Version Packages - #348
Version Packages#348github-actions[bot] wants to merge 1 commit into
Conversation
cf34d1a to
01bff01
Compare
PR SummaryMedium Risk Overview @sei-js/precompiles@3.1.0 (minor) ships chunked @sei-js/create-sei@2.0.1 bumps the Next.js template pins ( @sei-js/mcp-server@1.0.1 isolates wallet policy per runtime by using a frozen @sei-js/sei-global-wallet@2.0.1 documents Dynamic Reviewed by Cursor Bugbot for commit f56e0c1. Bugbot is set up for automated code reviews on this repo. Configure here. |
Codecov Report✅ All modified and coverable lines are covered by tests. Additional details and impacted files@@ Coverage Diff @@
## main #348 +/- ##
=======================================
Coverage 97.17% 97.17%
=======================================
Files 80 80
Lines 5410 5410
=======================================
Hits 5257 5257
Misses 153 153
Flags with carried forward coverage won't be shown. Click here to find out more. ☔ View full report in Codecov by Harness. 🚀 New features to boost your workflow:
|
cc55cf5 to
41dfa0a
Compare
41dfa0a to
f56e0c1
Compare
This PR was opened by the Changesets release GitHub action. When you're ready to do a release, you can merge this and the packages will be published to npm automatically. If you're not ready to do a release yet, that's fine, whenever you add more changesets to main, this PR will be updated.
Releases
@sei-js/precompiles@3.1.0
Minor Changes
b7f4e54: Add
getLogsInRange,streamLogsInRange,blockRangesandMAX_GET_LOGS_BLOCK_RANGEfor reading logs across a block range.eth_getLogsis capped per request, so reading more history than one request allows means walking it in chunks, and every project that needs logs writes that loop again. This walk only sends requests a Sei node can answer. Spans are counted inclusively the way the node counts them (2000 blocks passes, 2001 is refused). A span too heavy to answer is halved and asked again, whether the node refuses it for matching more thanmax_log_no_blocklogs (sei-chain v6.7 and later), the response passes viem's size limit (before v6.7, when bounded requests are served whole), or the span times out. A node whose refusal names a smallermax_blocks_for_logis walked at that, and busy or rate limited refusals are retried with backoff. Every request carries an explicittoBlock, because nodes before v6.7 silently cut an open-ended request off at the log cap.streamLogsInRangeyields each chunk with its logs, so a backfill can store as it goes and resume from the lasttoBlock.getLogsInRangecollects the walk into one array and awaits an optionalonChunkfor each chunk. Both take viem'sgetLogsfilter (address,eventwithargs,events,strict), accept a whole contract ABI asevents, and take any viemClient, including one that carries an account. Without atoBlockthey read to the head, since Sei finalises a block as it is produced.blockRangesgives the fixed-width plan without making requests.No dependency or peer range changes: this uses the
viempeer already declared.@sei-js/create-sei@2.0.1
Patch Changes
cb882eb: Bump the Next template's
nextandsharppins to clear three newly published advisories.The generated-app smoke audits every variant and fails on any high or critical finding. Three advisories landed against the pinned versions, so the check went red without any change to the template:
GHSA-p293-qw3h-jr36— critical, unauthenticated RCE on Windows-hosted Next.js servers,>=13.4.0 <15.5.24.GHSA-2xp9-vwfh-vxw4— critical, unauthenticated RCE in the Image Optimization API when AVIF files are used,>=10.0.0 <15.5.24.GHSA-rgj7-g3m4-5g8c— high, heap overflow in Sharp's bundled libheif decoder,<0.35.4.nextmoves15.5.21to15.5.25and thesharpoverride0.35.3to0.35.4, both inside their pinned minors.Next also widened its own Sharp declaration to
^0.34.3 || ^0.35.4, so the pinned override now sits inside the range Next supports. The image notes in the template README andnext.config.mjssaid the opposite and are corrected: images stay unoptimized to avoid requiring a native Sharp build, which is a template choice rather than a security tradeoff. Thesharpoverride itself still is one, and both notes now say so — the0.34.xhalf of Next's range remains inside the advisory, making0.35.4the floor rather than a free upgrade.The remaining
decode-uri-componentfinding is moderate and does not block the smoke.@sei-js/mcp-server@1.0.1
Patch Changes
5a40dc8: Keep each MCP runtime on the wallet configuration that passed its security check.
