Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
2 changes: 1 addition & 1 deletion docs/packages/sdk/bsv-sdk.md
Original file line number Diff line number Diff line change
Expand Up @@ -3,7 +3,7 @@ id: bsv-sdk
title: '@bsv/sdk'
kind: package
domain: sdk
version: '2.2.18'
version: '2.3.0'
npm: '@bsv/sdk'
last_updated: '2026-07-31'
last_verified: '2026-07-31'
Expand Down
2 changes: 1 addition & 1 deletion docs/packages/wallet/wallet-toolbox-client.md
Original file line number Diff line number Diff line change
Expand Up @@ -3,7 +3,7 @@ id: pkg-wallet-toolbox-client
title: '@bsv/wallet-toolbox-client'
kind: package
domain: wallet
version: '2.4.22'
version: '2.5.0'
last_updated: '2026-07-31'
last_verified: '2026-07-31'
review_cadence_days: 30
Expand Down
2 changes: 1 addition & 1 deletion docs/packages/wallet/wallet-toolbox-mobile.md
Original file line number Diff line number Diff line change
Expand Up @@ -3,7 +3,7 @@ id: pkg-wallet-toolbox-mobile
title: '@bsv/wallet-toolbox-mobile'
kind: package
domain: wallet
version: '2.4.22'
version: '2.5.0'
last_updated: '2026-07-31'
last_verified: '2026-07-31'
review_cadence_days: 30
Expand Down
2 changes: 1 addition & 1 deletion docs/packages/wallet/wallet-toolbox.md
Original file line number Diff line number Diff line change
Expand Up @@ -4,7 +4,7 @@ title: '@bsv/wallet-toolbox'
kind: package
domain: wallet
npm: '@bsv/wallet-toolbox'
version: '2.4.22'
version: '2.5.0'
last_updated: '2026-07-31'
last_verified: '2026-07-31'
review_cadence_days: 30
Expand Down
23 changes: 12 additions & 11 deletions docs/reference/dependency-policy.md
Original file line number Diff line number Diff line change
Expand Up @@ -3,8 +3,8 @@ id: dependency-release-policy
title: 'Dependency and Release Policy'
kind: reference
version: '1.3.0'
last_updated: '2026-07-30'
last_verified: '2026-07-30'
last_updated: '2026-08-04'
last_verified: '2026-08-04'
review_cadence_days: 30
status: stable
tags: [reference, dependencies, security, releases]
Expand Down Expand Up @@ -121,10 +121,10 @@ unresolvable public declarations.

The root workspace carries two narrow audited dependency overrides:

- Jest 30.4.2 still constrains its reporting and coverage graph to minimatch
releases that require `brace-expansion` 1.x/2.x, while
GHSA-mh99-v99m-4gvg is fixed only in `brace-expansion` 5.0.8. The workspace
substitutes 5.0.8 until Jest adopts minimatch 10.2.5 or newer.
- Jest 30.4.2 still constrains parts of its reporting and coverage graph to
minimatch releases with older `brace-expansion` ranges. The follow-up
GHSA-rgw5-rvv9-x895 requires `brace-expansion` 5.0.9, so the workspace
substitutes 5.0.9 until every supported path resolves it natively.
- Stryker 9.6.1's current `typed-rest-client@2.3.1` dependency pins vulnerable
`qs@6.15.1` exactly. A parent-scoped substitution selects 6.15.3 until
upstream accepts 6.15.2 or newer. This replaces a fragile lock-only
Expand All @@ -139,13 +139,14 @@ frozen graph stayed clean without it. The machine-readable registry now maps
every remaining selector and exact value to its exception. CI rejects a new,
changed, stale, expired, unowned, or upstream-unlinked override.

Wave 38 repeated the removal rehearsal by regenerating every standalone lock
Wave 39 repeated the removal rehearsal by regenerating every standalone lock
without its `gaxios`, `uuid`, and `brace-expansion` substitutions and checking
the natural dependency graph. It also rechecked the root Jest/minimatch,
typed-rest-client/qs, and isolated Redocly closures. All 19 remaining
selectors still prevent a reproduced vulnerable resolution or preserve the
governed reproducible generator, so none can be removed safely yet. The
method, result, count, and next rehearsal are enforced in
typed-rest-client/qs, and isolated Redocly closures, then refreshed affected
locks for the current `brace-expansion`, `fast-uri`, `ip-address`, and
`socket.io-parser` advisories. All 19 remaining selectors still prevent a
reproduced vulnerable resolution or preserve the governed reproducible
generator, so none can be removed safely yet. The method, result, count, and next rehearsal are enforced in
`governance/dependency-release-policy.json`.

The independently locked OpenAPI generator also carries a narrow Redocly
Expand Down
82 changes: 41 additions & 41 deletions docs/reference/package-api-migrations.md

Large diffs are not rendered by default.

8 changes: 4 additions & 4 deletions docs/reference/stack-facts.md
Original file line number Diff line number Diff line change
Expand Up @@ -60,14 +60,14 @@ authorized release action.
| overlays | `@bsv/overlay-discovery-services` | `2.1.6` | node-library | node-cjs, node-esm | node | `>=22` | [packages/overlays/overlay-discovery-services](https://github.com/bsv-blockchain/ts-stack/tree/main/packages/overlays/overlay-discovery-services) |
| overlays | `@bsv/overlay-express` | `2.4.9` | node-library | node-cjs, node-esm | node | `>=22` | [packages/overlays/overlay-express](https://github.com/bsv-blockchain/ts-stack/tree/main/packages/overlays/overlay-express) |
| overlays | `@bsv/overlay-topics` | `1.6.8` | node-library | node-esm | node | `>=22` | [packages/overlays/topics](https://github.com/bsv-blockchain/ts-stack/tree/main/packages/overlays/topics) |
| sdk | `@bsv/sdk` | `2.2.18` | browser-library | browser-bundler, browser-esm, node-cjs, node-esm, umd-global | browser, node, umd | `>=22` | [packages/sdk](https://github.com/bsv-blockchain/ts-stack/tree/main/packages/sdk) |
| sdk | `@bsv/sdk` | `2.3.0` | browser-library | browser-bundler, browser-esm, node-cjs, node-esm, umd-global | browser, node, umd | `>=22` | [packages/sdk](https://github.com/bsv-blockchain/ts-stack/tree/main/packages/sdk) |
| sdk | `@bsv/verifast` | `0.3.4` | wasm-library | browser-bundler, browser-esm, node-cjs, node-esm, umd-global, wasm-worker | browser, node, umd, wasm, worker | `>=22` | [packages/verifast](https://github.com/bsv-blockchain/ts-stack/tree/main/packages/verifast) |
| wallet | `@bsv/btms` | `1.1.4` | node-library | node-cjs, node-esm | node | `>=22` | [packages/wallet/btms](https://github.com/bsv-blockchain/ts-stack/tree/main/packages/wallet/btms) |
| wallet | `@bsv/btms-permission-module` | `1.1.3` | node-library | node-esm | node | `>=22` | [packages/wallet/btms-permission-module](https://github.com/bsv-blockchain/ts-stack/tree/main/packages/wallet/btms-permission-module) |
| wallet | `@bsv/wallet-relay` | `0.3.4` | cli-library | browser-bundler, browser-esm, cli, node-cjs, node-esm | browser, node | `>=22` | [packages/wallet/ts-wallet-relay](https://github.com/bsv-blockchain/ts-stack/tree/main/packages/wallet/ts-wallet-relay) |
| wallet | `@bsv/wallet-toolbox` | `2.4.22` | node-library | node-cjs | node | `>=22` | [packages/wallet/wallet-toolbox](https://github.com/bsv-blockchain/ts-stack/tree/main/packages/wallet/wallet-toolbox) |
| wallet | `@bsv/wallet-toolbox-client` | `2.4.22` | browser-library | browser-bundler, browser-esm, node-cjs, node-esm | browser, node | `>=22` | [packages/wallet/wallet-toolbox/client](https://github.com/bsv-blockchain/ts-stack/tree/main/packages/wallet/wallet-toolbox/client) |
| wallet | `@bsv/wallet-toolbox-mobile` | `2.4.22` | react-native-library | react-native-metro | react-native | `>=22` | [packages/wallet/wallet-toolbox/mobile](https://github.com/bsv-blockchain/ts-stack/tree/main/packages/wallet/wallet-toolbox/mobile) |
| wallet | `@bsv/wallet-toolbox` | `2.5.0` | node-library | node-cjs | node | `>=22` | [packages/wallet/wallet-toolbox](https://github.com/bsv-blockchain/ts-stack/tree/main/packages/wallet/wallet-toolbox) |
| wallet | `@bsv/wallet-toolbox-client` | `2.5.0` | browser-library | browser-bundler, browser-esm, node-cjs, node-esm | browser, node | `>=22` | [packages/wallet/wallet-toolbox/client](https://github.com/bsv-blockchain/ts-stack/tree/main/packages/wallet/wallet-toolbox/client) |
| wallet | `@bsv/wallet-toolbox-mobile` | `2.5.0` | react-native-library | react-native-metro | react-native | `>=22` | [packages/wallet/wallet-toolbox/mobile](https://github.com/bsv-blockchain/ts-stack/tree/main/packages/wallet/wallet-toolbox/mobile) |

## Standalone infrastructure manifests

Expand Down
22 changes: 11 additions & 11 deletions governance/dependency-release-policy.json
Original file line number Diff line number Diff line change
@@ -1,6 +1,6 @@
{
"schemaVersion": 1,
"lastReviewed": "2026-07-30",
"lastReviewed": "2026-08-04",
"owner": "ts-stack-maintainers",
"routineUpdates": {
"dependabotConfig": ".github/dependabot.yml",
Expand Down Expand Up @@ -144,17 +144,17 @@
"closeImplementationWaveAfterPublication": false
},
"overrideRemovalReview": {
"reviewedAt": "2026-07-30",
"method": "Regenerated each standalone npm lockfile without gaxios, uuid, or brace-expansion overrides and compared the resulting natural graph; separately rechecked the root Jest/minimatch, typed-rest-client/qs, and isolated Redocly codegen closures.",
"reviewedAt": "2026-08-04",
"method": "Regenerated each standalone npm lockfile without gaxios, uuid, or brace-expansion overrides and compared the resulting natural graph; separately rechecked the root Jest/minimatch, typed-rest-client/qs, and isolated Redocly codegen closures, then refreshed the affected locks against the current brace-expansion, fast-uri, ip-address, and socket.io-parser advisories.",
"retainedCount": 19,
"result": "Every remaining override still prevents a reproduced vulnerable transitive version or preserves the isolated reproducible codegen closure. No override can be removed safely in this wave.",
"nextReview": "Rehearse removal monthly and immediately after upstream Google client, Jest/minimatch, typed-rest-client, or Redocly dependency changes."
"nextReview": "Rehearse removal monthly and immediately after upstream Google client, Jest/minimatch, typed-rest-client, Redocly, AJV, express-rate-limit, or Socket.IO dependency changes."
},
"overrideRegistry": [
{
"source": "pnpm-workspace.yaml",
"selector": "brace-expansion@<=5.0.7",
"value": "5.0.8",
"selector": "brace-expansion@<5.0.9",
"value": "5.0.9",
"exceptionId": "brace-expansion-jest-override"
},
{
Expand All @@ -176,7 +176,7 @@
"source": "tools/codegen/node/package.json",
"selector": "minimatch@10.2.5",
"value": {
"brace-expansion": "5.0.8"
"brace-expansion": "5.0.9"
},
"exceptionId": "openapi-typescript-redocly-overrides"
},
Expand All @@ -189,7 +189,7 @@
{
"source": "infra/message-box-server/package.json",
"selector": "brace-expansion",
"value": "5.0.8",
"value": "5.0.9",
"exceptionId": "brace-expansion-jest-override"
},
{
Expand All @@ -213,7 +213,7 @@
{
"source": "infra/uhrp-server-basic/package.json",
"selector": "brace-expansion",
"value": "5.0.8",
"value": "5.0.9",
"exceptionId": "brace-expansion-jest-override"
},
{
Expand All @@ -225,7 +225,7 @@
{
"source": "infra/uhrp-server-cloud-bucket/package.json",
"selector": "brace-expansion",
"value": "5.0.8",
"value": "5.0.9",
"exceptionId": "brace-expansion-jest-override"
},
{
Expand Down Expand Up @@ -255,7 +255,7 @@
{
"source": "infra/wab/package.json",
"selector": "brace-expansion",
"value": "5.0.8",
"value": "5.0.9",
"exceptionId": "brace-expansion-jest-override"
},
{
Expand Down
32 changes: 16 additions & 16 deletions governance/package-release-notes.json
Original file line number Diff line number Diff line change
Expand Up @@ -145,10 +145,10 @@
},
{
"name": "@bsv/sdk",
"publishedVersion": "2.2.0",
"releaseType": "patch",
"summary": "Accumulates security and correctness hardening, transaction and action-batch performance work, strict package contracts, safer text and telemetry handling, and caches unchanged BEEF dependency-sort results so repeated wallet known-txid preparation avoids a full topological sort.",
"migration": "No consumer migration is required. BEEF ordering, validation results, serialized bytes, SDK 2.x wire encodings, BRC-103/104 behavior, and supported imports are unchanged."
"publishedVersion": "2.2.18",
"releaseType": "minor",
"summary": "Adds batched proven-transaction BEEF assembly and deferred-then-compound Merkle proof validation, reuses shared proof hashes and BRC-42 counterparty secrets, and accelerates optional-backend P2PKH public-key emission.",
"migration": "No consumer migration is required. The new APIs are additive; BEEF ordering and bytes, proof validity, signatures, synchronous signing, SDK 2.x wire encodings, BRC-103/104 behavior, and supported imports are unchanged."
},
{
"name": "@bsv/simple",
Expand Down Expand Up @@ -194,24 +194,24 @@
},
{
"name": "@bsv/wallet-toolbox",
"publishedVersion": "2.4.4",
"releaseType": "patch",
"summary": "Adds fee-aware read-only legacy createAction planning, one-transaction funding claims, exact reservation filtering, Knex and IndexedDB funding indexes, faster known-txid and proof handling, and privacy-safe timings for every material funding and BEEF phase.",
"migration": "No consumer migration is required. SQLite/MySQL and IndexedDB indexes are added by the existing migration paths; wallet data and results, BRC-103/104, AuthFetch, Auth Express Middleware, AuthSocket, JSON-RPC, provider calls, and wallet wire behavior are unchanged."
"publishedVersion": "2.4.22",
"releaseType": "minor",
"summary": "Makes the successful fragmented createAction path atomic and set-based, overlaps batched proof reads with persistence, batch-validates compound proofs and canonical P2PKH signatures, shares BRC-42 derivation work, removes unused commit reads, bulk-inserts outputs, coalesces authenticated timestamp-only Knex session touches, and adds timings for every remaining material phase.",
"migration": "No consumer migration is required. Storage-provider additions are backward-compatible with fallbacks, existing databases use the normal migration path, and wallet results, BRC-103/104, AuthFetch, Auth Express Middleware, AuthSocket, JSON-RPC, provider calls, and wallet wire behavior are unchanged."
},
{
"name": "@bsv/wallet-toolbox-client",
"publishedVersion": "2.4.4",
"releaseType": "patch",
"summary": "Carries the lockstep browser build with read-only funding planning, atomic claims, IndexedDB funding indexes, BEEF-history caching, and expanded privacy-safe createAction timings.",
"migration": "No consumer migration is required; IndexedDB upgrades automatically, and BRC-103/104, AuthFetch, browser entry points, JSON-RPC, and remote storage contracts remain unchanged."
"publishedVersion": "2.4.22",
"releaseType": "minor",
"summary": "Carries the lockstep browser build with batched proof assembly, linear funding/signing work, canonical P2PKH verification, expired-reservation filtering, and complete privacy-safe createAction timings.",
"migration": "No consumer migration is required; older compatible SDK peers retain the validated sequential proof fallback, IndexedDB upgrades automatically, and BRC-103/104, AuthFetch, browser entry points, JSON-RPC, and remote storage contracts remain unchanged."
},
{
"name": "@bsv/wallet-toolbox-mobile",
"publishedVersion": "2.4.4",
"releaseType": "patch",
"summary": "Carries the lockstep mobile build with read-only funding planning, atomic claims, faster BEEF-history handling, and expanded privacy-safe createAction timings.",
"migration": "No consumer migration is required; BRC-103/104, AuthFetch, React Native, the mobile bridge, JSON-RPC, and remote storage contracts remain unchanged."
"publishedVersion": "2.4.22",
"releaseType": "minor",
"summary": "Carries the lockstep mobile build with batched proof assembly, linear funding/signing work, canonical P2PKH verification, expired-reservation filtering, and complete privacy-safe createAction timings.",
"migration": "No consumer migration is required; older compatible SDK peers retain the validated sequential proof fallback, and BRC-103/104, AuthFetch, React Native, the mobile bridge, JSON-RPC, and remote storage contracts remain unchanged."
},
{
"name": "create-bsv-app",
Expand Down
8 changes: 4 additions & 4 deletions governance/repository-health/baselines.json
Original file line number Diff line number Diff line change
Expand Up @@ -320,13 +320,13 @@
"@bsv/overlay-discovery-services": "2.1.6",
"@bsv/overlay-express": "2.4.9",
"@bsv/overlay-topics": "1.6.8",
"@bsv/sdk": "2.2.18",
"@bsv/sdk": "2.3.0",
"@bsv/verifast": "0.3.4",
"@bsv/btms": "1.1.4",
"@bsv/btms-permission-module": "1.1.3",
"@bsv/wallet-relay": "0.3.4",
"@bsv/wallet-toolbox-client": "2.4.22",
"@bsv/wallet-toolbox-mobile": "2.4.22",
"@bsv/wallet-toolbox": "2.4.22"
"@bsv/wallet-toolbox-client": "2.5.0",
"@bsv/wallet-toolbox-mobile": "2.5.0",
"@bsv/wallet-toolbox": "2.5.0"
}
}
8 changes: 5 additions & 3 deletions governance/repository-health/exceptions.json
Original file line number Diff line number Diff line change
@@ -1,6 +1,6 @@
{
"schemaVersion": 1,
"lastReviewed": "2026-07-30",
"lastReviewed": "2026-08-04",
"exceptions": [
{
"id": "scorecard-maintainer-merge-policy",
Expand Down Expand Up @@ -89,7 +89,7 @@
"category": "override",
"target": "pnpm-workspace.yaml and four standalone Jest service manifests overriding brace-expansion <=5.0.7",
"owner": "ts-stack-maintainers",
"reason": "Jest 30.4.2 still constrains its reporting and coverage paths to minimatch releases that require brace-expansion 1.x/2.x, while GHSA-mh99-v99m-4gvg is fixed only in brace-expansion 5.0.8.",
"reason": "Jest 30.4.2 still constrains reporting and coverage paths to minimatch releases that require older brace-expansion ranges. GHSA-mh99-v99m-4gvg required 5.0.8, and the follow-up GHSA-rgw5-rvv9-x895 requires 5.0.9, so the governed substitution selects the current patched release.",
"evidence": [
"pnpm-workspace.yaml#overrides",
"pnpm-lock.yaml#overrides",
Expand All @@ -99,11 +99,12 @@
"infra/uhrp-server-cloud-bucket/package.json#overrides",
"infra/wab/package.json#overrides",
"https://github.com/advisories/GHSA-mh99-v99m-4gvg",
"https://github.com/advisories/GHSA-rgw5-rvv9-x895",
"https://github.com/bsv-blockchain/ts-stack/issues/324"
],
"created": "2026-07-25",
"reviewBy": "2026-08-25",
"removeWhen": "Remove after the supported Jest dependency graph adopts minimatch 10.2.5 or newer and natively resolves brace-expansion 5.0.8 or newer."
"removeWhen": "Remove after the supported Jest dependency graph natively resolves brace-expansion 5.0.9 or newer across every coverage and reporting path."
},
{
"id": "standalone-gaxios-advisory-override",
Expand Down Expand Up @@ -168,6 +169,7 @@
"tools/codegen/node/package-lock.json",
"https://github.com/advisories/GHSA-52cp-r559-cp3m",
"https://github.com/advisories/GHSA-mh99-v99m-4gvg",
"https://github.com/advisories/GHSA-rgw5-rvv9-x895",
"https://github.com/openapi-ts/openapi-typescript/blob/openapi-typescript%407.13.0/packages/openapi-typescript/package.json"
],
"created": "2026-07-25",
Expand Down
Loading
Loading