-
Notifications
You must be signed in to change notification settings - Fork 55
All issues
Issue creation is restricted in this repository
Issues
is:issue state:open
is:issue state:open
Search results
Makefile's stellar contract optimize step silently swallows real failures via || true
architectureArchitecture/design issueArchitecture/design issuebugSomething isn't workingSomething isn't workinghelp wantedExtra attention is neededExtra attention is neededStellar WaveIssues in the Stellar wave programIssues in the Stellar wave programvery hardVery difficult task, expert-level effort requiredVery difficult task, expert-level effort requiredStatus: Open.#130 In MergeFi/contracts;maintenance-pool has no MAX_DEPOSITS bound on deposit_count, unlike MAX_SPONSORS in escrow/milestones
architectureArchitecture/design issueArchitecture/design issuebugSomething isn't workingSomething isn't workinghelp wantedExtra attention is neededExtra attention is neededStellar WaveIssues in the Stellar wave programIssues in the Stellar wave programvery hardVery difficult task, expert-level effort requiredVery difficult task, expert-level effort requiredStatus: Open.#94 In MergeFi/contracts;No reproducible-build / supply-chain verification — deployed testnet WASM hash cannot be independently confirmed against published source
documentationImprovements or additions to documentationImprovements or additions to documentationGrantFox OSSIssue tracked in GrantFox OSSIssue tracked in GrantFox OSSMaybe RewardedIssue may be eligible for a GrantFox rewardIssue may be eligible for a GrantFox rewardOfficial Campaign | FWC26Campaign: Official Campaign | FWC26Campaign: Official Campaign | FWC26securitySecurity-related issueSecurity-related issueThird CampaignCampaign: Third CampaignCampaign: Third Campaignvery hardVery difficult task, expert-level effort requiredVery difficult task, expert-level effort requiredStatus: Open.#59 In MergeFi/contracts;All three contracts: fee_bps is read fresh at payout time, not snapshotted at deposit — #20's mutable-fee design would enable retroactive fee changes
architectureArchitecture/design issueArchitecture/design issueGrantFox OSSIssue tracked in GrantFox OSSIssue tracked in GrantFox OSSMaybe RewardedIssue may be eligible for a GrantFox rewardIssue may be eligible for a GrantFox rewardOfficial Campaign | FWC26Campaign: Official Campaign | FWC26Campaign: Official Campaign | FWC26securitySecurity-related issueSecurity-related issueThird CampaignCampaign: Third CampaignCampaign: Third Campaignvery hardVery difficult task, expert-level effort requiredVery difficult task, expert-level effort requiredStatus: Open.#53 In MergeFi/contracts;milestones::allocate: issue_id uniqueness is only enforced within a single milestone_id — the same GitHub issue can be paid out from multiple milestones
bugSomething isn't workingSomething isn't workingGrantFox OSSIssue tracked in GrantFox OSSIssue tracked in GrantFox OSSMaybe RewardedIssue may be eligible for a GrantFox rewardIssue may be eligible for a GrantFox rewardOfficial Campaign | FWC26Campaign: Official Campaign | FWC26Campaign: Official Campaign | FWC26securitySecurity-related issueSecurity-related issueThird CampaignCampaign: Third CampaignCampaign: Third Campaignvery hardVery difficult task, expert-level effort requiredVery difficult task, expert-level effort requiredStatus: Open.#51 In MergeFi/contracts;escrow: dead NotExpired/InsufficientBalance error variants suggest a missing defensive balance check in release()/refund()
bugSomething isn't workingSomething isn't workingGrantFox OSSIssue tracked in GrantFox OSSIssue tracked in GrantFox OSSMaybe RewardedIssue may be eligible for a GrantFox rewardIssue may be eligible for a GrantFox rewardOfficial Campaign | FWC26Campaign: Official Campaign | FWC26Campaign: Official Campaign | FWC26testingTesting/QA infrastructureTesting/QA infrastructureThird CampaignCampaign: Third CampaignCampaign: Third Campaignvery hardVery difficult task, expert-level effort requiredVery difficult task, expert-level effort requiredStatus: Open.#48 In MergeFi/contracts;maintenance-pool::get_deposit returns misleading Error::PoolNotFound for a missing deposit index, not just a missing pool