A later programmatic
main()could overwrite the process-wide config object while an HTTP listener started earlier was still serving requests. New sessions on that listener then built their tool list from the updated singleton, so a wallet-disabled HTTP server could expose signing tools after a trusted stdio start in the same process. No shipped CLI or host spawn does that, but the public lifecycle returned independent runtimes without isolating their keys.parseArgs()now returns a frozenAppConfigsnapshot, and every transport handles requests against that snapshot. Stopping one runtime evicts only its provider cache entry, while other runtimes keep their original signer. HTTP transports require that snapshot and derive signing policy from it.@sei-js/sei-global-wallet@2.0.1
Patch Changes
66deb15: Document that
@dynamic-labs/ethereum-aahas to match the@dynamic-labs/global-wallet-clientversion npm resolves, and keep the release checks on that resolved version instead of a constant.Dynamic declares
@dynamic-labs/ethereum-aaas an exact peer of its client and pins its internal packages to the client's version, so the two move together on every patch.@dynamic-labs/global-wallet-clientis a^4.96.3dependency here, which means a Dynamic patch inside that range changes the peer version consumers need. Pinning an older@dynamic-labs/ethereum-aathan the resolved client does not fail the install: npm cannot place the client's exact peer beside the older root copy, so it nests the client under this package and duplicates the whole Dynamic runtime. The Optional peer versions table now states this and shows how to read the version the resolved client asks for.The consumer verifier resolved
4.96.3regardless of what the range resolved to, so Dynamic publishing@dynamic-labs/global-wallet-client@4.96.4turned the nightly consumer run red on a duplicated Dynamic subtree rather than on any change in this repository. It now resolves the declared range against the registry, pins that client and the peer version it requests in each full consumer, and reports both, so a Dynamic patch is exercised the way an application receives it while a peer pin moving outside this package's published range still fails. A client that npm nests instead of hoisting is now reported as such, rather than as an unresolved dependency.No published dependency or peer range changes.
cb882eb: Override the newly advised
sharppin, and waive the one optional-AA advisory that no override can reach.Two advisories published against the existing dependency graph, so the nightly consumer run went red without any change in this repository.
GHSA-rgj7-g3m4-5g8ccoverssharpbelow0.35.4, and@dynamic-labs/iconicpinssharp@0.35.0exactly. That is the same shape as the existing Axios and UUID pins: the vulnerable copy is reachable from@dynamic-labs/global-wallet-client, overrides are root-only in both npm and Bun, and this package cannot propagate them to an application. A plain install reported nine high findings, one root advisory cascading up the Dynamic chain to@sei-js/sei-global-walletitself. The Required consumer overrides blocks now carry"sharp": "0.35.4", a patch-level move inside the pinned minor. The advisory is a heap overflow in the bundled libheif decoder, so it needs untrusted HEIF input to trigger andsharpis a build-time dependency of the icon package that never reaches a browser bundle, but it is high severity with a compatible fix available, so it is corrected rather than waived.GHSA-528h-pc64-c93xcovers everystream-jsonup to3.4.0, which the Solana RPC client'sjaysonrequires as CommonJS on the optional AA path. It cannot be overridden:3.5.0onward is ESM-only under a movedsrc/layout, so pointingjaysonat a fixed version replaces the advisory with aMODULE_NOT_FOUNDon its own require, and every CommonJS version is inside the advisory. It is now an accepted advisory for the full npm consumer, alongside the Bun waiver that already existed for advisories with no compatible fix. The finding is anO(depth²)slowdown in filters that no wallet path feeds, and the wallet-only npm consumer is still held to a strictly clean audit with no waiver, so a default install is unaffected.Several verifier gaps this exposed are closed as well.
The npm audits ran without allowing a non-zero exit, so any finding surfaced as a raw spawn error carrying the whole audit JSON rather than the assertion naming the consumer; they now fail with the offending package and advisory URL. Allowing that exit means the body has to be validated, because
npm auditfails the same way when it cannot reach the registry: anENOAUDITpayload carries no counts, so an unvalidated report would read as zero findings and turn an audit that never ran into a pass on the gate this check exists to enforce. Every npm audit result is now rejected unless it carries a real vulnerability count.The "overrides still required" report and the Bun "overrides are taking effect" assertion are now derived from the override block instead of a hardcoded
axios/uuidlist, so a newly overridden package cannot be left out and let a partial upstream fix ask for the whole waiver to be dropped. The README override blocks are asserted against the sets the consumers install, so the three hand-maintained copies cannot document an override that is never tested.The audit and override-parsing helpers moved into
scripts/consumer-audit.tsandscripts/documented-overrides.tswith unit tests, so these cases are pinned bybun test --isolate scriptsrather than only by a full consumer run.No published dependency or peer range changes.