IFT-TS 2026/01/19

top highlights

  • Released nim-libp2p v1.15.0 and landed gossipsub support for extensions control message.
  • Status Desktop E2E tests are now running in CI on Windows as well.
  • Implementing Logos stock and flow diagrams in Machinations.
  • Status Web improvements spanning translations, vault enablement and LI.FI swaps.

team highlights

  • BI: Expanded Circle and Forum data pipelines with Telegram extraction and dashboard updates.
  • BI: Continued finance reporting dashboard work and People Ops external contributor extraction.
  • DST: Published nim-libp2p v1.15.0 regression report and documented Status nWaku discovery issues.
  • DST: Advanced lab deployment with new components, Kyverno rules, and end-to-end workflow validation.
  • DST: Expanded DST tooling with merged deployment script improvements and new nim-libp2p deployment builders.
  • Infra: Rolled out NixOS, Geth, and Nethermind upgrades and restored stable MEV-Boost builds.
  • Infra: Improved CI tooling with new licensing checks, LevelDB migration, and Jenkins query updates.
  • Infra: Fixed Status mobile proxy issues and continued Logos app signing and DigiCert authorization.
  • Nim: Shipped Nimble 1.0.0 fixes for lockfile handling, defaults, and CI stability.
  • Nim: Progressed json-rpc EthJson flavors and intops/Stint integration plus documentation updates.
  • P2P: Released nim-libp2p v1.15.0, maintenance and multiple Kad-DHT fixes across core repos.
  • P2P: Landed gossipsub extensions support and advanced Logos core module integration work.
  • QA: Expanded RLN negative-path test coverage and advanced token-gated community functional tests.
  • QA: Added messaging network-condition tests and continued nim-libp2p Kad-DHT test refactors.
  • QA: Status Desktop e2e tests are now running in CI also on a windows machine.
  • RFC: Drafted Bedrock Service Declaration Protocol and Architecture Overview RFCs for Nomos.
  • RFC: Merged approved RFCs and continued LIPS process planning and adversarial spec review.
  • SC: Researched NSSA attestation systems, including EAS and LSSA contracts, and updated docs.
  • SC: Maintained Status L2 contracts with StakeVault refactor for safer call patterns.
  • Sec: Completed focused security code reviews across repos, emphasizing key management and CI workflows.
  • Sec: Monitored incidents and triaged new vulnerability reports across dependencies and infrastructure.
  • TKE: Continued Logos digital twin and validator behavior modeling for stress-test scenarios.
  • TKE: Progressed XPRIZE outputs and Logos tokenomics support with LSSA prep work.
  • TKE: Implementing Logos stock and flow diagrams in Machinations.
  • Web: Advanced SN Hub self-hosting, SEO, translations, and GUSD vault enablement.
  • Web: Shipped wallet extension updates for LI.FI swaps and global password context.
  • Web: Maintained IFT web tooling and contribute portal guidelines, plus Logos CMS research.

ift-ts:bi:

ift-ts:dst:

ift-ts:infra:

  • lido
    • Rolled out NixOS upgrades to the fleet.
    • Rolled out Geth and Nethermind security upgrades.
    • Restored stable MEV-Boost builds and started testing Ultrasound relay re-add.
    • Submitted Q4 2025 quarterly data.
  • eth2
    • Reduced Nethermind data volumes and resynced nodes.
  • ci
    • Worked on repo licensing detection and Windows 11 VM license activation.
    • Improved build list formatting and multi-org support in GH comment manager.
    • Migrated comment manager from LokiJS to LevelDB.
    • Researched Terraform CI automation and improved Jenkins version querying.
  • bi
    • Deployed a test Kubernetes cluster.
  • office
    • Fixed CiviCRM access, DB resource usage, and backup/restore procedure.
    • Fixed Watchtower issues with the Vesting Finance tool.
    • Fixed BambooHR and Keycloak sync automation.
    • Backed up the OpenKM Pro Docker image.
  • status
    • Fixed failing market proxy requests on iOS.
    • Created CI jobs for new Mobile E2E tests and planned mobile build refactors.
    • Supported push-notifications setup for the new Mobile app.
  • logos
    • Continued Logos app POC releases/signing and DigiCert org authorization.
  • nimbus
    • Fixed cross-compilation of Nimbus-eth2 releases and improved Nim compiler build errors.
    • Started nimbus-build-system derivation work and investigated Hoodi sync issues.
  • waku
    • Researched DB errors on status.prod fleet and discussed RLN prover architecture.
  • sites
    • Started self-hosting the Status Hub website and fixed contribute.logos.co builds.
    • Fixed a dangling MailGun DNS record.
  • hq
    • Resumed Waku logs cleanup in Elasticsearch and investigated Wazuh manager cert issues.