bugSomething isn't workingSomething isn't workingGrantFox OSSIssue tracked in GrantFox OSSIssue tracked in GrantFox OSSMaybe RewardedIssue may be eligible for a GrantFox rewardIssue may be eligible for a GrantFox rewardOfficial Campaign | FWC26Campaign: Official Campaign | FWC26Campaign: Official Campaign | FWC26Third CampaignCampaign: Third CampaignCampaign: Third Campaignvery hardVery difficult task, expert-level effort requiredVery difficult task, expert-level effort requiredStatus: Open.#46 In MergeFi/contracts;maintenance-pool::withdraw's recipient is never validated against the contract's own address — self-payment corrupts the balance invariant without theft
bugSomething isn't workingSomething isn't workingGrantFox OSSIssue tracked in GrantFox OSSIssue tracked in GrantFox OSSMaybe RewardedIssue may be eligible for a GrantFox rewardIssue may be eligible for a GrantFox rewardOfficial Campaign | FWC26Campaign: Official Campaign | FWC26Campaign: Official Campaign | FWC26securitySecurity-related issueSecurity-related issueThird CampaignCampaign: Third CampaignCampaign: Third Campaignvery hardVery difficult task, expert-level effort requiredVery difficult task, expert-level effort requiredStatus: Open.#44 In MergeFi/contracts;All three contracts: fee_bps has no sanity ceiling below 10000 (100%) — a valid-but-predatory full-fee config silently zeros every payout
bugSomething isn't workingSomething isn't workingGrantFox OSSIssue tracked in GrantFox OSSIssue tracked in GrantFox OSSMaybe RewardedIssue may be eligible for a GrantFox rewardIssue may be eligible for a GrantFox rewardOfficial Campaign | FWC26Campaign: Official Campaign | FWC26Campaign: Official Campaign | FWC26securitySecurity-related issueSecurity-related issueThird CampaignCampaign: Third CampaignCampaign: Third Campaignvery hardVery difficult task, expert-level effort requiredVery difficult task, expert-level effort requiredStatus: Open.#40 In MergeFi/contracts;Migrate initialize to a Soroban constructor to close the deploy/init front-running race
documentationImprovements or additions to documentationImprovements or additions to documentationGrantFox OSSIssue tracked in GrantFox OSSIssue tracked in GrantFox OSSMaybe RewardedIssue may be eligible for a GrantFox rewardIssue may be eligible for a GrantFox rewardOfficial Campaign | FWC26Campaign: Official Campaign | FWC26Campaign: Official Campaign | FWC26spikeOpen-ended research/investigation taskOpen-ended research/investigation taskStatus: Open.#33 In MergeFi/contracts;Long-run invariant fuzzing of
total_deposited/total_withdrawn/balancedrift in maintenance-poolGrantFox OSSIssue tracked in GrantFox OSSIssue tracked in GrantFox OSSMaybe RewardedIssue may be eligible for a GrantFox rewardIssue may be eligible for a GrantFox rewardOfficial Campaign | FWC26Campaign: Official Campaign | FWC26Campaign: Official Campaign | FWC26securitySecurity-related issueSecurity-related issuetestingTesting/QA infrastructureTesting/QA infrastructurevery hardVery difficult task, expert-level effort requiredVery difficult task, expert-level effort requiredStatus: Open.#29 In MergeFi/contracts;Correctness audit of
compute_splitunder zero-recipient-adjacent, duplicate-address, and self-referential edge casesbugSomething isn't workingSomething isn't workingGrantFox OSSIssue tracked in GrantFox OSSIssue tracked in GrantFox OSSMaybe RewardedIssue may be eligible for a GrantFox rewardIssue may be eligible for a GrantFox rewardOfficial Campaign | FWC26Campaign: Official Campaign | FWC26Campaign: Official Campaign | FWC26securitySecurity-related issueSecurity-related issuetestingTesting/QA infrastructureTesting/QA infrastructurevery hardVery difficult task, expert-level effort requiredVery difficult task, expert-level effort requiredStatus: Open.#28 In MergeFi/contracts;