Skip to content

[G4] External security review evidence follow-up - unblock security:rc #22

Description

@everest-an

Status

The G4 external security review request (issue #11) received a provisional review by email on 2026-07-31: no Critical/High/Medium findings, two Low observations, two Informational notes. The technical feedback is useful, but the email does not yet qualify as G4 evidence under the policy.

Consequence: pnpm security:rc remains blocked, and the project must not be described as security-ready. This is intentional - the gate must fail until the reviewer publishes a corrected, reviewer-attested evidence record.

What is missing (see audits/g4/external/REVIEW_INTAKE_2026-07-31.md)

  1. Reviewer identity - name, organization or independent status, external GitHub owner.
  2. Public report - reviewer-controlled repository, stable URL, exact bytes, SHA-256, ISO-8601 publication time.
  3. Methodology - tool versions, manual-review notes, exact commands executed.
  4. API correction - the email names grantAudit/acknowledgeAudit/revokeAudit/getSpaceInfo; the reviewed commit exposes grant/acknowledge/revoke/spaceAuthorization/head/transition. Please confirm which source was reviewed.
  5. Finding reclassification - LOW-1 (scope ECDSA fallback to EIP-7702-delegated EOAs), LOW-2 (STATICCALL defense-in-depth vs. reentrancy), INFO-1 (control-flow correction), INFO-2 (sequence continuity by induction) per the follow-up letter.
  6. Completed external-review.json - following audits/g4/external/external-review.template.json, including all reviewed residual-risk IDs.

Feedback questions

  1. Reviewer: can you publish the corrected report + completed external-review.json in a reviewer-controlled repository?
  2. Maintainers: does anything in the follow-up letter (audits/g4/external/REVIEWER_FOLLOWUP.md) need clarification?
  3. Is the ten-file scope (audits/g4/scope.json) the right frozen boundary, or should the API-correction discussion change it?

Why this matters

G4 security-ready is a blocker for any release claim. Until the evidence record is complete and accepted, pnpm security:rc fails by design - this issue tracks that exact gap.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    help wantedExtra attention is needed

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions