-
Notifications
You must be signed in to change notification settings - Fork 84
All issues
Issue creation is restricted in this repository
Issues
is:issue state:open
is:issue state:open
Search results
BountiesService.expireOverdue() overwrites concurrently-advanced bounties to EXPIRED — read-then-save with no status re-check and no assertTransition
architectureArchitecture/design issueArchitecture/design issuebugSomething isn't workingSomething isn't workingStellar WaveIssues in the Stellar wave programIssues in the Stellar wave programvery hardVery difficult task, expert-level effort requiredVery difficult task, expert-level effort requiredStatus: Open.#460 In MergeFi/backend;assignReward decrements MaintenancePool.balance before poolWithdraw() and never restores it when the withdrawal fails
architectureArchitecture/design issueArchitecture/design issuebugSomething isn't workingSomething isn't workingStellar WaveIssues in the Stellar wave programIssues in the Stellar wave programvery hardVery difficult task, expert-level effort requiredVery difficult task, expert-level effort requiredStatus: Open.#459 In MergeFi/backend;[Regression on closed #273] assignReward's double-payout guard is keyed on (pool, recipient) instead of (pool, issue) — the same issue can still be paid twice
bugSomething isn't workingSomething isn't workingsecuritySecurity-related issueSecurity-related issueStellar WaveIssues in the Stellar wave programIssues in the Stellar wave programvery hardVery difficult task, expert-level effort requiredVery difficult task, expert-level effort requiredStatus: Open.#458 In MergeFi/backend;MaintenancePoolService.deposit() always throws PessimisticLockTransactionRequiredError — the #275 SELECT ... FOR UPDATE runs outside any transaction
architectureArchitecture/design issueArchitecture/design issuebugSomething isn't workingSomething isn't workingStellar WaveIssues in the Stellar wave programIssues in the Stellar wave programvery hardVery difficult task, expert-level effort requiredVery difficult task, expert-level effort requiredStatus: Open.#457 In MergeFi/backend;GithubWebhooksController.handle always returns 202 even when handleEvent marks the event FAILED, and no job ever reprocesses FAILED WebhookEvent rows
Stellar WaveIssues in the Stellar wave programIssues in the Stellar wave programStatus: Open.#317 In MergeFi/backend;- Status: Open.#300 In MergeFi/backend;
- Status: Open.#299 In MergeFi/backend;
Bounty/Milestone/MaintenancePool/User list endpoints have no pagination and return the entire table in one unbounded response
GrantFox OSSIssue tracked in GrantFox OSSIssue tracked in GrantFox OSSMaybe RewardedIssue may be eligible for a GrantFox rewardIssue may be eligible for a GrantFox rewardOfficial Campaign | FWC26Campaign: Official Campaign | FWC26Campaign: Official Campaign | FWC26performancePerformance/optimization issuePerformance/optimization issueThird CampaignCampaign: Third CampaignCampaign: Third Campaignvery hardVery difficult task, expert-level effort requiredVery difficult task, expert-level effort requiredStatus: Open.#63 In MergeFi/backend;TeamMemberSplit.user uses onDelete: CASCADE, so deleting any team member's account silently desyncs a team's split percentages from 100 and can permanently strand that team's bounty
architectureArchitecture/design issueArchitecture/design issuebugSomething isn't workingSomething isn't workingGrantFox OSSIssue tracked in GrantFox OSSIssue tracked in GrantFox OSSMaybe RewardedIssue may be eligible for a GrantFox rewardIssue may be eligible for a GrantFox rewardOfficial Campaign | FWC26Campaign: Official Campaign | FWC26Campaign: Official Campaign | FWC26Third CampaignCampaign: Third CampaignCampaign: Third Campaignvery hardVery difficult task, expert-level effort requiredVery difficult task, expert-level effort requiredStatus: Open.#58 In MergeFi/backend;Because no money-moving route requires auth, IdempotencyInterceptor buckets every caller under a shared 'anonymous' identity per scope, letting unrelated callers collide on each other's cached responses
bugSomething isn't workingSomething isn't workingGrantFox OSSIssue tracked in GrantFox OSSIssue tracked in GrantFox OSSMaybe RewardedIssue may be eligible for a GrantFox rewardIssue may be eligible for a GrantFox rewardOfficial Campaign | FWC26Campaign: Official Campaign | FWC26Campaign: Official Campaign | FWC26securitySecurity-related issueSecurity-related issueThird CampaignCampaign: Third CampaignCampaign: Third Campaignvery hardVery difficult task, expert-level effort requiredVery difficult task, expert-level effort requiredStatus: Open.#55 In MergeFi/backend;release() and splitRelease() never check for pre-existing Payment rows, so calling them after releasePartial causes a double payout of the full escrow amount
bugSomething isn't workingSomething isn't workingGrantFox OSSIssue tracked in GrantFox OSSIssue tracked in GrantFox OSSMaybe RewardedIssue may be eligible for a GrantFox rewardIssue may be eligible for a GrantFox rewardOfficial Campaign | FWC26Campaign: Official Campaign | FWC26Campaign: Official Campaign | FWC26securitySecurity-related issueSecurity-related issueThird CampaignCampaign: Third CampaignCampaign: Third Campaignvery hardVery difficult task, expert-level effort requiredVery difficult task, expert-level effort requiredStatus: Open.#44 In MergeFi/backend;Money-moving DTOs trust client-supplied contributorId/recipientId/funderAddress instead of binding to the authenticated caller
architectureArchitecture/design issueArchitecture/design issueGrantFox OSSIssue tracked in GrantFox OSSIssue tracked in GrantFox OSSMaybe RewardedIssue may be eligible for a GrantFox rewardIssue may be eligible for a GrantFox rewardOfficial Campaign | FWC26Campaign: Official Campaign | FWC26Campaign: Official Campaign | FWC26securitySecurity-related issueSecurity-related issueThird CampaignCampaign: Third CampaignCampaign: Third Campaignvery hardVery difficult task, expert-level effort requiredVery difficult task, expert-level effort requiredStatus: Open.#40 In MergeFi/backend;