Skip to content

Add constant.finance to whitelist - #1848

Open
wujinzhou wants to merge 1 commit into
phantom:masterfrom
wujinzhou:constant-finance
Open

Add constant.finance to whitelist#1848
wujinzhou wants to merge 1 commit into
phantom:masterfrom
wujinzhou:constant-finance

Conversation

@wujinzhou

@wujinzhou wujinzhou commented Sep 8, 2026

Copy link
Copy Markdown

Summary

We would like to add *.constant.finance to whitelist.yaml after discovering that the Phantom browser extension currently identifies our website as malicious.

About us

Constant Finance is a DeFi lending protocol currently under development. Our application is in public beta on a testnet and does not interact with mainnet.

The issue

When users visit our application, the Phantom browser extension blocks the page and displays the following warning:

Phantom believes this website is malicious and unsafe to use.

This site has been flagged as part of a community-maintained database of known phishing websites and scams.

We believe this is a false positive. Since the application currently operates only on a testnet, we would appreciate any information about the signals or source used to classify our domain as risky. Understanding the reason would help us investigate and address any specific concerns.

Steps we have taken

We have:

  • Submitted a Phantom dApp review request.
  • Searched for the appropriate process to report and resolve a false positive.
  • Reviewed the publicly available information and similar reports from other projects.

The warning page directs developers to this repository to report an issue. However, the repository README states that the fuzzylist and whitelist are not currently in active use, so it is unclear whether this change can affect the warning or where its underlying classification originates.

We are submitting this PR both as a request for assistance and as a public record that constant.finance and its official subdomains belong to the Constant Finance project.

Request

We have noticed that other legitimate projects have encountered similar warnings, including several requests in this repository.

It would be extremely helpful if Phantom could provide a clear public channel where developers can:

  • Report false-positive domain classifications.
  • Learn which source or risk signal caused a warning.
  • Follow the review status.
  • Receive confirmation when a classification has been updated.

We would be grateful for guidance on the correct next step and for a review of constant.finance.

Thank you for your time and help.

Summary by CodeRabbit

  • New Features

    • Added support for *.constant.finance through whitelist configuration.
  • Configuration

    • Retained nftplus.io in the whitelist.

@coderabbitai

coderabbitai Bot commented Sep 8, 2026

Copy link
Copy Markdown

Review Change StackReview Change Stack

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration

Configuration used: Organization UI

Review profile: CHILL

Plan: Advanced

Run ID: b878276a-acdd-4895-85ed-c0a75138417f

📥 Commits

Reviewing files that changed from the base of the PR and between 5030186 and cb86047.

📒 Files selected for processing (1)
  • whitelist.yaml

Included review availability: Your plan provides up to 1 included review per hour; 0 remain after this review.


📝 Walkthrough

Walkthrough

The whitelist now includes *.constant.finance and continues to include nftplus.io.

Changes

Whitelist Update

Layer / File(s) Summary
Add constant.finance pattern
whitelist.yaml
The whitelist adds *.constant.finance and retains nftplus.io.

Priority: ⬇️ Low — Defer the whitelist update because it is a narrow two-line domain-classification change for a reported testnet false positive.

Merge Risk: ⚪ Minimal · up to cb860

This adds constant.finance to the whitelist so matching sites are no longer classified as malicious. No concrete current-head merge-blocking risk remains.

🚥 Pre-merge checks | ✅ 5
✅ Passed checks (5 passed)
Check name Status Explanation
Description Check ✅ Passed Check skipped - CodeRabbit’s high-level summary is enabled.
Title check ✅ Passed The title clearly and concisely describes the main change: adding constant.finance to the whitelist.
Docstring Coverage ✅ Passed No functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check. Docstring coverage is scoped to functions touched by this diff. Analyzed 0 functions across 0…
Linked Issues check ✅ Passed Check skipped because no linked issues were found for this pull request.
Out of Scope Changes check ✅ Passed Check skipped because no linked issues were found for this pull request.
✨ Finishing Touches
🧪 Generate unit tests (beta)
  • Create PR with unit tests

Comment @coderabbitai help to get the list of available commands.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant