Skip to content

Prepare repo for public bug bounty launch#13

Merged
cronicc merged 2 commits into
testnetfrom
chore/public-bounty-prep
Jul 17, 2026
Merged

Prepare repo for public bug bounty launch#13
cronicc merged 2 commits into
testnetfrom
chore/public-bounty-prep

Conversation

@cronicc

@cronicc cronicc commented Jul 14, 2026

Copy link
Copy Markdown
Member
  • Add MIT LICENSE (The Horizen Foundation) and license field in package.json
  • Add SECURITY.md: reporting channel (Immunefi link TBD), phased scope (testnet until Jul 27 2026, then mainnet), local-only PoC rule, and frontend attack-surface notes (static export, subgraph health banner, third-party infra out of scope)
  • Point all staker-repo references at HorizenOfficial/staker (canonical org after transfer; old HorizenLabs path only works via redirect), including the user-visible link in HowItWorks
  • Reference the dev branch for subgraphs/docs until PR Bump typescript from 5.9.3 to 6.0.3 in /frontend #6 merges to main
  • Fix case-broken CLAUDE.md link in README and drop stale "ERC1967 proxy" wording (testnet deployment is not a proxy)
  • Fix mangled comment and missing trailing newline in .env.template
  • Remove .env.testnet.gov (out-of-scope temporary preview config that could mislead bounty researchers about in-scope contracts)

- Add MIT LICENSE (The Horizen Foundation) and license field in package.json
- Add SECURITY.md: reporting channel (Immunefi link TBD), phased scope
  (testnet until Jul 27 2026, then mainnet), local-only PoC rule, and
  frontend attack-surface notes (static export, subgraph health banner,
  third-party infra out of scope)
- Point all staker-repo references at HorizenOfficial/staker (canonical org
  after transfer; old HorizenLabs path only works via redirect), including
  the user-visible link in HowItWorks
- Reference the dev branch for subgraphs/docs until PR #6 merges to main
- Fix case-broken CLAUDE.md link in README and drop stale "ERC1967 proxy"
  wording (testnet deployment is not a proxy)
- Fix mangled comment and missing trailing newline in .env.template
- Remove .env.testnet.gov (out-of-scope temporary preview config that could
  mislead bounty researchers about in-scope contracts)

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

@rushby rushby left a comment

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM

@andreanistico andreanistico left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

check if conflicts after redesign AND maybe we should merge in "testnet" before that in main (now the testnet branch deploys on the testnet staking website) @cronicc

@cronicc
cronicc changed the base branch from main to testnet July 16, 2026 09:36
Review nit: pointing at frontend/.env.testnet made a mutable config file
the scope authority; scope should not silently move with operational
config changes.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
@cloudflare-workers-and-pages

cloudflare-workers-and-pages Bot commented Jul 16, 2026

Copy link
Copy Markdown

Deploying staker-services-testnet with  Cloudflare Pages  Cloudflare Pages

Latest commit: be756eb
Status: ✅  Deploy successful!
Preview URL: https://e61f93be.staker-services-testnet.pages.dev
Branch Preview URL: https://chore-public-bounty-prep.staker-services-testnet.pages.dev

View logs

@cloudflare-workers-and-pages

Copy link
Copy Markdown

Deploying staker-services with  Cloudflare Pages  Cloudflare Pages

Latest commit: be756eb
Status: ✅  Deploy successful!
Preview URL: https://c55c8566.staker-services.pages.dev
Branch Preview URL: https://chore-public-bounty-prep.staker-services.pages.dev

View logs

@cronicc
cronicc marked this pull request as ready for review July 17, 2026 16:35
@cronicc
cronicc merged commit fe81565 into testnet Jul 17, 2026
2 checks passed
@cronicc
cronicc deleted the chore/public-bounty-prep branch July 17, 2026 16:40
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants