Skip to content

Add Cantina audit report for the rounding and billing change (v1.1.0, #90) - #93

Merged
amiecorso merged 3 commits into
mainfrom
ruohan/add-pr90-audit
Jul 27, 2026
Merged

Add Cantina audit report for the rounding and billing change (v1.1.0, #90)#93
amiecorso merged 3 commits into
mainfrom
ruohan/add-pr90-audit

Conversation

@RuoHan-Chen

@RuoHan-Chen RuoHan-Chen commented Jul 24, 2026

Copy link
Copy Markdown
Collaborator

Summary

Adds the Cantina audit report covering the rounding and billing change from #90 (the fixed-fee feeAmount product-requirement change shipped in v1.1.0), and lists it in the security audit tables alongside the existing reports.

  • File: audits/report-cli-cantina-eb1cc8bc-577c-422d-ad76-db7495f29a5a-2026-07-22-coinbase-commerce-payments-pr-90.pdf
  • Auditor: Cantina (Spearbit)
  • Date: 2026-07-22
  • Scope: Rounding and billing fix #90 — rounding and billing change (v1.1.0)

Changes

  • Add the Cantina audit report PDF to audits/
  • Add a row to the Security Audits table in README.md
  • Add the matching row to the audit table in docs/Security.md

This completes the audit provenance for the v1.1.0 rounding and billing change: the prior committed reports predate #90, and this report is the review of that specific change.

Co-authored-by: OpenCode <opencode-noreply@coinbase.com>
@cb-heimdall

cb-heimdall commented Jul 24, 2026

Copy link
Copy Markdown
Collaborator

✅ Heimdall Review Status

Requirement Status More Info
Reviews 1/1
Denominator calculation
Show calculation
1 if user is bot 0
1 if user is external 0
2 if repo is sensitive 0
From .codeflow.yml 1
Additional review requirements
Show calculation
Max 0
0
From CODEOWNERS 0
Global minimum 0
Max 1
1
1 if commit is unverified 1
Sum 2

Co-authored-by: OpenCode <opencode-noreply@coinbase.com>
Comment thread docs/Security.md Outdated
| Spearbit audit 1 | 04/01/2025 | [Report](/audits/Cantina-Report-04-01-2025.pdf) |
| Coinbase Protocol Security audit 3 | 04/15/2025 | [Report](/audits/CommercePaymentsAudit3CoinbaseProtoSec.pdf) |
| Spearbit audit 2 | 04/22/2025 | [Report](/audits/Cantina-Report-04-22-2025.pdf) |
| Spearbit audit 3 (rounding and billing fix, #90) | 07/22/2026 | [Report](/audits/report-cli-cantina-eb1cc8bc-577c-422d-ad76-db7495f29a5a-2026-07-22-coinbase-commerce-payments-pr-90.pdf) |

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

only feedback is maybe let's call this "rounding and billing change, v1.1.0" because "fix" implies something was broken when really it was just that we had need for a different product requirement around rounding

… review

'Fix' implied something was broken; it was a product-requirement change to rounding/billing. Adopts @amiecorso's suggested wording.

Co-authored-by: OpenCode <opencode-noreply@coinbase.com>
@RuoHan-Chen RuoHan-Chen changed the title Add Cantina audit report for PR #90 (rounding and billing fix) Add Cantina audit report for the rounding and billing change (v1.1.0, #90) Jul 27, 2026
@RuoHan-Chen

Copy link
Copy Markdown
Collaborator Author

Good call — updated to "rounding and billing change, v1.1.0" in the title, PR body, and both audit tables (README + docs/Security.md). Agreed that "fix" mischaracterized it; it was a product-requirement change to rounding/billing, not a bug fix. Thanks @amiecorso.

@RuoHan-Chen
RuoHan-Chen requested a review from amiecorso July 27, 2026 15:26
@amiecorso
amiecorso merged commit ff84ce2 into main Jul 27, 2026
6 checks passed
@amiecorso
amiecorso deleted the ruohan/add-pr90-audit branch July 27, 2026 15:34
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants