Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
6 changes: 0 additions & 6 deletions .dockerignore

This file was deleted.

12 changes: 6 additions & 6 deletions .github/workflows/build.yml
Original file line number Diff line number Diff line change
@@ -1,21 +1,21 @@
name: Docker
name: CI
on: [push, 'pull_request']
jobs:
build:
runs-on: ubuntu-latest
steps:
- name: Check out code
uses: actions/checkout@v4
uses: actions/checkout@v7

- name: Install pnpm
uses: pnpm/action-setup@v4
uses: pnpm/action-setup@v6.1.0
with:
package_json_file: 'package.json'

- name: Setup Node.js environment
uses: actions/setup-node@v4
uses: actions/setup-node@v7
with:
node-version: 22
node-version: 24.21.0
cache: 'pnpm'

- name: Install Dependencies
Expand All @@ -37,7 +37,7 @@ jobs:
run: pnpm exec dotenv -c development -- next build

- name: Publish coveralls report
uses: coverallsapp/github-action@master
uses: coverallsapp/github-action@v2.3.8
with:
path-to-lcov: 'coverage/lcov.info'
github-token: ${{ secrets.GITHUB_TOKEN }}
10 changes: 5 additions & 5 deletions .github/workflows/chromatic.yml
Original file line number Diff line number Diff line change
Expand Up @@ -4,17 +4,17 @@ jobs:
chromatic-deployment:
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@v4
- uses: actions/checkout@v7
with:
fetch-depth: 0 #required to retrieve git history

- name: Install pnpm
uses: pnpm/action-setup@v4
uses: pnpm/action-setup@v6.1.0

- name: Setup Node.js environment
uses: actions/setup-node@v4
uses: actions/setup-node@v7
with:
node-version: 22
node-version: 24.21.0
cache: 'pnpm'

- name: Install Dependencies
Expand All @@ -24,7 +24,7 @@ jobs:
run: pnpm build-storybook

- name: Publish to Chromatic
uses: chromaui/action@v13.2.0
uses: chromaui/action@v18.9.4
with:
token: ${{ secrets.GITHUB_TOKEN }}
storybookBuildDir: storybook-static
Expand Down
3 changes: 3 additions & 0 deletions .gitignore
Original file line number Diff line number Diff line change
Expand Up @@ -43,3 +43,6 @@ yarn-error.log*
*.db-wal

*storybook.log

# pnpm
.pnpm-store/
12 changes: 11 additions & 1 deletion CHANGELOG.md
Original file line number Diff line number Diff line change
Expand Up @@ -7,6 +7,15 @@ and this project adheres to [Semantic Versioning](https://semver.org/spec/v2.0.0

## [Unreleased]

## [3.12.7] - 2026-09-22

- Upgrade Node.js to 24.21.0 (LTS) and pnpm to 11.27.1.
- Migrate pnpm build-script approvals from `onlyBuiltDependencies` to `allowBuilds`.
- Add pnpm supply-chain protections: strict dependency builds, a 7-day release-age gate, trust-downgrade checks and blocked transitive exotic sources.
- Replace the git-sourced `ethereumjs-abi` transitive dependency with the equivalent registry release.
- Update GitHub Actions to node24-runtime versions ahead of the node20 runtime removal.
- Remove the obsolete Dockerfile.

## [3.12.6] - 2026-09-21

- Upgrade to Next.js 16 ahead of the 15.x maintenance window closing on 21 Oct 2026.
Expand Down Expand Up @@ -470,7 +479,8 @@ Staking Pools

- First release

[unreleased]: https://github.com/cartesi/explorer/compare/v3.12.6...HEAD
[unreleased]: https://github.com/cartesi/explorer/compare/v3.12.7...HEAD
[3.12.7]: https://github.com/cartesi/explorer/compare/v3.12.7...v3.12.6
[3.12.6]: https://github.com/cartesi/explorer/compare/v3.12.6...v3.12.5
[3.12.5]: https://github.com/cartesi/explorer/compare/v3.12.5...v3.12.4
[3.12.4]: https://github.com/cartesi/explorer/compare/v3.12.4...v3.12.3
Expand Down
17 changes: 0 additions & 17 deletions Dockerfile

This file was deleted.

45 changes: 44 additions & 1 deletion README.md
Original file line number Diff line number Diff line change
Expand Up @@ -8,6 +8,49 @@ This web application shows several informations about Cartesi Proof of Stake:
- action to claim a node through metamask
- action to release a node from the current owner

## Toolchain

This project pins its toolchain, and CI uses the same versions:

- **Node.js 24.21.0** (Active LTS)
- **pnpm 11.27.1**, declared in `packageManager`

pnpm is activated through Corepack, which ships with Node.js 24:

```
$ corepack enable
$ pnpm --version # 11.27.1
```

> Corepack is still flagged Experimental in Node.js 24 and is **not** distributed
> with Node.js 25 or newer. When this project moves past Node.js 24, install pnpm
> directly instead (e.g. `npm install -g pnpm@11.27.1`).

## Package management

Dependency installs are governed by `pnpm-workspace.yaml`. Install with:

```
$ pnpm install --frozen-lockfile
```

The following supply-chain protections are enabled:

- `allowBuilds` — dependency install scripts are **denied unless explicitly
listed**. When a new dependency needs to run a build script, pnpm reports it
and the package has to be added here deliberately.
- `strictDepBuilds: true` — the install fails rather than silently skipping a
dependency whose build script has not been reviewed.
- `blockExoticSubdeps: true` — transitive dependencies may not be pulled from
git repositories or tarball URLs, only from the registry.
- `minimumReleaseAge: 10080` — a newly published version must be at least
7 days old before it can be resolved, which blunts hijacked-release attacks.
- `trustPolicy: no-downgrade` — a package whose trust level drops relative to
its previous releases fails the install.

`overrides` is used to pin transitive dependencies away from vulnerable or
non-registry sources.

## Running locally

This is a [Next.js](https://nextjs.org) application which uses smart contracts deployed by the [pos-dlib](https://github.com/cartesi/pos-dlib) and [staking-pool](https://github.com/cartesi/staking-pool) projects.
Expand Down Expand Up @@ -90,7 +133,7 @@ Check the `.env` to see the available variables. [additional.d.ts](./additional.
Simply run:

```
$ yarn dev
$ pnpm dev
```

### Open application and setup MetaMask
Expand Down
6 changes: 3 additions & 3 deletions package.json
Original file line number Diff line number Diff line change
Expand Up @@ -97,7 +97,7 @@
"@types/humanize-duration": "3.27.4",
"@types/jest": "^30.0.0",
"@types/lodash": "^4.17.24",
"@types/node": "^22",
"@types/node": "^24",
"@types/react": "^19.3.0",
"@types/react-dom": "^19.3.0",
"@types/react-gtm-module": "^2.0.4",
Expand Down Expand Up @@ -127,7 +127,7 @@
"vite": "^7.3.6"
},
"engines": {
"node": "22.x"
"node": "24.x"
},
"packageManager": "pnpm@10.25.0"
"packageManager": "pnpm@11.27.1"
}
Loading
Loading