Skip to content

Conversation

@atharv02-git
Copy link

@atharv02-git atharv02-git commented Mar 22, 2025

Description

This pull request documents the collaboration agreement between OnTrack and HardHat's AppAttack team, outlining the testing scope, responsibilities, and timeline. In addition to the agreement, this PR also includes:

  • Upload of 11 vulnerability reports as part of Stage 1 findings from AppAttack.
  • Addition of the End of Trimester Report as a final deliverable from the AppAttack team also mentioning.

Summary of Resolved Vulnerabilities

The following vulnerabilities were assessed and resolved as part of this collaboration. Future contributors should refer to the Guidance for Future Security Contributors to avoid duplicate fixes.

Vulnerability Name Impact Level
Clickjacking Severe
Insecure Direct Object Reference (IDOR) Major
Malicious Code Execution Major
Exposed JavaScript Source Maps (False Positive) Major
Session Hijacking and Fixation Significant
Token Exposure via Local Storage and HTTP Headers (False Positive) Significant
Misconfigured CORS (False Positive) Significant

Type of Change

  • Documentation (update or new)

How Has This Been Tested?

  1. All markdown and PDF files were reviewed locally via VS Code to ensure correct file structure
  2. Verified that:
    • All linked reports are accessible within the docs directory structure.
    • Index pages correctly reference and organize the uploaded reports.

Testing Checklist

  • Tested in latest Chrome (for live preview rendering, if needed)
  • Tested in latest Safari
  • Tested in latest Firefox

Checklist

  • My code follows the style guidelines of this project
  • I have made corresponding changes to the documentation
  • All PDF files are named consistently and organized in logical folders
  • I have requested a review from @aNebula on the Pull Request

Adds collaboration agreement outlining testing scope, responsibilities, and timelines between OnTrack and HardHat's AppAttack team.
@netlify
Copy link

netlify bot commented Mar 22, 2025

Deploy Preview for ontrackdocumentation failed.

Name Link
🔨 Latest commit be4e56a
🔍 Latest deploy log https://app.netlify.com/projects/ontrackdocumentation/deploys/68538510717bf20008152c8f

@atharv02-git atharv02-git changed the title docs: AppAttack x OnTrack testing agreement docs: AppAttackxOnTrack testing Contract, Vulnerability Reports and End of Trimester Final Report May 18, 2025
…dea of what fixes has been made to avoid duplicacy and rework
…dea of what fixes has been made to avoid duplicacy and rework for Clickjacking Vulnerability
…dea of what fixes has been made to avoid duplicacy and rework
Copy link
Collaborator

@aNebula aNebula left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

@atharv02-git Please resolve the conflict

@atharv02-git
Copy link
Author

@atharv02-git Please resolve the conflict

Hey @aNebula ! I’ve resolved the conflicts and pushed the updates. Could you please re-approve the PR and approve the pending Netlify workflow? It’s being blocked for deploy preview and final merge.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants