Skip to content

chore: add SM+SR ET factories config#191

Merged
TheDZhon merged 3 commits into
mainfrom
sm-sr-et-yaml
Jul 14, 2026
Merged

chore: add SM+SR ET factories config#191
TheDZhon merged 3 commits into
mainfrom
sm-sr-et-yaml

Conversation

@tamtamchik

Copy link
Copy Markdown
Member

Builds on #189: converts the config to YAML, pins the audited commit with a link to the 07-2026 MixBytes Easy Track Factories audit, tags the OZ dependency as v4.3.2, and declares the known diffs:

  • source: verified sources on Etherscan carry root-relative imports, GitHub uses relative ones (import hunks only, scoped via line_ranges);
  • bytecode: cbor_metadata only — the metadata hash covers source file hashes, so the rewritten imports change it while the runtime code matches byte-for-byte.

Run is green: 9 allowed source + 9 allowed bytecode diffs, 0 failures.

@tamtamchik
tamtamchik requested a review from a team as a code owner July 13, 2026 20:37
@tamtamchik
tamtamchik requested a review from Copilot July 13, 2026 20:38

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Adds a new YAML config sample for DiffyScan to verify Easy Track factory contracts for CSMv3, CMv2, and SRv3 on Ethereum mainnet, with an audited upstream commit pin and explicitly allowlisted known source/metadata-only differences.

Changes:

  • Introduces a mainnet SM+SR Easy Track factories config in YAML format.
  • Pins the audited lidofinance/easy-track commit and adds an OpenZeppelin v4.3.2 dependency pin.
  • Declares expected diffs: import-path-only source hunks and CBOR-metadata-only bytecode differences.

💡 Add Copilot custom instructions for smarter, more guided reviews. Learn how to get started.

@TheDZhon TheDZhon left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM, should it be in CI or not though?

@TheDZhon
TheDZhon merged commit e789fe0 into main Jul 14, 2026
17 checks passed
@TheDZhon
TheDZhon deleted the sm-sr-et-yaml branch July 14, 2026 10:36
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants