code-423n4 / 2024-03-revert-lend-findings

7 stars 7 forks source link

QA Report #128

Open c4-bot-5 opened 5 months ago

c4-bot-5 commented 5 months ago

See the markdown file with the details of this report here.

c4-pre-sort commented 5 months ago

0xEVom marked the issue as sufficient quality report

c4-pre-sort commented 5 months ago

0xEVom marked the issue as high quality report

0xEVom commented 5 months ago

GA-05: reckless admin mistake, invalid QA-09: invalid

kalinbas commented 5 months ago

QA-01 Depending on the network 1 minute may be enough, also TWAP is only used to verify prices in the standard scenario where Chainlink prices are used mainly. 30 minutes is way to much when prices move fast. QA-02 If chainlink is down, only liquidiate, decreaseLiquidity and borrow functionality would be down. Thats why there is the emergency mode to disable chainlink completely if needed. QA-03 This will never reach 0 for a normal token (and this code is already deployed) - so we will leave it QA-04 Only called by admin so not that important QA-05: Invalid QA-06 Will be part of adding new tokens taking care that pools have enough history. If there is a problem with it, the history size may be increased by anyone. QA-07 Ok agree QA-08 No, its ok that ETH is sent to any address. QA-09: Invalid

c4-sponsor commented 5 months ago

kalinbas (sponsor) acknowledged

c4-judge commented 5 months ago

jhsagd76 marked the issue as grade-a

c4-judge commented 5 months ago

jhsagd76 marked the issue as selected for report

jhsagd76 commented 4 months ago

Invalid

Low

Downgraded Low

NC

Summary

1 Low 2 NC + 3 Downgraded QA Low

thebrittfactor commented 4 months ago

Just a note that C4 is excluding the invalid entries from the official report.