Skip to content

chore(deps): bump the minor-and-patch group with 22 updates - #37

Open
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/npm_and_yarn/minor-and-patch-a4003ec2b0
Open

dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/npm_and_yarn/minor-and-patch-a4003ec2b0

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Oct 1, 2026

Copy link
Copy Markdown
Contributor

Bumps the minor-and-patch group with 22 updates:

Package From To
@typescript-eslint/eslint-plugin 8.69.0 8.70.1
@typescript-eslint/parser 8.69.0 8.70.1
prettier 3.9.6 3.9.9
@hiero-ledger/sdk 2.87.0 2.89.0
@reown/appkit 1.8.23 1.8.24
@reown/appkit-controllers 1.8.23 1.8.24
@reown/walletkit 1.5.6 1.6.0
@tanstack/react-query 5.102.8 5.104.0
@walletconnect/ethereum-provider 2.24.0 2.25.0
@walletconnect/universal-provider 2.24.0 2.25.0
@x402/core 2.25.0 2.27.0
@x402/hedera 2.25.0 2.27.0
daisyui 5.7.28 5.7.46
next 15.5.25 15.5.26
react 19.2.8 19.3.0
@types/react 19.2.18 19.3.0
react-dom 19.2.8 19.3.0
@types/react-dom 19.2.7 19.3.0
react-hot-toast 2.6.0 2.6.1
viem 2.56.3 2.56.9
eslint-config-next 15.5.25 15.5.26
tsx 4.23.13 4.23.15

Updates @typescript-eslint/eslint-plugin from 8.69.0 to 8.70.1

Release notes

Sourced from @​typescript-eslint/eslint-plugin's releases.

v8.70.1

8.70.1 (2026-09-21)

🩹 Fixes

  • ast-spec: narrow import attribute keys to identifiers and strings (#12879)
  • eslint-plugin: [no-useless-default-assignment] avoid false positives on tuples with a rest element (#12768)
  • eslint-plugin: [no-unnecessary-type-parameters] handle type precedence in the suggestion fixer (#12637)
  • eslint-plugin: [no-explicit-any] use unknown[] for bare any rest parameters (#12818)
  • eslint-plugin: [no-generated-empty-object-type] don't report a mapped type whose keys are not resolved yet (#12854)
  • eslint-plugin: [no-misused-spread] omit WeakMap spread suggestions (#12850)
  • eslint-plugin: [no-unnecessary-type-assertion] false positive for empty object asserted to a type alias of Record (#12869)
  • eslint-plugin: [no-meaningless-void-operator] allow void on assignment expressions (#12873)
  • eslint-plugin: [await-thenable] prevent autofix from breaking code when removing await (#12716)
  • eslint-plugin: [no-unnecessary-parameter-property-assignment] account for parameter reassignment (#12880)
  • eslint-plugin: [unbound-method] treat Intl.Collator.prototype.compare as spec-bound (#12845)
  • eslint-plugin: [no-unnecessary-condition] handle union-keyed index access on the left-hand side of nullish assignment (#12747)
  • eslint-plugin: [no-useless-default-assignment] convert the fixer to a suggestion fixer (#12826)
  • eslint-plugin: [no-misused-promises] handle multiple Promise constituents (#12904)
  • rule-tester: test the final autofix output instead of the first pass (#12867)
  • scope-manager: merge implicit global definitions (#12809)
  • type-utils: match package specifiers on whole path components (#12838)
  • typescript-estree: resolve symlinked paths when matching files to projects (#12725)
  • typescript-estree: add missing < token opening type arguments (#12821)
  • typescript-estree: require string literal import attribute values (#12894)
  • website: prevent playground from breaking down after opening link with the .js file type (#12777)

❤️ Thank You

See GitHub Releases for more information.

... (truncated)

Changelog

Sourced from @​typescript-eslint/eslint-plugin's changelog.

8.70.1 (2026-09-21)

🩹 Fixes

  • eslint-plugin: [no-misused-promises] handle multiple Promise constituents (#12904)
  • eslint-plugin: [no-useless-default-assignment] convert the fixer to a suggestion fixer (#12826)
  • eslint-plugin: [no-unnecessary-condition] handle union-keyed index access on the left-hand side of nullish assignment (#12747)
  • eslint-plugin: [unbound-method] treat Intl.Collator.prototype.compare as spec-bound (#12845)
  • eslint-plugin: [no-unnecessary-parameter-property-assignment] account for parameter reassignment (#12880)
  • eslint-plugin: [await-thenable] prevent autofix from breaking code when removing await (#12716)
  • eslint-plugin: [no-meaningless-void-operator] allow void on assignment expressions (#12873)
  • eslint-plugin: [no-unnecessary-type-assertion] false positive for empty object asserted to a type alias of Record (#12869)
  • eslint-plugin: [no-misused-spread] omit WeakMap spread suggestions (#12850)
  • eslint-plugin: [no-generated-empty-object-type] don't report a mapped type whose keys are not resolved yet (#12854)
  • eslint-plugin: [no-explicit-any] use unknown[] for bare any rest parameters (#12818)
  • eslint-plugin: [no-unnecessary-type-parameters] handle type precedence in the suggestion fixer (#12637)
  • eslint-plugin: [no-useless-default-assignment] avoid false positives on tuples with a rest element (#12768)

❤️ Thank You

See GitHub Releases for more information.

You can read about our versioning strategy and releases on our website.

8.70.0 (2026-09-07)

🚀 Features

  • eslint-plugin: [no-generated-empty-object-type] add rule (#12730)

🩹 Fixes

  • eslint-plugin: [no-deprecated] report deprecated imported values used in object shorthand properties (#12780)
  • eslint-plugin: [no-unnecessary-condition] no false positive on RHS of a nested logical expression (#12728)
  • eslint-plugin: [member-ordering] don't report fields that read fields declared before them (#12729)

❤️ Thank You

... (truncated)

Commits
  • 23d38ce chore(release): publish 8.70.1
  • 9d82e4b chore: expand eslint-plugin rules test files glob (#12878)
  • f7482f6 fix(eslint-plugin): [no-misused-promises] handle multiple Promise constituent...
  • 2673044 docs(eslint-plugin): [prefer-promise-reject-errors] add option sections and e...
  • 8f141a2 fix(eslint-plugin): [no-useless-default-assignment] convert the fixer to a su...
  • 479cd85 chore: enable assertion option requireData for all rule tests (#12816)
  • f3c190c fix(eslint-plugin): [no-unnecessary-condition] handle union-keyed index acces...
  • b1993df fix(eslint-plugin): [unbound-method] treat Intl.Collator.prototype.compare as...
  • da394bc fix(eslint-plugin): [no-unnecessary-parameter-property-assignment] account fo...
  • 4a742ff fix(eslint-plugin): [await-thenable] prevent autofix from breaking code when ...
  • Additional commits viewable in compare view

Updates @typescript-eslint/parser from 8.69.0 to 8.70.1

Release notes

Sourced from @​typescript-eslint/parser's releases.

v8.70.1

8.70.1 (2026-09-21)

🩹 Fixes

  • ast-spec: narrow import attribute keys to identifiers and strings (#12879)
  • eslint-plugin: [no-useless-default-assignment] avoid false positives on tuples with a rest element (#12768)
  • eslint-plugin: [no-unnecessary-type-parameters] handle type precedence in the suggestion fixer (#12637)
  • eslint-plugin: [no-explicit-any] use unknown[] for bare any rest parameters (#12818)
  • eslint-plugin: [no-generated-empty-object-type] don't report a mapped type whose keys are not resolved yet (#12854)
  • eslint-plugin: [no-misused-spread] omit WeakMap spread suggestions (#12850)
  • eslint-plugin: [no-unnecessary-type-assertion] false positive for empty object asserted to a type alias of Record (#12869)
  • eslint-plugin: [no-meaningless-void-operator] allow void on assignment expressions (#12873)
  • eslint-plugin: [await-thenable] prevent autofix from breaking code when removing await (#12716)
  • eslint-plugin: [no-unnecessary-parameter-property-assignment] account for parameter reassignment (#12880)
  • eslint-plugin: [unbound-method] treat Intl.Collator.prototype.compare as spec-bound (#12845)
  • eslint-plugin: [no-unnecessary-condition] handle union-keyed index access on the left-hand side of nullish assignment (#12747)
  • eslint-plugin: [no-useless-default-assignment] convert the fixer to a suggestion fixer (#12826)
  • eslint-plugin: [no-misused-promises] handle multiple Promise constituents (#12904)
  • rule-tester: test the final autofix output instead of the first pass (#12867)
  • scope-manager: merge implicit global definitions (#12809)
  • type-utils: match package specifiers on whole path components (#12838)
  • typescript-estree: resolve symlinked paths when matching files to projects (#12725)
  • typescript-estree: add missing < token opening type arguments (#12821)
  • typescript-estree: require string literal import attribute values (#12894)
  • website: prevent playground from breaking down after opening link with the .js file type (#12777)

❤️ Thank You

See GitHub Releases for more information.

... (truncated)

Changelog

Sourced from @​typescript-eslint/parser's changelog.

8.70.1 (2026-09-21)

This was a version bump only for parser to align it with other projects, there were no code changes.

See GitHub Releases for more information.

You can read about our versioning strategy and releases on our website.

8.70.0 (2026-09-07)

This was a version bump only for parser to align it with other projects, there were no code changes.

See GitHub Releases for more information.

You can read about our versioning strategy and releases on our website.

Commits

Updates prettier from 3.9.6 to 3.9.9

Release notes

Sourced from prettier's releases.

3.9.9

  • Markdown: Fix text with $ been incorrectly parsed as math syntax (#20140 by @​fisker)

🔗 Changelog

3.9.8

  • Markdown: Don't let Liquid objects interrupt paragraphs (#20087 by @​seiyab)

🔗 Changelog

3.9.7

  • Support Angular 22.2
  • Fix regressions in v3.9

🔗 Changelog

Changelog

Sourced from prettier's changelog.

3.9.9

diff

Markdown: Fix text with $ been incorrectly parsed as math syntax (#20140 by @​fisker)

<!-- Input -->
**Uses $FOO** from `a.sh` and `b.sh`, plus `$BAR` from `c.sh`, before anything else runs here.
<!-- Prettier 3.9.8 -->
Uses $FOO from a.sh and b.sh, plus $BARfromc.sh, before anything else runs here.
<!-- Prettier 3.9.9 -->
Uses $FOO from a.sh and b.sh, plus $BAR from c.sh, before anything else runs here.

3.9.8

diff

Markdown: Don't let Liquid objects interrupt paragraphs (#20087 by @​seiyab)

<!-- Input -->
If `module` is not a [`WebAssembly.Module`](https://github.com/prettier/prettier/blob/main/en-US/docs/WebAssembly/Reference/JavaScript_interface/Module) object instance, a
{{jsxref("TypeError")}} is thrown.
<!-- Prettier 3.9.7 -->
If module is not a WebAssembly.Module object instance, a
{{jsxref("TypeError")}} is thrown.
<!-- Prettier 3.9.8 -->
If module is not a WebAssembly.Module object instance, a
{{jsxref("TypeError")}} is thrown.

3.9.7

diff

Markdown: Prevent indentation drift in list-item code blocks (#19647, #19990 by @​Austin1serb, @​giaBaoJS)

<!-- Input -->
- [x] short first line.
</tr></table> 

... (truncated)

Commits

Updates @hiero-ledger/sdk from 2.87.0 to 2.89.0

Release notes

Sourced from @​hiero-ledger/sdk's releases.

v2.89.0

This release moves every mirror node REST query onto a shared HTTP transport layer, the cross-SDK design agreed in sdk-collaboration-hub#286. The transport is configured once on the client with MirrorNodeHttpConfig, one MirrorNodeHttpRetryPolicy governs attempts, timeouts and retryable statuses for every mirror call, and an application can inject its own HttpTransport for a corporate proxy, mTLS or tracing. AccountBalanceQuery is deprecated and no longer functional, since consensus node 0.77 removed cryptoGetBalance; the new MirrorNodeTokenBalanceQuery covers the token balances it used to return, next to the HBAR-only MirrorNodeAccountBalanceQuery. CommonJS projects on moduleResolution: node16 or nodenext can now require() the SDK and @hiero-ledger/cryptography, which is co-released as 1.22.0. A set of address book, retry and precision fixes rounds out the release.

Breaking Changes

  • AccountBalanceQuery is deprecated and no longer functional. Constructing one logs a deprecation warning and execute() rejects immediately without contacting a consensus node. Read HBAR with MirrorNodeAccountBalanceQuery and token balances with MirrorNodeTokenBalanceQuery. #4306 #4285
  • Every mirror node REST query (MirrorNodeAccountBalanceQuery, MirrorNodeTokenBalanceQuery, FeeEstimateQuery, MirrorNodeContractCallQuery, MirrorNodeContractEstimateQuery, RegisteredNodeAddressBookQuery, AddressBookQuery on WebClient and NativeClient, and the populateAccountNum / populateAccountEvmAddress helpers) now goes through the client's shared transport and one retry policy. What changes per call site: #4387 #4376
    • client.setMaxAttempts(), client.setMinBackoff() and client.setMaxBackoff() no longer affect mirror REST calls; they govern consensus node gRPC requests only. Set retryPolicy on MirrorNodeHttpConfig instead.
    • The default is 5 attempts per request with exponential backoff and full jitter from 250 ms up to 8 s. Every call is bounded by totalDeadline (defaults to client.requestTimeout, 2 min) and every attempt by perAttemptTimeout (30 s). Queries that had no timeout (FeeEstimateQuery, the two contract queries, the populate helpers) are now bounded, and the balance queries no longer use client.maxAttempts. On a loopback mirror node (localhost, 127.0.0.1) the default is 15 attempts and a 90 s deadline; an explicit policy on the client overrides it.
    • Retryable statuses are a pinned list: 408, 429, 500, 502, 503 and 504. 501, 505 and the other 5xx statuses stop being retried. A Retry-After header is honoured, bounded by the remaining deadline.
    • Error messages follow one shape, HTTP <status>: <mirror node detail>. MirrorNodeContractCallQuery and MirrorNodeContractEstimateQuery reported HTTP error! status: <status> and never retried; they now retry transient failures. Every mirror REST error keeps the underlying failure in cause.
    • setMaxAttempts(n) on RegisteredNodeAddressBookQuery and the web AddressBookQuery now means n attempts in total, not n retries after the first attempt, and setMaxAttempts(0) throws a RangeError at execute.
    • The mirror node base URL is chosen round-robin per call instead of at random per request. Response bodies are capped at 32 MiB (response-too-large-error), and the Node transport follows at most 5 redirects, dropping caller headers on a cross-origin hop.
    • On Node, mirror REST no longer goes through the global fetch, so a proxy installed with undici.setGlobalDispatcher() is no longer picked up. The Node transport honours --use-env-proxy / NODE_USE_ENV_PROXY (Node 24.5 / 22.19 and later). Inject FetchHttpTransport to keep using the fetch dispatcher.
    • Browsers send a CORS preflight before every cross-origin mirror request, because x-user-agent is not a safelisted header.
    • The web AddressBookQuery on a local network targets mirror REST port 5551 instead of the mirror node's gRPC port.
  • Wallet.getAccountBalance(), LocalProvider.getAccountBalance() and LocalProviderWeb.getAccountBalance() are backed by the mirror node. The returned AccountBalance carries the HBAR balance only, its tokens and tokenDecimals maps are always empty, and the value may lag consensus by a few seconds. An unknown account throws MirrorNodeStatusError with Status.InvalidAccountId rather than PrecheckStatusError. #4306 #4335
  • The maxBackoff getter on every transaction and query is typed number | null and returns null until the request executes, matching minBackoff and maxAttempts. setMinBackoff() on a fresh request no longer throws for values above 8 s. #4382
  • Client.ping(), Client.pingAll() and any request pinned with setNodeAccountIds to a node account ID missing from the client's network map reject with NodeAccountId not recognized: <id> instead of silently running against a random node. A TransactionReceiptQuery or TransactionRecordQuery pinned to a node that has since left the map now errors; a request pinned to several nodes skips the unknown ones. #4375
  • AddressBookQueryWeb (the AddressBookQuery of WebClient and NativeClient) reports HTTP 404: <detail> instead of HTTP error! status: 404, and execute(client, requestTimeout) is the total budget for the whole query rather than a per-attempt, per-page bound. #4380

Upgrading

  • Replace AccountBalanceQuery with the two mirror node queries:

    import {
        MirrorNodeAccountBalanceQuery,
        MirrorNodeTokenBalanceQuery,
    } from "@hiero-ledger/sdk";
    const hbar = await new MirrorNodeAccountBalanceQuery()
    .setAccountId("0.0.1234")
    .execute(client);
    console.log(hbar.hbars.toString());
    const token = await new MirrorNodeTokenBalanceQuery()
    .setAccountId("0.0.1234")
    .setTokenId("0.0.5678")
    .execute(client);
    console.log(token.balance.toString(), token.decimals);

    A just-created account fails with INVALID_ACCOUNT_ID until the mirror node ingests it, typically a few seconds. Match on error.status, not on the error class, and retry create-then-read flows.

  • Move mirror retry tuning from the client's gRPC knobs to the mirror HTTP config:

    client.setMirrorNodeHttpConfig({
        ...client.getMirrorNodeHttpConfig(),
        retryPolicy: { maxAttempts: 3, totalDeadline: 30_000 },
    });

... (truncated)

Changelog

Sourced from @​hiero-ledger/sdk's changelog.

v2.89.0

Deprecated

  • AccountBalanceQuery is deprecated and no longer functional. The consensus node removed CryptoService/cryptoGetBalance in release 0.77, and the query had already been dropped from the mainnet, testnet and previewnet throttle configurations. Constructing one logs a deprecation warning, and execute() now rejects immediately without contacting a consensus node. #4285 #4306

Added

  • A shared HTTP transport layer for every mirror node REST query, implementing the cross-SDK proposal in sdk-collaboration-hub#286. New public API: the HttpTransport SPI (roundTrip(request, signal) and close(closeTimeout)) with HttpRequest, HttpResponse, HttpMethod and HttpTransportConfiguration (connectTimeout, maxRedirects, maxResponseBytes, defaultHeaders); HttpTransportError with the seven stable HttpTransportErrorCode values (connection-error, timeout-error, unknown-host-error, tls-error, client-closed-error, cancelled-error, response-too-large-error); MirrorNodeHttpRetryPolicy (maxAttempts, perAttemptTimeout, totalDeadline, initialBackoff, maxBackoff, retryableStatusCodes) and MirrorNodeHttpConfig (transport, transportConfiguration, retryPolicy, requestHeaders); Client.setMirrorNodeHttpConfig() / Client.getMirrorNodeHttpConfig(). DefaultHttpTransport is the SDK-built transport of each entry point: NodeHttpTransport on Node (a private keep-alive connection pool, a connect timeout, at most 5 redirects with caller headers dropped on a cross-origin hop, a streaming 32 MiB body cap, and a bounded drain on close) and FetchHttpTransport in the browser and on React Native (also exported on Node for applications that want the global fetch and whatever dispatcher or proxy it was given). An application injects its own transport, for a corporate proxy, mTLS or tracing, with client.setMirrorNodeHttpConfig({ ...client.getMirrorNodeHttpConfig(), transport }); an injected transport is never closed by the SDK. Every mirror request carries x-user-agent: hiero-sdk-js/<version>, the same value as the gRPC path; user-agent and x-user-agent are reserved and rejected by requestHeaders. #4376 #4387, #4392
  • FeeEstimateQuery.execute(), MirrorNodeContractCallQuery.execute() and MirrorNodeContractEstimateQuery.execute() accept an optional requestTimeout, the total budget for the whole operation in milliseconds, matching the other mirror node queries. #4387
  • MirrorNodeTokenBalanceQuery reads a single token balance from the mirror node (GET /api/v1/accounts/{id}/tokens?token.id={tokenId}), returning the balance and its decimals. This is the replacement for the token balances AccountBalanceQuery used to return: MirrorNodeAccountBalanceQuery is HBAR-only, and AccountInfoQuery.tokenRelationships is deprecated as of HIP-367 and truncated at 1000 relationships. Requires both setAccountId and setTokenId. This single-token form is the one the shared HTTP transport proposal (sdk-collaboration-hub#286) lists as an existing query, so it is the stable API; if pagination is added later, it will build on this API rather than replace it. An account the mirror node does not know throws MirrorNodeStatusError with Status.InvalidAccountId, matching MirrorNodeAccountBalanceQuery. An account that exists but holds no relationship with the token returns a zero balance. #4306

