Skip to content

docs+chore: security policy + bounty tiers, audit addendum, Saltant/ProtonUK endpoints, testnet chainId fix - #81

Merged
paulgnz merged 1 commit into
mainfrom
chore/endpoints-saltant-protonuk
Sep 22, 2026
Merged

paulgnz merged 1 commit into
mainfrom
chore/endpoints-saltant-protonuk

Conversation

@paulgnz

@paulgnz paulgnz commented Sep 22, 2026 •

Copy link
Copy Markdown
Collaborator

Three changes in this PR:

  1. SECURITY.md now includes bounty tiers based on past payouts, a duplicate rule, a "test against current main and the on-chain code hash" section, rules of engagement, and explicit scope that covers shipped defaults.
  2. docs/SECURITY_AUDIT.md gets an addendum for the 0xgons batch-2 reports (security: Telegram /run bypass, A2A default authz, agent-card SSRF redirect #77, test(agentvalid): cancelchal flag-desync regression #78, chore: retire the Docker installer path and GHCR images #80, and the 10k bounty). A2A refactor: route signing through proton CLI (key isolation) #7/docs(readme): align with proton CLI as primary path; demote Docker #8 are marked as fixed.
  3. Endpoints: proton.eosusa.io is replaced everywhere it shipped with Saltant (api-xprnetwork-main.saltant.io), with ProtonUK (proton.protonuk.io) as the alternative. Each of these serves chain RPC and Hyperion /v2 from the same host, and both passed verification.

Bug fix: the frontend and the deploy-service frontend hardcoded the wrong testnet chain id. That breaks wallet login and signing on testnet.

SDK tests pass (299). Typecheck is clean for openclaw and the agent. Both touched skills build, and the template copies are still in sync.

The runtime default changes in sdk, the plugin and the runner only reach third parties with the next SDK/openclaw publish.

…t/ProtonUK endpoints

SECURITY.md: publish bounty tiers (anchored on what has been paid: 20k XSS, 15k
slash evasion, 5k each for this round), a duplicate rule (fixed on main or deployed
on chain before the report = duplicate), and ask reporters to test against current
main and compare the on-chain code hash. Three of the last four external reports
targeted a stale commit. Scope now names shipped defaults explicitly; the obsolete
Docker-private-key limitation is replaced with the proton CLI keychain and a2a key notes.

docs/SECURITY_AUDIT.md: addendum for the 0xgons batch-2 reports (#77, #78, #80,
10k bounty); A2A #7/#8 residual marked fixed (#70/#71).

Endpoints: replace proton.eosusa.io in shipped defaults, SDK NETWORKS, plugin/runner
fallbacks, skills and docs with producer endpoints that serve chain RPC and Hyperion
/v2 on one host — Saltant (api-xprnetwork-main.saltant.io) with ProtonUK
(proton.protonuk.io) as the alternative; both verified (table reads, get_actions,
head lag < 0.2s). smart-contracts maps nodeos-only hosts to Saltant and testnet to
Saltant's testnet Hyperion. deploy-service CSP updated to match.

Fix: frontend and deploy-service frontend hardcoded the wrong testnet chain id
(71ee83bcf20d…); the real one (from tn1 and Saltant testnet get_info) is
71ee83bcf521…abeaf3d3dd, which the SDK already used. The smart-contracts SKILL.md
testnet id was also wrong.
@paulgnz
paulgnz merged commit cf4e3ca into main Sep 22, 2026
7 checks passed
@paulgnz
paulgnz deleted the chore/endpoints-saltant-protonuk branch September 22, 2026 20:14
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant