The Zap team engaged Guardian to review the security of its upgradeable token contract. On the 30th of September 2 auditors reviewed the source code in scope.
- Published
- Language
- Solidity
- Chains
- Base
- Sector
- Tokens
- 0 Critical
- 0 High
- 0 Medium
- 1 Low
- 0 Informational
Scope
Overview
The Zap team engaged Guardian to review the security of its upgradeable token contract. On the 30th of September 2 auditors reviewed the source code in scope.
Findings 1
-
L-01 Low Security Contract Suggestion Security Contact Acknowledged
Description
The ZapToken contract does not include a security contact in it’s NatSpec.
This is a best practice as it allows the deployer to direct communication of potential vulnerabilities, reducing the risk of a miscommunication or lack of reporting when a security vulnerability arises.
Recommendation
Consider adding a security contact in a NatSpec comment above the ZapToken contract. For example, the
@custom:security-contact XXX@XXX.comconvention is recommended.Resolution
ZAP Team: Acknowledged.
No findings match.
More from Zap
Put your code through the same review.
This review started with a conversation about scope. Tell us what you are building and we will plan yours with you.
