docs: add manual security disclosure collection - #994
Open
TheDZhon wants to merge 2 commits into
Open
Conversation
TheDZhon
commented
Sep 12, 2026
TheDZhon
force-pushed
the
agent/disclosure-candidates
branch
from
September 12, 2026 01:36
60f9f50 to
38344cd
Compare
TheDZhon
marked this pull request as ready for review
September 12, 2026 01:37
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
The disclosure ledger is missing the August Accounting Oracle / VEBO post-mortem, and there is no repeatable way to compare forum disclosures against it. This adds a manual candidate collector and the reviewed ledger entry.
Stacked on #960. The base is
chore/update-audits-and-lipsso this PR shows only the disclosure additions. After #960 merges, retarget this PR tomainand update its base as needed.Changes
npm run fetch-disclosures, using docs: add new audit reports and LIP-37 #960's existinglib/http,lib/markdown, andlib/taskshelpers and exportedrun()convention..security-triage/directory, containing source links, ids, dates, hashes, candidates, already-listed topics, routing exclusions, and errors. Do not persist titles, bodies, or author identities.Incident / Low, and clarify that the main ledger focuses on Lido's staking business.The existing audit/LIP/quorum fetchers, aggregate fetch command, shared helpers, redirects, dependencies, and CI workflows are unchanged. Live forum collection is a separate manual command; it does not publish ledger rows or assign severity.
Evidence and validation
Source: https://research.lido.fi/t/11756/3 — August 6 is the post-mortem publication date.
Lowis the reviewed editorial classification.npm test: 82 tests passed (70 inherited and 12 new).npm run build: passed.git diff --check: passed.11756, already-listed11342, nine product/operator exclusions, complete collection, zero errors.