Hello ICP developer community!
My name is Jordan Last, the leader of Demergent Labs, an independent company and DFINITY grantee which has been developing the Azle (TypeScript/JavaScript) and Kybra (Python) CDKs since 2022.
Azle is now in its release candidate phase and is edging ever closer to its 1.0 release. Azle 1.0 will indicate that Demergent Labs is confident in Azle’s use as a production-ready CDK on ICP.
As part of this process, Demergent Labs is undertaking its own in-depth internal security reviews. We would now like to invite the community to participate in reviewing Azle’s security. We invite you to participate in any depth or capacity which you would like. Please make sure to strictly follow Azle’s official security policy (e.g. sensitive findings must be kept private until addressed).
We are not offering monetary rewards nor compensation. Any work done would be strictly voluntary contributions to an open source project. At your discretion, we will publish your review under your name or username in the Azle GitHub repository. Even if you decide to remain anonymous, we do ask to be able to publish your findings after coordination with us to address them.
For any members of the community who decide to help us review Azle’s security, we are deeply grateful. Please help us to bring Azle to its 1.0 production-ready release. Thank you!
If you are interested, we are willing to work very closely with you to get you up-to-speed with the codebase, answer any questions, and guide you as needed during your review. If you’ve ever been interested in the lower-level workings of a CDK/SDK, this is a great opportunity for 1 on 1 guidance.
Below are some important resources for those interested. Please reach out to me (Jordan Last, lastmjs) at lastmjs@demergentlabs.org, @lastmjs on Telegram, or @lastmjs on X for further collaboration.
Azle GitHub repository: GitHub - demergent-labs/azle: A WebAssembly runtime for TypeScript and JavaScript on ICP
Scope: Azle’s stable mode, generally found in the src/stable directory: azle/src/stable at main · demergent-labs/azle · GitHub