I want to consolidate everything into one clear, factual message so we can close this out with a definitive answer rather than another round of back-and-forth @artkor.
**First, on Zaino being “not yet ready for use.”** With respect, that is not a criterion in the program. The terms explicitly list Zaino:
Supporting Infrastructure — Zallet, Zaino, and lightwalletd. Findings are capped at High, since defects in these repositories cannot by themselves directly break a core tenet at scale.
Zaino is named as in scope, and the **High cap is precisely how the program already accounts for its role** in the stack. There is no clause anywhere excluding a repository because it is pre-production or because no team has adopted it yet. Introducing that condition now — after the reports were submitted, accepted, remediated, and publicly disclosed — is adding a requirement that was never part of the terms I reported under.
**Second, on severity.** I am not asking anyone to take my word on severity. The program states that *“severity is assigned by the remediation team and/or technical reviewers.”* The Zaino maintainers reviewed these reports, **accepted** them, and assigned the ratings themselves; the corresponding fixes have been merged. These were not my self-assessments. So the findings cannot be waved away as unqualified — they were validated and rated by the people the program designates for exactly that.
**Third, these are exactly the conditions you previously said were required.** You said additional reports would be *“handled separately … once remediation is complete and public advisories can be properly coordinated,”* and that you would bring a contribution to ZCG once the lead developers acknowledged it in updates. That has now happened: the advisories are public, I am credited on each, and the fixes are merged. “ZCG hasn’t received updates from the infra teams” is no longer accurate — **the public advisories are the update.**
For reference, my in-scope, now-public advisories include:
**Zaino:**
- [GHSA-55pv-cqqp-mwj3](Validator Fork Acceptance — Height Equality Used as Sync Truth (No Hash/Work Check) · Advisory · zingolabs/zaino · GitHub)
- [GHSA-h268-r3v6-jqj6](`get_treestate` Proxies Arbitrary Hashes to Validator Without Validation · Advisory · zingolabs/zaino · GitHub)
- [GHSA-j3f2-h3wv-wfr9](`send_raw_transaction` Forwards Unvalidated Hex to Validator · Advisory · zingolabs/zaino · GitHub)
- [GHSA-3whf-vgf2-9w6g](Non-Finalized State Reorg — No Cycle Detection or Depth Limit · Advisory · zingolabs/zaino · GitHub)
**Zebra:**
- [GHSA-84j3-rw4c-gqmj](Peer-Advertised Mempool Transactions Can Stall Tokio Workers via Synchronous Transparent Script FFI Before Policy Rejection · Advisory · ZcashFoundation/zebra · GitHub) (fixed in zebra-6.0.0) @ZcashFoundation
Each was submitted while the program was active, and the closure announcement is explicit that *“reports already submitted before this announcement will be handled under the terms that applied at the time of submission.”*
**Fourth, the “making things public without my consent” point.** The only private message I have ever received from you is your 2 June note:
Hello @ouicate! Please give it a little time. Someone authorized to handle the ZCG reward process will contact you directly with the next steps. Thanks for your patience.
That message contains no confidential information — no technical details, no personal data, nothing sensitive — only a procedural reassurance that someone would contact me. If quoting that single line is what you mean by “making things public without my consent,” please say so directly. If you mean something else, please identify specifically what I disclosed that was not appropriate to share. I don’t think it’s fair to frame a request for a status update as a breach of trust — especially when, more than six weeks later, that 2 June note is still the only substantive thing I have been told.
I’ve engaged in good faith throughout: reported responsibly, worked through remediation, and in the Zaino cases authored the merged fixes myself. I’m simply asking the program to be applied as written. A clear timeline would let us close this cleanly.