ift-ts:nim:

ift-ts:p2p:

ift-ts:qa:

ift-ts:rfc:

ift-ts:sc:

ift-ts:sec:

  • ift:2026q1-cicd-security-review:focused-code-reviews
    • Reviewed PRs across IFT, Status, Waku, and VAC for security-sensitive changes.
    • Audited cryptography, key management, signing, and secret handling paths (including Keycard).
    • Identified Keycard components for deeper audit and started bug bounty discussion.
    • Audited serialization/parsing/validation for boundary and malformed input cases.
    • Reviewed storage, persistence, and config changes for unsafe defaults or exposure.
    • Examined dependency updates/lockfiles for supply-chain risk.
    • Reviewed CI/GitHub Actions/workflow changes for permission drift and secrets usage.
    • Validated secret scanning alerts.
  • ift:2026q1-vulma-and-ir:incident-monitoring
    • Monitored new vulnerabilities and followed up on recently closed incidents.
    • Investigated Waku incident waku-27.
    • Investigated Mailgun domain hijack Status-359.
    • Verified infra fix dropping unused domains (infra-misc commit).
    • Ran spot checks on build logs and alerts for anomalies.
    • Tracked ecosystem incidents for potential IFT impact.
  • ift:2026q1-vulma-and-ir:triage-and-planning
    • Triaged CodeQL, Dependabot, and third-party reports.
    • Unsanitized input issue mdast-util-to-hast.
    • Electron ASAR integrity bypass reports dependabot/20 and dependabot/17.
    • Performed secondary reviews on security, infra, and hotfix PRs.
    • Documented areas for deeper review and coordinated remediation ownership.
  • ift:2026q1-finance-automation-bug fixing & support
    • Daily monitoring of Finance executions.
    • Investigated new use cases.
  • ift:2026q1-finance-automation-enhancements
    • Deployed final PO duplicate-identification logic.
    • Found BBHR vs Iplicit org-structure mismatches and isolated impact.
    • Implemented temporary fixes and started testing.
    • Ran daily corrections for unsynchronized data.

ift-ts:tke:

  • ift-ts:tke:ift:logos-token:logos-digital-twin
    • Continued implementing Logos stock and flow diagrams in Machinations.
  • ift-ts:tke:blockchain:stress-test:realistic-validator-model
    • Continued the behavioral model for validators joining and leaving the system.
  • ift-ts:tke:ift:logos-token:fundraise
    • Updated tokenomics data.
  • ift-ts:tke:ift:support-to-ift-units:explore-bi
    • Prepared spreadsheet parameters for the Logos model.
  • ift-ts:tke:ift:support-to-ift-units:reading-by-jarrad
    • Continued reading about virtual worlds and economies.
  • ift-ts:tke:blockchain:stress-test:nomos-dse
    • Reviewed Nomos DSE documents and addressed comments.
  • ift-ts:tke:ift:ecodev:xprize
    • Finished XPRIZE outputs and worked through ecodev feedback.
    • Reviewed the RFP doc.
  • ift-ts:tke:ift:tokenomics-research-forum:betfundme
    • Deferred review of proposed directions (time permitting).
  • misc
    • Played around with LSSA and prepared for discussions with the LSSA team.
    • Continued PS Lisbon prep work.
    • Reviewed gas notes from Moudy.

ift-ts:web: