Skip to content

fix: pin version 1.7.1 in skills and add audit TOB as references#362

Open
iamquang95 wants to merge 1 commit intomainfrom
iamquang95/skill-pin-versions-and-audit
Open

fix: pin version 1.7.1 in skills and add audit TOB as references#362
iamquang95 wants to merge 1 commit intomainfrom
iamquang95/skill-pin-versions-and-audit

Conversation

@iamquang95
Copy link
Copy Markdown
Collaborator

Fix #345


## Reference Version

Use Charon v1.7.1 as the default Go reference for AI-assisted porting and review. For DKG, sync, reshare, FetchDefinition, and peer-indexed broadcast code, treat the [February 20, 2026 Trail of Bits Charon Pedersen DKG audit](https://github.com/ObolNetwork/charon/blob/main/docs/audit/2026%20-%20Charon%20V2%20Audit%20-%20TrailOfBits.pdf) as a required security overlay: preserve v1.7.1 compatibility unless the audit documents vulnerable behavior, then port the audited fix intent.
Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Can we convert the audit findings to .md and store it in the repository or make a skill with their compliance?

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Update (AI) docs to include audit findings

2 participants