Skip to main content

Product updates

  • Explorer cards:
    • The Etherscan card gives critical findings that the client acknowledged without fixing their own state: orange, “1 critical acknowledged, not fixed” or ” criticals acknowledged, not fixed”. The worst state wins: an exploit, then open critical findings, then acknowledged ones, then none.
    • The Blockscout card has a new field, acknowledgedCriticalIssuesNumber, counted apart from activeCriticalIssuesNumber. It also reports activeHighIssuesNumber, activeRektsNumber and latestRektAt.
    • Both card routes answer an unknown project, or a project with no published audit, with 200 and isFound: false.
    • Both card routes answer 503 with a Retry-After header when the database cannot be reached, and 500 for any other failure. A failed lookup is no longer returned as a “no audit” card.
  • API keys:
    • Send your key as Authorization: Bearer <key>. The older x-trustblock-api-key header, refused since June 2024, is accepted again.
    • GET /v1/key checks a key without using a credit, and says which header carried it.
    • From the dashboard you can test your key, see your last accepted and last refused call (and why it was refused), and rotate your key. Your remaining credits move to the new key.
  • A signed-in developer has a Dashboard button in the header.
  • Integrator dashboard at /integrator/dashboard: your API key and usage, and the project label, auditor widget and explorer card with live previews and copy-paste snippets (curl, JavaScript, Python).
  • Card playground at /playground/cards: look up a project by name, token or contract address and see both cards and their raw JSON.
  • The project widget has a compact label variant, set with data-tb-variant="label".
  • Twelve Cosmos-ecosystem chains: Cosmos Hub, Osmosis, Neutron, Terra, Sei, Juno, Stargaze, Dymension, Archway, Noble, Stride and Persistence.
  • A finding published by an audit provider needs a title.
  • The audit page says when it cannot show the PDF, and links to it.
  • Old short project slugs redirect to the project’s page.
  • The account page shows a profile picture right after it is uploaded, and Save confirms and disables itself.
  • Link previews: the app and the docs share one title, description and image.

Bugs fixed

  • A developer sign-up keeps the company name and website across the email step, and no longer fails when no tags are chosen.
  • Moving an audit to another project leaves the contracts that other audits still use.
  • Page titles no longer cut a name in the middle of a word.

Documentation

  • New guide and endpoint pages for the two card routes.
  • Finding statuses, API credits, supported chains and the roles pages now match the product and the API.
  • The page comparing Trustblock with other platforms was removed.
  • The Security Data API page covers both key headers, the key check and key rotation.