chore: sync published workspace versions - #529
Merged
Merged
Conversation
ty-everett
approved these changes
Sep 10, 2026
ty-everett
left a comment
Collaborator
There was a problem hiding this comment.
Approved as the generated dependency and image-version synchronization for the verified PR #486 npm release.
|
|
Review the following changes in direct dependencies. Learn more about Socket for GitHub.
|
Quaakee
added a commit
to Quaakee/ts-stack
that referenced
this pull request
Sep 15, 2026
Quaakee
added a commit
to Quaakee/ts-stack
that referenced
this pull request
Sep 19, 2026
Quaakee
added a commit
to Quaakee/ts-stack
that referenced
this pull request
Sep 25, 2026
… fork main (bsv-blockchain#59) [skip ci] Merge base 0b01acd. Upstream's auth rework (134e4ec session-identity binding, 813d8b9 auth policy, e5c5334 BRC-104 empty-body preimage, cc1256c discovery deadlines, e095155 empty AES-GCM payloads) and the wallet-toolbox correctness fixes (476b135/eacfe4b63, c52049f) are taken intact; the fork's bsv-blockchain#529 zero-field initial-response certificate proofs and bsv-blockchain#520 exact signed-failed-action resume are re-applied on top. Versions follow upstream (@bsv/sdk 2.8.2, @bsv/wallet-toolbox 2.14.0). Conflicted files: - packages/sdk/src/auth/Peer.ts: upstream's file is the base. bsv-blockchain#529's session snapshot is upstream's own PeerSession.certificatePolicy (same contract: locally retained, never on the wire) and bsv-blockchain#529's "Wrong peer" check is upstream's initialResponse identity check. Re-applied on top: the policy the session store actually retained is captured in authenticateInitialResponse before upstream's `certificatePolicy ??=` refill and is the only zero-field authority (validateCertificates(..., allowZeroFields = retained != null)); the standalone certificateResponse path passes allowZeroFields=false. No upstream check is weakened, reordered or bypassed. - packages/sdk/src/auth/types.ts: upstream's certificatePolicy and pendingCertificateRequests fields; the fork's requestedCertificates field is dropped as redundant and its zero-field contract folded into the certificatePolicy doc comment. - packages/sdk/src/auth/utils/validateCertificates.ts (auto-merged, reviewed): upstream's bounded snapshots, 100-certificate cap and non-empty disclosed field assertion, with bsv-blockchain#529's allowZeroFields early return before decryptFields for an exact fields=[] request with an empty/nullish keyring. - packages/sdk/package.json: upstream 2.8.2. - packages/sdk/CHANGELOG.md, packages/sdk/README.md: upstream entries kept; the fork's zero-field notes re-worded for the 2.8.2 base and certificatePolicy. - packages/wallet/wallet-toolbox/src/storage/methods/attemptToPostReqsToNetwork.ts: upstream's typed imports and input-spend-evidence double-spend classification plus the fork's exact-resume lock/post/updateExactResume path; the only textual conflict was updateExactResume's placement. - packages/wallet/wallet-toolbox/src/storage/methods/processAction.ts: upstream's argument normalization, complete-set gating and delayed-share error status plus the fork's resumeFailedSendWith call and exact-resume scheduling; the now-unused transactionIds local is dropped. - packages/wallet/wallet-toolbox/README.md: both sections kept. - governance/package-release-notes.json: upstream's 2.8.2 sdk and 2.14.0 toolbox records with the fork's bsv-blockchain#529/bsv-blockchain#520 sentences appended. - docs/packages/sdk/bsv-sdk.md: manifest version 2.8.2, upstream prose plus the fork's zero-field paragraph. - docs/reference/package-api-migrations.md, docs/reference/stack-facts.md: regenerated with scripts/package-documentation.mjs and scripts/generate-stack-facts.mjs. - governance/repository-health/baselines.json: upstream's publicPackageVersions (every manifest version is upstream's); scripts/repository-health.mjs reports 0 findings. Test adaptations: Peer.zeroFields.test.ts follows upstream's store contract (claimMessageNonce/claimInitialRequestNonce, certificatePolicy, upstream error texts, responder-side authentication before a standalone response); Peer.certificatePolicy.test.ts expects validateCertificates' explicit allowZeroFields=false on the standalone path. The bsv-blockchain#520 fixtures (test/atlas/exact-resume.cjs, real-wpm.cjs) pass chain 'mock' to StorageKnex, Monitor and Wallet, matching MockServices as upstream's own tests do, because upstream's Monitor now requires monitor, services and ChainTracks to agree. Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.



Program and scope
Impact
Affected services and intended patch versions are the changed infra package manifests in this PR.
Verification
Security and dependencies
Dependency evidence
Release and operations
The protected infrastructure release builds Linux/amd64 images, rejects high and critical findings, publishes immutable GHCR tags, and attaches SBOM, provenance, and signature evidence after merge. Existing immutable tags remain the rollback path.
Completion evidence