Changed

  • Behavior change: every mirror node REST query (MirrorNodeAccountBalanceQuery, MirrorNodeTokenBalanceQuery, FeeEstimateQuery, MirrorNodeContractCallQuery, MirrorNodeContractEstimateQuery, RegisteredNodeAddressBookQuery, AddressBookQuery on WebClient and NativeClient, and AccountId.populateAccountNum(), AccountId.populateAccountEvmAddress() and ContractId.populateAccountNum()) now goes through the client's shared HTTP transport and one retry policy, MirrorNodeHttpRetryPolicy, instead of each deciding its own attempt count, timeout and retryable statuses. What moves, per call site, in #4376 and #4387:
    • A total bound applies everywhere. FeeEstimateQuery, the two contract queries and the three populate helpers had no timeout and could hang on the OS TCP timeout; every call is now bounded by totalDeadline, which defaults to client.requestTimeout (2 min), and every attempt by perAttemptTimeout (30 s). An explicit execute(client, requestTimeout) argument is the total budget for the call, every page and every retry included, on every query that takes one.
    • Attempt counts change. The default is 5 attempts per request with exponential backoff and full jitter from 250 ms up to 8 s. The balance queries used client.maxAttempts (10, or 1000 on a local network), FeeEstimateQuery 5, the contract queries and populate helpers 1 (no retry at all), RegisteredNodeAddressBookQuery and the web AddressBookQuery client.maxAttempts + 1. On a loopback mirror node (localhost, 127.0.0.1) the default policy uses 15 attempts and a 90 s total deadline so a mirror node still starting under a local test harness is waited for; an explicit policy on the client overrides that.
    • client.setMaxAttempts(), client.setMinBackoff() and client.setMaxBackoff() no longer affect mirror REST calls. They govern consensus node gRPC requests only. Set retryPolicy on MirrorNodeHttpConfig instead. setMaxAttempts() and setMaxBackoff() on RegisteredNodeAddressBookQuery and the web AddressBookQuery keep working and override only the field they name; setMaxAttempts(n) on those two now means n attempts in total, where it previously meant n retries after the first attempt.
    • Retryable statuses are a pinned list: 408, 429, 500, 502, 503 and 504. 408 and 429 become retryable; 501, 505 and the other 5xx statuses stop being retried. A Retry-After header on a retryable status is honoured, bounded by the remaining total deadline; a header the deadline cannot fit fails the call at once instead of retrying sooner than the node asked. A transport failure classified as terminal (unknown host, TLS, oversized body, cancellation) fails after one attempt instead of consuming the budget.
    • The mirror node base URL is chosen round-robin over the configured mirror nodes, one node per call, and every attempt and every page of that call targets the same node. It was drawn at random per request before, so a two-node network with one node down was a coin flip on every call.
    • Error messages follow one shape: HTTP <status>: <mirror node detail>. MirrorNodeContractCallQuery and MirrorNodeContractEstimateQuery reported HTTP error! status: <status> and never retried; they now retry transient failures and report the mirror node's _status.messages[].detail. The two address book queries report retries exhausted after <n> attempts. Last error: ... and request deadline of <ms> ms exceeded. Last error: ... through their existing Failed to query ... prefixes.
    • Response bodies are capped at 32 MiB and a larger body fails with response-too-large-error rather than being truncated; the Node transport follows at most 5 redirects and drops caller headers on a cross-origin hop.
    • Client.close() also releases the HTTP transport the client built, giving reads in flight a 5 s grace period, and a mirror REST call still running starts no new attempt and does not sleep out a backoff. It never closes an injected transport.
    • Errors keep their cause. Every mirror REST query still throws its own Error (or MirrorNodeStatusError), and its cause now carries the underlying failure: the transport error with its code, or the adapter's retries-exhausted-error / deadline-exceeded-error with the last response.
    • Proxies on Node. The Node transport uses the proxy configuration Node applied to its own global agents at startup (--use-env-proxy or NODE_USE_ENV_PROXY, Node 24.5 / 22.19 and later, reading HTTP_PROXY, HTTPS_PROXY and NO_PROXY), so it agrees with http.globalAgent in every case. A proxy installed on the global fetch with undici.setGlobalDispatcher(new ProxyAgent(...)) is no longer picked up, because mirror REST no longer goes through fetch on Node; inject FetchHttpTransport to keep using it: client.setMirrorNodeHttpConfig({ ...client.getMirrorNodeHttpConfig(), transport: FetchHttpTransport.create() }).
    • Browsers preflight every cross-origin mirror request. x-user-agent is not a CORS-safelisted header, so a cross-origin GET is now preceded by an OPTIONS request, cached only for as long as the mirror node's Access-Control-Max-Age allows; the public mirror nodes send none on /balances, so there the preflight happens on every request.
    • setMaxAttempts(0) on RegisteredNodeAddressBookQuery and the web AddressBookQuery now throws a RangeError at execute. It used to mean "no retries"; that is setMaxAttempts(1) now, since the value counts attempts.
    • The web AddressBookQuery on a local network calls the mirror REST port. On a loopback mirror node it now targets port 5551 like every other mirror REST query, instead of the port the mirror node was configured with for gRPC (5600 on NativeClient.forLocalNode()), where /api/v1/network/nodes is not served.
    • The web AddressBookQuery still derives its base URL from the mirror node's address rather than from client.mirrorRestApiBaseUrl; that second step of its migration lands with the local-port work of the ingress proposal.
  • Provider.getAccountBalance, LocalProvider.getAccountBalance, and LocalProviderWeb.getAccountBalance accept an optional requestTimeout in milliseconds and apply it to the mirror-node balance request. #4390
  • Wallet.getAccountBalance(), LocalProvider.getAccountBalance() and LocalProviderWeb.getAccountBalance() keep working, but are now backed by the mirror node rather than the consensus node. Two behavior changes for callers: the returned AccountBalance carries the HBAR balance only: its tokens and tokenDecimals maps are always empty, and the value may lag consensus by a few seconds, so it is not read-after-write consistent. Read token balances with MirrorNodeTokenBalanceQuery. For an account the mirror node does not know, these methods now throw MirrorNodeStatusError carrying Status.InvalidAccountId rather than the PrecheckStatusError the consensus-node query used to raise. Match on status, not on the error class. #4335 #4306
  • Examples and integration tests no longer use AccountBalanceQuery. Examples read HBAR with MirrorNodeAccountBalanceQuery and token balances with MirrorNodeTokenBalanceQuery; integration tests use AccountInfoQuery, which the consensus node still serves and which is immediately consistent. #4306, #4390

