2026-06-26 10:38:08 +00:00

Proposed #99 hashable-integrable-macro 2026-06-30 18:01:41 +00:00

Proposed #100 fix: terminate VaultGate connection after vault lockout 2026-06-30 18:07:10 +00:00

15 Issues closed from 1 user

Closed #79 Not using quantum-resistant schemes 2026-07-07 06:32:09 +00:00

Closed #59 Bootstrap token persists on disk with weak file permissions 2026-06-30 18:06:07 +00:00

Closed #60 Unseal and bootstrap handshake lack brute-force protection 2026-06-30 18:01:01 +00:00

Closed #64 User-agent signing endpoint accepts arbitrary client_id 2026-06-29 18:00:15 +00:00

Closed #73 Consumed bootstrap token is not zeroized in memory 2026-06-29 18:00:15 +00:00

Closed #67 Bootstrap token RNG seeding should be made explicit 2026-06-29 18:00:15 +00:00

Closed #65 Integrity envelopes do not survive root key rotation 2026-06-29 18:00:15 +00:00

Closed #54 Encrypted key material not bound to wallet address — cross-wallet signing possible 2026-06-29 18:00:15 +00:00

Closed #71 Wallet-access revocation deletes by wallet_id instead of entry id 2026-06-29 18:00:15 +00:00

Closed #63 SDK client metadata is silently rewritten on reconnect 2026-06-29 18:00:15 +00:00

Closed #52 Come up with mechanism for enforcing integrity protection usage 2026-06-22 15:54:08 +00:00

Closed #68 RequestTracker allows arbitrary gaps across request flows 2026-06-19 17:15:51 +00:00

Closed #74 Zombie user-agent sessions can block all new client approvals 2026-06-19 14:04:58 +00:00

Closed #62 Bootstrap token registration lacks proof of possession 2026-06-18 18:00:29 +00:00

Closed #56 revoked_at is not included in signature 2026-06-11 09:44:29 +00:00

2 Issues created by 1 user

Opened #96 Allow clippy's CI to automatically fix some of the linting issues 2026-06-19 11:49:22 +00:00

Opened #97 Require explicit VERSION in Integrable trait 2026-06-22 15:53:09 +00:00

4 Unresolved Conversations

Open #66 Transaction logs can be tampered with to reset rate limits 2026-06-22 13:04:47 +00:00

Open #70 Client approval quorum differs from documented consensus model 2026-06-19 11:53:43 +00:00

Open #86 suspicious as keywords 2026-06-11 13:45:43 +00:00

Open #37 Useragent doesn't check server certificate 2026-06-09 16:24:13 +00:00