Status
The G4 external security review request (issue #11) received a provisional review by email on 2026-07-31: no Critical/High/Medium findings, two Low observations, two Informational notes. The technical feedback is useful, but the email does not yet qualify as G4 evidence under the policy.
Consequence: pnpm security:rc remains blocked, and the project must not be described as security-ready. This is intentional - the gate must fail until the reviewer publishes a corrected, reviewer-attested evidence record.
What is missing (see audits/g4/external/REVIEW_INTAKE_2026-07-31.md)
- Reviewer identity - name, organization or independent status, external GitHub owner.
- Public report - reviewer-controlled repository, stable URL, exact bytes, SHA-256, ISO-8601 publication time.
- Methodology - tool versions, manual-review notes, exact commands executed.
- API correction - the email names
grantAudit/acknowledgeAudit/revokeAudit/getSpaceInfo; the reviewed commit exposes grant/acknowledge/revoke/spaceAuthorization/head/transition. Please confirm which source was reviewed.
- Finding reclassification - LOW-1 (scope ECDSA fallback to EIP-7702-delegated EOAs), LOW-2 (STATICCALL defense-in-depth vs. reentrancy), INFO-1 (control-flow correction), INFO-2 (sequence continuity by induction) per the follow-up letter.
- Completed
external-review.json - following audits/g4/external/external-review.template.json, including all reviewed residual-risk IDs.
Feedback questions
- Reviewer: can you publish the corrected report + completed
external-review.json in a reviewer-controlled repository?
- Maintainers: does anything in the follow-up letter (
audits/g4/external/REVIEWER_FOLLOWUP.md) need clarification?
- Is the ten-file scope (
audits/g4/scope.json) the right frozen boundary, or should the API-correction discussion change it?
Why this matters
G4 security-ready is a blocker for any release claim. Until the evidence record is complete and accepted, pnpm security:rc fails by design - this issue tracks that exact gap.
Status
The G4 external security review request (issue #11) received a provisional review by email on 2026-07-31: no Critical/High/Medium findings, two Low observations, two Informational notes. The technical feedback is useful, but the email does not yet qualify as G4 evidence under the policy.
Consequence:
pnpm security:rcremains blocked, and the project must not be described as security-ready. This is intentional - the gate must fail until the reviewer publishes a corrected, reviewer-attested evidence record.What is missing (see
audits/g4/external/REVIEW_INTAKE_2026-07-31.md)grantAudit/acknowledgeAudit/revokeAudit/getSpaceInfo; the reviewed commit exposesgrant/acknowledge/revoke/spaceAuthorization/head/transition. Please confirm which source was reviewed.external-review.json- followingaudits/g4/external/external-review.template.json, including all reviewed residual-risk IDs.Feedback questions
external-review.jsonin a reviewer-controlled repository?audits/g4/external/REVIEWER_FOLLOWUP.md) need clarification?audits/g4/scope.json) the right frozen boundary, or should the API-correction discussion change it?Why this matters
G4 security-ready is a blocker for any release claim. Until the evidence record is complete and accepted,
pnpm security:rcfails by design - this issue tracks that exact gap.