status · Not linked
Third-party audits
No third-party audit report is linked on this page at the moment. When audits are completed and approved for release, published reports will appear here with dates and scope.
Audit reporting belongs in the open: publish links to third-party reports when available, and keep day-to-day security work anchored to verifiable checks and a clear disclosure process.
When third-party audit reports exist, they are linked here. If nothing is linked, treat the status as unpublished — not as an implied clean bill of health.
status · Not linked
No third-party audit report is linked on this page at the moment. When audits are completed and approved for release, published reports will appear here with dates and scope.
channel · Private first
Vulnerabilities should be reported privately. Fixes should ship before public discussion whenever possible. See the disclosure process for channels and response targets.
A small set of repeatable checks. Other repositories may have additional gates — treat their CI workflows as the canonical source.
| Check | Command |
|---|---|
| Lint | bun run lint |
| Links | bun run check:links |
| Doc samples | node scripts/check-doc-samples.mjs |
| Build | bun run build |
Start with the threat model and primitive choices, then push edge cases into RFCs so verifier behavior stays explicit.