Vac 2025/12/29

highlights

  • BI: Renamed GitHub sources and fixed dbt model issues to stabilize synchronization pipelines for reporting.
  • BI: Started LLM benchmarks across models and tooling to inform future RAG evaluation decisions for the team.
  • BI: Finished finance dashboard dbt models and began building dashboard views for weekly internal reporting.
  • DST: Status-go chat protocol benchmark setup nearly finished, with runs and data collection queued next week.
  • DST: Added go-libp2p test node Prometheus metrics, aligning names for shared Grafana dashboards across teams.
  • DST: Implemented Vaclab bandwidth-aware scheduler and documented scheduling logic with validation results in a Notion write-up.
  • Infra: Investigated missed validator proposals, updated cachix, and added ultrasound to Hoodi MEV-Boost list updates.
  • Infra: Continued Status mobile signing and Nix build work, unblocking iOS updates and Android PR signing.
  • Infra: Cleaned DigitalOcean space after security alert and documented CiviCRM backup procedure for office ops.
  • Nim: Landed Nimble fixes for package list reading, parser warnings, and bootstrap config paths updates.
  • Nim: Advanced confutils updates and core fixes while tracking closure iterator traceback issues in Nim.
  • Nim: Progressed intops refactor and langserver shutdown debugging with new PRs and issue analysis work.
  • P2P: Advanced IPv6 support with CI interop updates, address work, and transport review follow-through across repos.
  • P2P: Shipped maintenance PRs improving docs, interop cosmetics, and flaky test behavior for nim-libp2p core.
  • P2P: Continued QUIC stabilization with nim-lsquic CI improvements and dependency cleanup for Windows builds support.
  • QA: Expanded Status-go wallet testing with token-gated community cases and tracked new blocker issues for releases.
  • QA: Addressed Status Desktop maintenance items including join-community, crash, and E2E regression fixes this week.
  • QA: Closed emoji reactions, local backup, and Qt6 migration activities in the desktop QA track.
  • RFC: Drafted mantle specification work for Nomos and opened the initial RFC index PR this week.
  • RFC: Produced bootstrap sync draft for Nomos and shared the specification PR for early review.
  • RFC: Completed RFC index maintenance responses while drafting LIPs definitions and follow-up items from calls.
  • SC: Fixed KarmaAirdrop delegatee validation to prevent invalid first-claim delegatees in production flows and tests.
  • SC: Addressed PoseidonHasher modulo handling and StakeManager emergency pause signaling changes across contracts this week.
  • SC: Advanced contract maintenance with MP variable removal and RLN CI asm-keccak256 rule bypass updates.
  • Security: Continued secure signing environment documentation and annual signing account revalidation work for treasury process.
  • Security: Completed broad security code reviews across PRs, CI changes, and dependency updates this week.
  • Security: Performed proactive Vulma/IR reviews, including CodeQL follow-ups and incident remediation support across teams recently.
  • TKE: Continued Logos digital twin modeling in Machinations to refine stock-and-flow diagrams for planning work.
  • TKE: Updated the Logos token sales spreadsheet and reviewed EcoDev support status for Q1 planning.
  • TKE: Continued reading on virtual worlds and economies to inform research support work this quarter.
  • Web: Released WETH vault updates and multiple Status Hub fixes while debugging TVL on VPN.
  • Web: Built Karma UI updates and investigated Vercel bot protection impacts during Status Hub TVL debugging.
  • Web: Progressed SEO and maintenance work, including contribution portal updates and press engine fixes this week.

vac:bi:

  • vac:bi:ift:2025q4-github-extractions
    • Renamed sources and fixed dbt model issues for GitHub synchronization.
  • vac:bi:ift:2025q4-llm-rag
    • Started LLM benchmarks across models and tools.
  • vac:bi:ift:2025q4-finance-dashboard
    • Finished dbt models and started the finance dashboard.

vac:dst:

vac:infra:

  • lido & ethereum validator
    • Investigated missed proposal.
    • Updated cachix.
    • Added ultrasound to the Hoodi MEV-Boost list.
  • misc
    • Cleaned DigitalOcean space following a security alert.
  • status
    • Fixed broken Status Go update for the iOS signing PR.
    • Continued Android PR signing work.
    • Worked on the Nix build.
  • office
    • Documented the CiviCRM backup procedure.

vac:nim:

vac:p2p:

vac:qa:

vac:rfc:

vac:sc:

vac:sec:

  • ift:2025q4-secure-signing-environment:build-cold-signing-workstation
    • Continued refining documentation about the secure signing environment.
  • ift:2025q4-treasury-continuity-plan:signing-accounts-revalidation
    • Continued annual revalidation of signing accounts (request for signing).
  • ift:2025q4-treasury-continuity-plan:implement-backup-requirements
    • Tested local safe environment multisig (prepare tx for rejection).
  • ift:2025q4-cicd-security-review:code-reviews
    • Reviewed newly opened IFT PRs for security feature usage, key handling, and secret lifecycle boundaries (status-go#7237).
    • Audited dApp PRs for navigation logic, origin enforcement, permission checks, and sandbox escape regressions.
    • Reviewed storage and persistence changes across Nimbus, Logos, and Keycard for plaintext handling risks.
    • Examined dependency update PRs for supply-chain risk and unexpected post-install behavior.
    • Reviewed CI and GitHub Actions changes for permission scope increases, token usage, and secret exposure.
  • ift:2025q4-vulma-and-ir:proactive-review
  • ift:2025q4-vulma-and-ir:follow-ups
    • Re-reviewed CodeQL findings after recent merges.
    • Performed secondary reviews on PRs labeled security or infra.
    • Coordinated with maintainers on high-risk PRs to unblock reviews.
    • Investigated and supported remediation of the Status-361 S3 bucket incident (report).
  • admin/misc
    • OOO: 5 CC days.

vac:tke:

  • admin
    • OOO: 7 CC days.
  • vac:tke:ift:logos-token:logos-digital-twin
    • Continued implementing Logos stock and flow diagrams in Machinations.
  • vac:tke:ift:logos-token::logos-token-sales
    • Updated the spreadsheet.
  • vac:tke:ift:support-to-ift-units::ecodev-support
    • Reviewed current state.
  • vac:tke:ift:support-to-ift-units:reading-by-jarrad
    • Continued reading about virtual worlds and economies.

vac:web: