Prepare repo for public bug bounty launch#13
Merged
Conversation
cronicc
commented
Jul 14, 2026
Member
- Add MIT LICENSE (The Horizen Foundation) and license field in package.json
- Add SECURITY.md: reporting channel (Immunefi link TBD), phased scope (testnet until Jul 27 2026, then mainnet), local-only PoC rule, and frontend attack-surface notes (static export, subgraph health banner, third-party infra out of scope)
- Point all staker-repo references at HorizenOfficial/staker (canonical org after transfer; old HorizenLabs path only works via redirect), including the user-visible link in HowItWorks
- Reference the dev branch for subgraphs/docs until PR Bump typescript from 5.9.3 to 6.0.3 in /frontend #6 merges to main
- Fix case-broken CLAUDE.md link in README and drop stale "ERC1967 proxy" wording (testnet deployment is not a proxy)
- Fix mangled comment and missing trailing newline in .env.template
- Remove .env.testnet.gov (out-of-scope temporary preview config that could mislead bounty researchers about in-scope contracts)
- Add MIT LICENSE (The Horizen Foundation) and license field in package.json - Add SECURITY.md: reporting channel (Immunefi link TBD), phased scope (testnet until Jul 27 2026, then mainnet), local-only PoC rule, and frontend attack-surface notes (static export, subgraph health banner, third-party infra out of scope) - Point all staker-repo references at HorizenOfficial/staker (canonical org after transfer; old HorizenLabs path only works via redirect), including the user-visible link in HowItWorks - Reference the dev branch for subgraphs/docs until PR #6 merges to main - Fix case-broken CLAUDE.md link in README and drop stale "ERC1967 proxy" wording (testnet deployment is not a proxy) - Fix mangled comment and missing trailing newline in .env.template - Remove .env.testnet.gov (out-of-scope temporary preview config that could mislead bounty researchers about in-scope contracts) Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
andreanistico
approved these changes
Jul 16, 2026
Contributor
There was a problem hiding this comment.
check if conflicts after redesign AND maybe we should merge in "testnet" before that in main (now the testnet branch deploys on the testnet staking website) @cronicc
Review nit: pointing at frontend/.env.testnet made a mutable config file the scope authority; scope should not silently move with operational config changes. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Deploying staker-services-testnet with
|
| Latest commit: |
be756eb
|
| Status: | ✅ Deploy successful! |
| Preview URL: | https://e61f93be.staker-services-testnet.pages.dev |
| Branch Preview URL: | https://chore-public-bounty-prep.staker-services-testnet.pages.dev |
Deploying staker-services with
|
| Latest commit: |
be756eb
|
| Status: | ✅ Deploy successful! |
| Preview URL: | https://c55c8566.staker-services.pages.dev |
| Branch Preview URL: | https://chore-public-bounty-prep.staker-services.pages.dev |
cronicc
marked this pull request as ready for review
July 17, 2026 16:35
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.