fix(protocol): use native token ID and pin signer dependencies - #158
Merged
Merged
Conversation
mellowcroc
added this pull request to stack #156
October 2, 2026 07:30
mellowcroc
force-pushed
the
fix/sca-token-id
branch
from
October 2, 2026 07:39
3049a38 to
0009828
Compare
mellowcroc
force-pushed
the
fix/sca-token-id
branch
from
October 2, 2026 08:08
0009828 to
4b91b6e
Compare
graikos
previously approved these changes
Oct 2, 2026
mellowcroc
force-pushed
the
fix/sca-token-id
branch
from
October 2, 2026 09:09
4b91b6e to
fdcda36
Compare
mellowcroc
force-pushed
the
fix/sca-token-id
branch
from
October 2, 2026 09:31
fdcda36 to
6a1cf17
Compare
graikos
approved these changes
Oct 2, 2026
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Findings
Addresses F-2026-19093 and F-2026-19127.
tokenIdas Mina's native token identifier and update contract checks, event consumers, lightnet fixtures, and online/offline signing together.o1js@3.0.0directly in contracts, use npmmina-signer@4.1.0across the signing surfaces, and remove the vendored signer submodule. Update the offline WASM shim, CI/release packaging, and audit guides for the new dependency layout.This PR targets #157 (
fix/sca-contract-rules) and is followed byfix/sca-event-memoin stack #156. Offline request/response format remains v1.Validation and merge gate
On the rebased full local stack: contracts build; 153 focused contract tests, 13 UI tests, and 27 offline CLI tests passed. Contract and CLI tests used
SKIP_PROOFS=1. The SCA patches were unchanged by the rebase.The complete offline end-to-end run with real proofs timed out during the first proof in the earlier local attempt and has not been completed on this head. It remains a merge gate, along with source-bound testnet/mainnet VK and hosted checks. No deployment or release is included.