Skip to content

docs: prototype banner + scoped SECURITY (audit H1)#12

Merged
github-actions[bot] merged 1 commit intomainfrom
fix/audit-h1-prototype-banner
May 7, 2026
Merged

docs: prototype banner + scoped SECURITY (audit H1)#12
github-actions[bot] merged 1 commit intomainfrom
fix/audit-h1-prototype-banner

Conversation

@satyakwok
Copy link
Copy Markdown
Contributor

Per audit 2026-05-07 finding H1: README positions Solux as 'self-custody mobile wallet' but app is UI-only mock with zero crypto. Adds explicit PROTOTYPE / DO NOT SEND REAL FUNDS banner at top of README, updates SECURITY.md scope to match.

Solux currently has zero crypto implementation — no key generation,
no signing, no on-chain integration. README previously positioned
the app as a 'self-custody mobile wallet'; users could install the
APK believing they could store real SRX in it. The 'Send', 'View
Seed Phrase', and 'Export Private Key' buttons are non-functional
placeholders.

Per 2026-05-07 audit (audits/2026-05-07-solux-audit.md H1), add a
prototype banner at the top of README and update SECURITY.md scope
to reflect that key-handling reports won't apply until the crypto
layer lands. The repo IS still receiving security reports for UI/
build/deps vulns — that scope is preserved.
@github-actions github-actions Bot enabled auto-merge (squash) May 7, 2026 14:15
@github-actions github-actions Bot merged commit 040fb4f into main May 7, 2026
2 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant