Release digest
Fixed
- CRYPTO-SECURITY-PROVENANCE-COVERAGE (Audit Source Visibility) — Crypto
project headers now show every attached security provenance source instead of
only the first one, so assets such as LayerZero can surface both
DropstabandOfficial Auditswhen the API provides both sources.
Internal
- Added frontend runtime-contract coverage to keep crypto security provenance from being truncated back to one source.
- Verified the targeted frontend runtime-contract tests locally.
- Verified frontend lint and the dashboard production build locally.
- Smoke-tested the local
/app/crypto/layerzeropreview with mocked security sources and confirmed bothSecurity: DropstabandSecurity: Official Auditsrender without a project-not-found state. - Updated release notes for the production-visible crypto security provenance fix. No knowledge-base update is required because this only clarifies an authenticated dashboard source-display behavior and does not introduce public setup, API, or legal guidance.