Product updates
- Findings can be recorded as acknowledged: the client read the finding and accepted the risk without fixing it.
- Audit firms can submit the status
acknowledgedwhen publishing or editing an audit. - The project page lists acknowledged findings among the active ones, labelled “Acknowledged”.
- In the public API, an acknowledged finding keeps
status: not_fixedand carriesisAcknowledged: trueon each item ofactiveIssues. isDeemedDangerousdoes not count acknowledged findings.
- Audit firms can submit the status
- Shorter audit card text. The card says “No open critical findings”, “N criticals acknowledged, not fixed”, or “No audit on Trustblock” when the address has none.
- Security incidents on the card follow one rule: an incident shows while it is more recent than the project’s latest audit, or less than 12 months old. Phishing of users is never attached to a project.
- Projects whose reports name no chain show “Chain not stated” instead of an empty chain list.
- Audit firm profiles that Trustblock maintains from a firm’s public reports are listed on /auditors, each labelled “This profile is managed by Trustblock”.
- Sign-up asks who you are first (audit firm or developer), then shows the shortest form for that role.
Bugs fixed
- Publishing an audit with findings no longer fails on the findings step.
- The publish form sends an audit once; a second click can no longer publish the same report twice.
- A signed-in audit firm is no longer shown the sign-up page when their profile takes a moment to load, and someone signed in without a profile can finish sign-up.
- A page shows “not found” only when the project, audit or audit firm really doesn’t exist.
Performance, Security & Reliability improvements
- Pages retry when the API answers that it is busy, instead of failing.
- Page updates after a change (a new audit, an edit, a removal) are no longer held up by a request about a deleted project.