Fixed

  • Mirror node REST responses no longer lose precision on integers above Number.MAX_SAFE_INTEGER (2^53 - 1). MirrorNodeAccountBalanceQuery and MirrorNodeTokenBalanceQuery returned a rounded balance for large values (for example 9007199254740993 came back as 9007199254740992), because the body was parsed with JSON.parse. The shared mirror JSON parser now keeps such integers as exact decimal strings, which Long reads without loss; this also covers the fee totals FeeEstimateQuery reads. #4336 #4391
  • RegisteredNodeAddressBookQuery no longer calls AbortSignal.timeout unguarded, which threw on React Native, and the balance queries no longer run unbounded there: every mirror REST call is bounded by the transport, which falls back to AbortController on runtimes without AbortSignal.timeout. #4385 #4387
  • The mirror REST retry and fetch helpers that each query carried are gone; MirrorNodeHttpClient owns retry, backoff, timeouts and status classification for all of them. #4356 #4387
  • client.setMaxBackoff() now applies to transactions and queries. Executable hardcoded its own maxBackoff to 8 s, so the client value was never inherited unless setMaxBackoff was called on the request itself. AddressBookQuery (gRPC) and AddressBookQueryWeb fall back to the client value the same way. Behavior change: the maxBackoff getter on every transaction and query is now typed number | null and returns null until the request executes, matching minBackoff and maxAttempts; strict TypeScript code that assigned it to a number must handle null. setMinBackoff() on a fresh request also no longer throws for values above 8 s, since there is no longer a hidden maximum to compare against. #4379 #4382
  • AddressBookQueryWeb (the address book query used by WebClient and NativeClient) no longer retries 4xx responses or malformed bodies. It retried every non-2xx status, so a mirror node returning 404 for /api/v1/network/nodes cost ~48 s of retries on a default client and hours on a local network before updateNetwork() gave up. Only 5xx, timeouts and transport errors are retried now, matching the other mirror REST queries, retries are logged through the client logger, and the per-attempt console.error is gone. The error message changes from HTTP error! status: 404 to HTTP 404: <mirror node detail>; AddressBookQuery in the browser and React Native builds is this class, so callers matching on the old text should match on HTTP 404 instead. The shared isRetryableNetworkError helper now classifies an HTTP <status> message by status alone (a 4xx body that echoes a path containing network was retried by every mirror REST query) and recognises the Chrome (Failed to fetch) and Safari (Load failed) network failure messages. #4377 #4380
  • AddressBookQueryWeb now bounds every mirror node request. WebClient and NativeClient never passed a timeout, so a mirror node that accepted the connection and never answered hung updateNetwork(), forMainnetAsync() and forTestnetAsync() indefinitely and left _isUpdatingNetwork set, which silently disabled every later scheduled update. execute(client, requestTimeout) now treats requestTimeout as the total budget for the whole query, every page and every retry, defaulting to client.requestTimeout (2 min), the same meaning it has on Executable and the mirror node balance queries; previously an explicit value applied per attempt and per page. Independently, one attempt never waits longer than 30 s. Runtimes without AbortSignal.timeout fall back to AbortController. #4378 #4380
  • Client.ping(), Client.pingAll() and any query or transaction pinned with setNodeAccountIds to a node account ID that is not in the client's network map now reject with NodeAccountId not recognized: <id> instead of silently executing against a random node. Behavior change: a TransactionReceiptQuery or TransactionRecordQuery pinned to a node that has since left the map (for example after an address book update) now errors instead of being routed to another node; a request pinned to several nodes skips the unknown IDs and errors only when none of them resolve. #4330 #4375
  • AddressBookQuery on WebClient and NativeClient, and RegisteredNodeAddressBookQuery, now reject when their setup fails instead of never settling. With no mirror network configured, execute() waited forever and left an unhandled rejection, so updateNetwork() hung and the scheduled network update stopped for good. Both now reject with Client has no mirror network configured or no healthy mirror nodes are available. #4383 #4384
  • CommonJS projects type-checking with moduleResolution: node16 or nodenext can now require("@hiero-ledger/sdk") and require("@hiero-ledger/cryptography"). Both packages ship CommonJS type declarations (lib/**/*.d.cts, generated at build time next to the ESM .d.ts) and declare per-condition types in their exports maps, so import resolves the ESM typings and require the CommonJS ones. This removes the TS1479, TS1340 (Module 'long' does not refer to a type) and TS2835 errors those consumers hit; JSDoc type references now use import("long").default and import("bignumber.js").default with explicit .js extensions. @hiero-ledger/cryptography 1.22.0 ships the same change. #2722 #4313

v2.88.0

Changed

  • Breaking: MirrorNodeAccountBalanceQuery now throws the new MirrorNodeStatusError carrying Status.InvalidAccountId for an account the mirror node does not know, instead of returning 0 ℏ as in v2.87.0. This matches the INVALID_ACCOUNT_ID failure of the deprecated AccountBalanceQuery it replaces, and the Java and Go SDKs. Match on error.status, not on the error class: mirror REST queries reach no consensus node, so this is deliberately not a PrecheckStatusError. A just-created account fails transiently until the mirror node ingests it, so create-then-read flows should retry; an account that exists holding nothing still returns zero, and a deleted account is reported as an ordinary zero balance because the balances endpoint does not expose the deleted flag. A malformed response (missing balances array or non-numeric balance) now throws a plain Error instead of returning zero. #4335

... (truncated)

Commits
  • 7ae7aed chore(release): v2.89.0 (#4393)
  • 6e58833 fix: keep an explicit mirror retry policy on a loopback mirror node (#4392)
  • adc0aa0 fix: make balance examples mirror-ingestion safe (#4390)
  • 0977c51 fix: keep int64 values above 2^53 exact in mirror node JSON (#4391)
  • 1f45d44 feat(tck): add AccountBalanceQuery deprecation hook and mirror token balance ...
  • 9263340 feat: shared HTTP transport layer for mirror node REST queries (#4387)
  • 8d35714 ci: bump solo to v0.91.0 (#4389)
  • ad90a75 chore(deps): bump step-security/harden-runner from 2.20.0 to 2.21.1 (#4348)

Bumps the minor-and-patch group with 22 updates:

| Package | From | To |
| --- | --- | --- |
| [@typescript-eslint/eslint-plugin](https://github.com/typescript-eslint/typescript-eslint/tree/HEAD/packages/eslint-plugin) | `8.69.0` | `8.70.1` |
| [@typescript-eslint/parser](https://github.com/typescript-eslint/typescript-eslint/tree/HEAD/packages/parser) | `8.69.0` | `8.70.1` |
| [prettier](https://github.com/prettier/prettier) | `3.9.6` | `3.9.9` |
| [@hiero-ledger/sdk](https://github.com/hiero-ledger/hiero-sdk-js) | `2.87.0` | `2.89.0` |
| [@reown/appkit](https://github.com/reown-com/appkit) | `1.8.23` | `1.8.24` |
| [@reown/appkit-controllers](https://github.com/reown-com/appkit) | `1.8.23` | `1.8.24` |
| [@reown/walletkit](https://github.com/reown-com/reown-walletkit-js/tree/HEAD/packages/walletkit) | `1.5.6` | `1.6.0` |
| [@tanstack/react-query](https://github.com/TanStack/query/tree/HEAD/packages/react-query) | `5.102.8` | `5.104.0` |
| [@walletconnect/ethereum-provider](https://github.com/WalletConnect/walletconnect-monorepo/tree/HEAD/providers/ethereum-provider) | `2.24.0` | `2.25.0` |
| [@walletconnect/universal-provider](https://github.com/WalletConnect/walletconnect-monorepo/tree/HEAD/providers/universal-provider) | `2.24.0` | `2.25.0` |
| [@x402/core](https://github.com/x402-foundation/x402) | `2.25.0` | `2.27.0` |
| [@x402/hedera](https://github.com/x402-foundation/x402) | `2.25.0` | `2.27.0` |
| [daisyui](https://github.com/saadeghi/daisyui/tree/HEAD/packages/daisyui) | `5.7.28` | `5.7.46` |
| [next](https://github.com/vercel/next.js) | `15.5.25` | `15.5.26` |
| [react](https://github.com/react/react/tree/HEAD/packages/react) | `19.2.8` | `19.3.0` |
| [@types/react](https://github.com/DefinitelyTyped/DefinitelyTyped/tree/HEAD/types/react) | `19.2.18` | `19.3.0` |
| [react-dom](https://github.com/react/react/tree/HEAD/packages/react-dom) | `19.2.8` | `19.3.0` |
| [@types/react-dom](https://github.com/DefinitelyTyped/DefinitelyTyped/tree/HEAD/types/react-dom) | `19.2.7` | `19.3.0` |
| [react-hot-toast](https://github.com/timolins/react-hot-toast) | `2.6.0` | `2.6.1` |
| [viem](https://github.com/wevm/viem) | `2.56.3` | `2.56.9` |
| [eslint-config-next](https://github.com/vercel/next.js/tree/HEAD/packages/eslint-config-next) | `15.5.25` | `15.5.26` |
| [tsx](https://github.com/privatenumber/tsx) | `4.23.13` | `4.23.15` |


