sherlock-audit / 2024-07-sense-points-marketplace-judging

2 stars 0 forks source link

Virtual Topaz Beaver - [I-1] Licensing conflict on inherited dependencies #211

Closed sherlock-admin3 closed 2 weeks ago

sherlock-admin3 commented 2 weeks ago

Virtual Topaz Beaver

Low/Info

[I-1] Licensing conflict on inherited dependencies

Location: [File name and line numbers]

Description

The version of Solmate contracts depended in the Point Tokenization Vault repository on are AGPL Licensed, making our repository adopt the same license. This license is incompatible with the currently UNLICENSED Rumpel related contracts.

Impact

Recommended mitigation

  1. Consider the later versions of Solmate which have updated licensing.
  2. Consider applying AGPL license to Rumpel.
sherlock-admin2 commented 1 week ago

The protocol team fixed this issue in the following PRs/commits: https://github.com/sense-finance/point-tokenization-vault/pull/40 https://github.com/sense-finance/rumpel-wallet/pull/7

sherlock-admin2 commented 1 week ago

The Lead Senior Watson signed off on the fix.