Whitelist monero-web.com — false positive#1809
Conversation
|
No actionable comments were generated in the recent review. 🎉 ℹ️ Recent review info⚙️ Run configurationConfiguration used: Organization UI Review profile: CHILL Plan: Pro Run ID: 📒 Files selected for processing (1)
📝 WalkthroughWalkthroughThe whitelist configuration file was updated to fix formatting of an existing entry and extend the domain whitelist. The Changes
🚥 Pre-merge checks | ✅ 3✅ Passed checks (3 passed)
✏️ Tip: You can configure your own custom pre-merge checks in the settings. ✨ Finishing Touches🧪 Generate unit tests (beta)
Comment |
|
The workflow changes were unintentionally pulled in via a fork sync — the core change is just adding monero-web.com to whitelist.yaml. Happy to clean this up if needed, but the workflow pin changes are harmless security improvements. Could a maintainer please review? |
Website URL: monero-web.com
Reason for Request: > This is a false positive block. monero-web.com is a non-custodial, open-source web interface for the Monero (XMR) blockchain. It does not store user private keys or transmit sensitive data to any server.
Technical Details:
Client-Side: All transaction signing and key generation happen locally in the user's browser.
Transparency: The site is fully auditable. Source code is hosted here: https://github.com/Medtabka/monero-web
Community Trust: Project announced and discussed with the Monero community here: https://www.reddit.com/r/Monero/comments/1skgqc4/monerowebcom_opensource_noncustodial_monero/
It appears the domain was automatically flagged due to containing the keyword "monero." Please review the source code and whitelist this domain. Thank you!
Summary by CodeRabbit
monero-web.comto the whitelist.