Updates `@typescript-eslint/eslint-plugin` from 8.69.0 to 8.70.1
- [Release notes](https://github.com/typescript-eslint/typescript-eslint/releases)
- [Changelog](https://github.com/typescript-eslint/typescript-eslint/blob/main/packages/eslint-plugin/CHANGELOG.md)
- [Commits](https://github.com/typescript-eslint/typescript-eslint/commits/v8.70.1/packages/eslint-plugin)

Updates `@typescript-eslint/parser` from 8.69.0 to 8.70.1
- [Release notes](https://github.com/typescript-eslint/typescript-eslint/releases)
- [Changelog](https://github.com/typescript-eslint/typescript-eslint/blob/main/packages/parser/CHANGELOG.md)
- [Commits](https://github.com/typescript-eslint/typescript-eslint/commits/v8.70.1/packages/parser)

Updates `prettier` from 3.9.6 to 3.9.9
- [Release notes](https://github.com/prettier/prettier/releases)
- [Changelog](https://github.com/prettier/prettier/blob/main/CHANGELOG.md)
- [Commits](prettier/prettier@3.9.6...3.9.9)

Updates `@hiero-ledger/sdk` from 2.87.0 to 2.89.0
- [Release notes](https://github.com/hiero-ledger/hiero-sdk-js/releases)
- [Changelog](https://github.com/hiero-ledger/hiero-sdk-js/blob/main/CHANGELOG.md)
- [Commits](hiero-ledger/hiero-sdk-js@v2.87.0...v2.89.0)

Updates `@reown/appkit` from 1.8.23 to 1.8.24
- [Release notes](https://github.com/reown-com/appkit/releases)
- [Commits](https://github.com/reown-com/appkit/compare/@reown/appkit@1.8.23...@reown/appkit@1.8.24)

Updates `@reown/appkit-controllers` from 1.8.23 to 1.8.24
- [Release notes](https://github.com/reown-com/appkit/releases)
- [Commits](https://github.com/reown-com/appkit/compare/@reown/appkit-controllers@1.8.23...@reown/appkit-controllers@1.8.24)

Updates `@reown/walletkit` from 1.5.6 to 1.6.0
- [Release notes](https://github.com/reown-com/reown-walletkit-js/releases)
- [Changelog](https://github.com/reown-com/reown-walletkit-js/blob/main/packages/walletkit/CHANGELOG.md)
- [Commits](https://github.com/reown-com/reown-walletkit-js/commits/@reown/walletkit@1.6.0/packages/walletkit)

Updates `@tanstack/react-query` from 5.102.8 to 5.104.0
- [Release notes](https://github.com/TanStack/query/releases)
- [Changelog](https://github.com/TanStack/query/blob/main/packages/react-query/CHANGELOG.md)
- [Commits](https://github.com/TanStack/query/commits/@tanstack/react-query@5.104.0/packages/react-query)

Updates `@walletconnect/ethereum-provider` from 2.24.0 to 2.25.0
- [Release notes](https://github.com/WalletConnect/walletconnect-monorepo/releases)
- [Changelog](https://github.com/WalletConnect/walletconnect-monorepo/blob/v2.0/providers/ethereum-provider/CHANGELOG.md)
- [Commits](https://github.com/WalletConnect/walletconnect-monorepo/commits/@walletconnect/ethereum-provider@2.25.0/providers/ethereum-provider)

Updates `@walletconnect/universal-provider` from 2.24.0 to 2.25.0
- [Release notes](https://github.com/WalletConnect/walletconnect-monorepo/releases)
- [Changelog](https://github.com/WalletConnect/walletconnect-monorepo/blob/v2.0/providers/universal-provider/CHANGELOG.md)
- [Commits](https://github.com/WalletConnect/walletconnect-monorepo/commits/@walletconnect/universal-provider@2.25.0/providers/universal-provider)

Updates `@x402/core` from 2.25.0 to 2.27.0
- [Commits](https://github.com/x402-foundation/x402/compare/npm-@x402/core@v2.25.0...npm-@x402/core@v2.27.0)

Updates `@x402/hedera` from 2.25.0 to 2.27.0
- [Commits](https://github.com/x402-foundation/x402/compare/npm-@x402/hedera@v2.25.0...npm-@x402/hedera@v2.27.0)

Updates `daisyui` from 5.7.28 to 5.7.46
- [Release notes](https://github.com/saadeghi/daisyui/releases)
- [Changelog](https://github.com/saadeghi/daisyui/blob/master/CHANGELOG.md)
- [Commits](https://github.com/saadeghi/daisyui/commits/v5.7.46/packages/daisyui)

Updates `next` from 15.5.25 to 15.5.26
- [Release notes](https://github.com/vercel/next.js/releases)
- [Commits](vercel/next.js@v15.5.25...v15.5.26)

Updates `react` from 19.2.8 to 19.3.0
- [Release notes](https://github.com/react/react/releases)
- [Changelog](https://github.com/react/react/blob/main/CHANGELOG.md)
- [Commits](https://github.com/react/react/commits/v19.3.0/packages/react)

