flashbots / flashbots/mev-boost-relay
Offering a free security review — no strings attached
- Dominant language
- Go
- Stars
- 498
- Forks
- 147
- PR merge metrics
- No merged PRs in 30d
Description
Hi @flashbots 👋
I'm **Aditya**, a security researcher at **Aditya Security Labs**.
I'd like to offer your project a **free, no-obligation security review**. Here's what I'll do:
- Review your authentication, authorization, and API security
- Check for common high-impact vulnerabilities (IDOR, SSRF, injection, logic flaws)
- Report *all* findings to you **privately and responsibly** — nothing public without your consent
- Provide a short written summary of what I find (even if it's "all clear")
**Why free?** I'm building my open-source portfolio and I genuinely want to contribute to the community. I've previously found and reported vulnerabilities in major platforms and would love to help your project too.
**No catch.** If you're interested, just reply here or email me. If you'd rather I not, no worries — I won't touch the codebase without permission.
Looking forward to hearing from you!
— Aditya
Aditya Security Labs
https://github.com/sivaadityacoder
> *This offer is made in good faith and in compliance with your SECURITY.md disclosure policy.*
Contributor guide
Research direction
No files, tests, or entry points are identified. Before any work begins, confirm that the maintainers want an authorized security review and agree on its scope, reporting process, and definition of done.
Written by the indexing model from the issue text.
Assessment
- Tech stack
- go
- Domain
- api, authentication, authorization, security
- Issue type
- Feature
- Difficulty
- 5/5
- Estimated time
- Over a week
- Activity status
- Quiet
- Clarity
- Needs clarification
- Newbie friendliness
- 10/100