docs: verify both security reports against v2.10.15 Source-level re-verification of the 2026-06-09 audit (vs ~v2.2.0) and the 2026-08-03 scan. Audit is almost entirely fixed/superseded (incl. CF-1/CF-2: the lock button and auto-lock exist and work). Confirmed still open: scan F1-F4 (passkey caller binding, origin synthesis, intent prefill, codex inflate cap) and audit MN-3 (sync-entry sanitization). Verdicts + fix queue in docs/security-findings-verification-2026-08-03.md; queue recorded in CONTINUITY.md. No code changes.
$ koh steal kepr.uk/peach-android@6a5ffd129172
·
parent: a4f412268332
discussion
log in to leave a comment.