pull down to refresh
Bots told me there were 4 high severity but after manual validation yesterday I only have maybe-one left that I have not fully repro'd yet, the rest of what was flagged high is at best low.
The maybe-high one is sitting in createBolt11FromWalletProtocols and I have a couple that could be worth fixing, but repro is slow af and I don't trust the bots for one second. They also keep disagreeing with themselves (including Claude and GPT disagreeing with their own prior analyses - I fuzz who wrote what to take out any bias)
I have 43 after my not-pushed msats/sats and description truncation work. Of the 43, 3 are high and about key rotation, 9 medium (some out of scope), and a long tail of low.