-
Notifications
You must be signed in to change notification settings - Fork 15
All issues
Issue creation is restricted in this repository
Issues
is:issue state:open
is:issue state:open
Search results
[Security] Rate-limit fallback fails open silently in production
apiAdds or modifies a REST endpoint in apps/apiAdds or modifies a REST endpoint in apps/apisecuritySecurity hardening, vulnerability fixes, or audit-related workSecurity hardening, vulnerability fixes, or audit-related worktrivialSelf-contained task, completable in < 2 hours with no deep protocol knowledge requiredSelf-contained task, completable in < 2 hours with no deep protocol knowledge requiredStatus: Open.#483 In drydocs/meridian;[Security] Submit allowlist includes the DeFindex factory, not just the vault
sdkInvolves Blend or DeFindex SDK helpers in packages/stellar-sdk-helpersInvolves Blend or DeFindex SDK helpers in packages/stellar-sdk-helperssecuritySecurity hardening, vulnerability fixes, or audit-related workSecurity hardening, vulnerability fixes, or audit-related worktrivialSelf-contained task, completable in < 2 hours with no deep protocol knowledge requiredSelf-contained task, completable in < 2 hours with no deep protocol knowledge requiredStatus: Open.#482 In drydocs/meridian;[Bug] SubmitRequestSchema has no max length, unlike api-local's body limit
apiAdds or modifies a REST endpoint in apps/apiAdds or modifies a REST endpoint in apps/apibugSomething isn't workingSomething isn't workingtrivialSelf-contained task, completable in < 2 hours with no deep protocol knowledge requiredSelf-contained task, completable in < 2 hours with no deep protocol knowledge requiredStatus: Open.#481 In drydocs/meridian;[Feature] Extract a wallet abstraction layer from the Freighter-specific connect flow
enhancementNew feature or requestNew feature or requestfrontendInvolves React components, Tailwind styling, or Next.js pagesInvolves React components, Tailwind styling, or Next.js pagesmediumRequires familiarity with the Meridian codebase or relevant tooling; expect 4–8 hoursRequires familiarity with the Meridian codebase or relevant tooling; expect 4–8 hoursStatus: Open.#476 In drydocs/meridian;[Feature] Fully automated cross-vault yield routing (delegated rebalance)
contractsInvolves writing or testing Rust/Soroban contracts in packages/contractsInvolves writing or testing Rust/Soroban contracts in packages/contractsenhancementNew feature or requestNew feature or requesthardComplex implementation spanning multiple packages or involving Soroban contractsComplex implementation spanning multiple packages or involving Soroban contractssecuritySecurity hardening, vulnerability fixes, or audit-related workSecurity hardening, vulnerability fixes, or audit-related worksorobanInvolves Soroban smart contract invocations or Soroban RPC callsInvolves Soroban smart contract invocations or Soroban RPC callsStatus: Open.#469 In drydocs/meridian;[Feature] TVL/APY displays can go stale indefinitely with no accrual keeper
contractsInvolves writing or testing Rust/Soroban contracts in packages/contractsInvolves writing or testing Rust/Soroban contracts in packages/contractsenhancementNew feature or requestNew feature or requesthardComplex implementation spanning multiple packages or involving Soroban contractsComplex implementation spanning multiple packages or involving Soroban contractssorobanInvolves Soroban smart contract invocations or Soroban RPC callsInvolves Soroban smart contract invocations or Soroban RPC callsStatus: Open.#466 In drydocs/meridian;[Feature] No safe way to migrate a live vault's capital to a new adapter
contractsInvolves writing or testing Rust/Soroban contracts in packages/contractsInvolves writing or testing Rust/Soroban contracts in packages/contractsenhancementNew feature or requestNew feature or requesthardComplex implementation spanning multiple packages or involving Soroban contractsComplex implementation spanning multiple packages or involving Soroban contractssorobanInvolves Soroban smart contract invocations or Soroban RPC callsInvolves Soroban smart contract invocations or Soroban RPC callsStatus: Open.#464 In drydocs/meridian;[Chore] Deduplicate adapter boilerplate between blend-adapter and defindex-adapter
choreBuild, CI, dependency updates, or repository maintenanceBuild, CI, dependency updates, or repository maintenancecontractsInvolves writing or testing Rust/Soroban contracts in packages/contractsInvolves writing or testing Rust/Soroban contracts in packages/contractshardComplex implementation spanning multiple packages or involving Soroban contractsComplex implementation spanning multiple packages or involving Soroban contractsStatus: Open.#460 In drydocs/meridian;[Docs] Document AdapterSwapUnsafe in the vault error code table
contractsInvolves writing or testing Rust/Soroban contracts in packages/contractsInvolves writing or testing Rust/Soroban contracts in packages/contractsdocsDocumentation, guides, README, inline docs, or ADRsDocumentation, guides, README, inline docs, or ADRsStellar WaveIssues in the Stellar wave programIssues in the Stellar wave programtrivialSelf-contained task, completable in < 2 hours with no deep protocol knowledge requiredSelf-contained task, completable in < 2 hours with no deep protocol knowledge requiredStatus: Open.#423 In drydocs/meridian;[Feature] Refresh adapter's cached total_assets before pricing on deposit/withdraw
contractsInvolves writing or testing Rust/Soroban contracts in packages/contractsInvolves writing or testing Rust/Soroban contracts in packages/contractsenhancementNew feature or requestNew feature or requestGrantFox OSSIssue tracked in GrantFox OSSIssue tracked in GrantFox OSShardComplex implementation spanning multiple packages or involving Soroban contractsComplex implementation spanning multiple packages or involving Soroban contractsMaybe RewardedIssue may be eligible for a GrantFox rewardIssue may be eligible for a GrantFox rewardOfficial Campaign | FWC26Campaign: Official Campaign | FWC26Campaign: Official Campaign | FWC26sorobanInvolves Soroban smart contract invocations or Soroban RPC callsInvolves Soroban smart contract invocations or Soroban RPC callsStatus: Open.#418 In drydocs/meridian;