Updates `@types/react` from 19.2.18 to 19.3.0
- [Release notes](https://github.com/DefinitelyTyped/DefinitelyTyped/releases)
- [Commits](https://github.com/DefinitelyTyped/DefinitelyTyped/commits/HEAD/types/react)

Updates `react-dom` from 19.2.8 to 19.3.0
- [Release notes](https://github.com/react/react/releases)
- [Changelog](https://github.com/react/react/blob/main/CHANGELOG.md)
- [Commits](https://github.com/react/react/commits/v19.3.0/packages/react-dom)

Updates `@types/react-dom` from 19.2.7 to 19.3.0
- [Release notes](https://github.com/DefinitelyTyped/DefinitelyTyped/releases)
- [Commits](https://github.com/DefinitelyTyped/DefinitelyTyped/commits/HEAD/types/react-dom)

Updates `react-hot-toast` from 2.6.0 to 2.6.1
- [Release notes](https://github.com/timolins/react-hot-toast/releases)
- [Commits](timolins/react-hot-toast@v2.6.0...v2.6.1)

Updates `viem` from 2.56.3 to 2.56.9
- [Release notes](https://github.com/wevm/viem/releases)
- [Commits](https://github.com/wevm/viem/compare/viem@2.56.3...viem@2.56.9)

Updates `@types/react` from 19.2.18 to 19.3.0
- [Release notes](https://github.com/DefinitelyTyped/DefinitelyTyped/releases)
- [Commits](https://github.com/DefinitelyTyped/DefinitelyTyped/commits/HEAD/types/react)

Updates `@types/react-dom` from 19.2.7 to 19.3.0
- [Release notes](https://github.com/DefinitelyTyped/DefinitelyTyped/releases)
- [Commits](https://github.com/DefinitelyTyped/DefinitelyTyped/commits/HEAD/types/react-dom)

Updates `eslint-config-next` from 15.5.25 to 15.5.26
- [Release notes](https://github.com/vercel/next.js/releases)
- [Commits](https://github.com/vercel/next.js/commits/v15.5.26/packages/eslint-config-next)

Updates `tsx` from 4.23.13 to 4.23.15
- [Release notes](https://github.com/privatenumber/tsx/releases)
- [Changelog](https://github.com/privatenumber/tsx/blob/master/release.config.cjs)
- [Commits](privatenumber/tsx@v4.23.13...v4.23.15)

---
updated-dependencies:
- dependency-name: "@typescript-eslint/eslint-plugin"
  dependency-version: 8.70.1
  dependency-type: direct:development
  update-type: version-update:semver-minor
  dependency-group: minor-and-patch
- dependency-name: "@typescript-eslint/parser"
  dependency-version: 8.70.1
  dependency-type: direct:development
  update-type: version-update:semver-minor
  dependency-group: minor-and-patch
- dependency-name: prettier
  dependency-version: 3.9.9
  dependency-type: direct:development
  update-type: version-update:semver-patch
  dependency-group: minor-and-patch
- dependency-name: "@hiero-ledger/sdk"
  dependency-version: 2.89.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: minor-and-patch
- dependency-name: "@reown/appkit"
  dependency-version: 1.8.24
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: minor-and-patch
- dependency-name: "@reown/appkit-controllers"
  dependency-version: 1.8.24
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: minor-and-patch
- dependency-name: "@reown/walletkit"
  dependency-version: 1.6.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: minor-and-patch
- dependency-name: "@tanstack/react-query"
  dependency-version: 5.104.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: minor-and-patch
- dependency-name: "@walletconnect/ethereum-provider"
  dependency-version: 2.25.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: minor-and-patch
- dependency-name: "@walletconnect/universal-provider"
  dependency-version: 2.25.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: minor-and-patch
- dependency-name: "@x402/core"
  dependency-version: 2.27.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: minor-and-patch
- dependency-name: "@x402/hedera"
  dependency-version: 2.27.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: minor-and-patch
- dependency-name: daisyui
  dependency-version: 5.7.46
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: minor-and-patch
- dependency-name: next
  dependency-version: 15.5.26
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: minor-and-patch
- dependency-name: react
  dependency-version: 19.3.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: minor-and-patch
- dependency-name: "@types/react"
  dependency-version: 19.3.0
  dependency-type: direct:development
  update-type: version-update:semver-minor
  dependency-group: minor-and-patch
- dependency-name: react-dom
  dependency-version: 19.3.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: minor-and-patch
- dependency-name: "@types/react-dom"
  dependency-version: 19.3.0
  dependency-type: direct:development
  update-type: version-update:semver-minor
  dependency-group: minor-and-patch
- dependency-name: react-hot-toast
  dependency-version: 2.6.1
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: minor-and-patch
- dependency-name: viem
  dependency-version: 2.56.9
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: minor-and-patch
- dependency-name: "@types/react"
  dependency-version: 19.3.0
  dependency-type: direct:development
  update-type: version-update:semver-minor
  dependency-group: minor-and-patch
- dependency-name: "@types/react-dom"
  dependency-version: 19.3.0
  dependency-type: direct:development
  update-type: version-update:semver-minor
  dependency-group: minor-and-patch
- dependency-name: eslint-config-next
  dependency-version: 15.5.26
  dependency-type: direct:development
  update-type: version-update:semver-patch
  dependency-group: minor-and-patch
- dependency-name: tsx
  dependency-version: 4.23.15
  dependency-type: direct:development
  update-type: version-update:semver-patch
  dependency-group: minor-and-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code labels Oct 1, 2026
@vercel

vercel Bot commented Oct 1, 2026 •

Copy link
Copy Markdown

The latest updates on your projects. Learn more about Vercel for GitHub.

Project Deployment Actions Updated
build Ready Ready Preview Oct 1, 2026 2:17pm UTC

This branch was successfully deployed

1 active deployment
Preview — c7f520a4 Deployed Oct 1, 2026 by vercel[bot]
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants