Skip to content

fix: audit risk#113

Merged
kuny0707 merged 19 commits intotronprotocol:developfrom
Sunny6889:fix_risk_scan
Mar 27, 2026
Merged

fix: audit risk#113
kuny0707 merged 19 commits intotronprotocol:developfrom
Sunny6889:fix_risk_scan

Conversation

@Sunny6889
Copy link
Copy Markdown
Contributor

What does this PR do?

Why are these changes required?

This PR has been tested by:

  • Unit Tests
  • Manual Testing

Follow up

Extra details

# Uses GitHub OIDC provider to assume an IAM role with short-lived credentials.
# No static keys needed — credentials expire after the workflow run.
# Prerequisites:
# 1. Create an IAM OIDC identity provider for token.actions.githubusercontent.com
Copy link
Copy Markdown
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

this workflows actually not used yet, so just modify the file and configure later

Comment thread conf/main_net_config.conf Outdated
# Address: TPL66VK2gCXNCD7EJg9pgJRfqcRazjhUZY
# WARNING: Replace with your own generated key for any real deployment
# NEVER use this key on mainnet with real funds
da146374a75310b9666e834ee4ad0866d6f4035967bfc76217c5a495fff9f0d0 # you must enable this value and the witness address are match.
Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Replace with YOUR_PRIVATE_KEY_HERE_64_CHARACTERS_HEXADECIMAL_STRING_EXAMPLE

Copy link
Copy Markdown
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

better not, because it will cause user cannot start the demo easily. I already mention it in related readme.

# Address: TCjptjyjenNKB2Y6EwyVT43DQyUUorxKWi
# WARNING: Replace with your own generated key for any real deployment
# NEVER use this key on mainnet with real funds
0ab0b4893c83102ed7be35eee6d50f081625ac75a07da6cb58b1ad2e9c18ce43 # you must enable this value and the witness address are match.
Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Replace with YOUR_PRIVATE_KEY_HERE_64_CHARACTERS_HEXADECIMAL_STRING_EXAMPLE

Copy link
Copy Markdown
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

same as above, for user quick-start

Comment thread metric_monitor/docker-compose/grafana.yml Outdated
Copy link
Copy Markdown
Contributor

@3for 3for left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM now.

@kuny0707 kuny0707 merged commit 1672b47 into tronprotocol:develop Mar 27, 2026
1 check passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants