⏰ Scheduling your mitigation review

<aside> <img src="/icons/clock_purple.svg" alt="/icons/clock_purple.svg" width="40px" />

Usually we can kick off the mit. review within a few days of judging + mitigations being completed, and they typically run for 5 days.

</aside>

⚙️ Technical guidelines

While judging for your audit is underway, your team should work through whatever mitigations you choose to pursue. For each mitigation, you'll leave a comment on the related C4 finding, linking to the PR that resolves it.

  1. Wherever possible, we ask that you create a single branch in your own organization’s repo containing all related pull requests (PRs). This branch should be based on the commit you used for your Code4rena audit.
  2. Mitigations should be provided in separate pull requests, one per finding. If that is not possible (e.g. because several audit findings stem from the same core problem), then please add the PR link via comment to all relevant findings it resolves.
    1. Most C4 mitigation reviews focus exclusively on reviewing mitigations of High and Medium risk findings. QA mitigations should go in a separate branch.
    2. If you want your mitigation review to include QA or Gas-related PRs, please reach out to C4 staff and let’s chat!
  3. Note that if you provide all fixes in a single PR, and it appears that unrelated issues have been combined, C4 staff may request that you split it apart.
  4. Please also include the following, if applicable:

👥 How C4 mitigation reviews work

During the mitigation review

<aside> ❗ A code freeze is in effect during the mitigation review.

</aside>

After a competitive mitigation review

Once the mitigation review competition ends, C4 staff will give the sponsor team, judge, and participating wardens access to the submissions.