diff --git a/.github/workflows/ci.yml b/.github/workflows/ci.yml index 507b94b2..217c8f61 100644 --- a/.github/workflows/ci.yml +++ b/.github/workflows/ci.yml @@ -157,6 +157,8 @@ jobs: steps: - name: Checkout Codebase uses: actions/checkout@v4 + with: + fetch-depth: 0 # commit-range signature checks (#619) - name: Setup Node.js Environment uses: actions/setup-node@v4 @@ -185,24 +187,6 @@ jobs: tests/e2e/layout.spec.ts-snapshots/ if-no-files-found: ignore - # Closes #540 — license gate (fails on GPL/unauthorized copyleft), - # install-script allowlist, registry/integrity hijack checks, and a - # committed licenses.json freshness check. Zero dependencies: no install. - supply-chain-audit: - name: Supply Chain & License Audit - runs-on: ubuntu-latest - steps: - - name: Checkout Codebase - uses: actions/checkout@v4 - - - name: Setup Node.js Environment - uses: actions/setup-node@v4 - with: - node-version: 22.x - - - name: Audit dependencies - run: node scripts/audit-deps.js --check - # Build-pipeline network egress monitor: every outbound connection made # while dependencies are fetched and while `npm run build` runs is captured # (tcpdump) and classified against the allowlist in @@ -210,9 +194,6 @@ jobs: # and the audit logs are uploaded for security review. build-egress-monitor: name: Build Egress Monitor & Data Exfiltration Gate - # #541 / #543 — Soroban contract unit tests (aegis_vault treasury, DAO oracle). - contracts: - name: Soroban Contract Tests runs-on: ubuntu-latest steps: - name: Checkout Codebase @@ -250,6 +231,116 @@ jobs: path: artifacts/build-egress/ if-no-files-found: warn + # #541 / #543 — Soroban contract unit tests (aegis_vault treasury, DAO oracle). + contracts: + name: Soroban Contract Tests + runs-on: ubuntu-latest + steps: + - name: Checkout code + uses: actions/checkout@v4 + + - name: Setup Rust toolchain + uses: dtolnay/rust-toolchain@stable + with: + targets: wasm32v1-none + + - name: Cache cargo registry and build artifacts + uses: Swatinem/rust-cache@v2 + with: + workspaces: | + contracts/aegis_vault + contracts/maintainer_vault + contracts/helphone_dao + contract + + - name: Run cargo test (aegis_vault) + working-directory: contracts/aegis_vault + run: cargo test --locked + + - name: Run cargo test (maintainer_vault) + working-directory: contracts/maintainer_vault + run: cargo test --locked + + # Closes #587 — DAO + open source sustainability reserve (1% fee, + # DAO-voted maintainer grants). + - name: Run cargo test (helphone_dao) + working-directory: contracts/helphone_dao + run: cargo test --locked + + # The `soroban` CLI was renamed to `stellar` (soroban-cli -> stellar-cli); + # `stellar contract build` is the current equivalent of the issue's + # `soroban contract build` and is what compiles contracts to the + # wasm32v1-none target actually deployed (see soroban-contract.md's + # documented deploy steps). + - name: Install Stellar CLI + run: cargo install --locked stellar-cli --version ^23 + + - name: Build aegis_vault contract (stellar contract build) + working-directory: contracts/aegis_vault + run: stellar contract build + + - name: Build helphone-contract (stellar contract build) + working-directory: contract + run: stellar contract build + + # Supply-chain security: typosquatting gate, transitive vulnerability scan, + # WASM reproducibility, dep health, license compliance, CVE patch plan, and + # maintainer key revocation check (#586 #587 #588 #589 #590 #591 #599 #619). + supply-chain: + runs-on: ubuntu-latest + steps: + - name: Checkout code + uses: actions/checkout@v4 + with: + fetch-depth: 0 # commit-range signature checks (#619) + + - name: Setup Node.js + uses: actions/setup-node@v4 + with: + node-version: 22.x + cache: 'npm' + + - name: Install dependencies + run: npm ci + + # Closes #588 — blocks PRs introducing typosquatted / hijacked packages. + - name: Typosquatting gate + run: node scripts/detect-typosquatting.js + + # Closes #589 — transitive DAG audit (offline graph + depth stats; + # live OSV lookup is best-effort via --audit). + - name: Transitive vulnerability scan + run: node scripts/transitive-vulnerability-scanner.js + + # Closes #590 — asserts committed ZK WASM artifact hash + flags. + - name: WASM reproducibility check + run: bash scripts/verify-wasm-build.sh + + # Closes #591 — informational health index; never blocks merges. + - name: Dependency health monitor + run: node scripts/monitor-dep-health.js --offline + continue-on-error: true + + # Closes #586 — npm + Cargo license scan; fails on unapproved + # GPL/AGPL/strong-copyleft licenses (see docs/legal-compliance.md). + - name: License compliance & copyleft gate + run: node scripts/license-compliance.js --no-write + + # Closes #599 — GitHub Security Advisory scan + minimum-patch plan. + # Report-only here; scheduled patch PRs come from cve-patch-bot.yml. + - name: CVE patch plan + run: node scripts/auto-patch-cve.js --fail-on critical + + # Closes #619 — commit signatures vs live key revocation lists + WoT. + - name: Maintainer key revocation check + run: | + if [ "${{ github.event_name }}" = "pull_request" ]; then + RANGE="origin/${{ github.base_ref }}..HEAD" + else + RANGE="HEAD" + fi + node scripts/security/verify_maintainer_keys.js --pinned --range "$RANGE" --max 100 + # Automated dependency version drift & breaking API change analyzer: the # exported TypeScript surface of every protected package (functions, class # members, call signatures) is extracted from its .d.ts entry point with the @@ -289,6 +380,7 @@ jobs: name: api-drift-report path: api-drift-report.txt if-no-files-found: ignore + - name: Setup Rust toolchain uses: dtolnay/rust-toolchain@stable diff --git a/.github/workflows/cve-patch-bot.yml b/.github/workflows/cve-patch-bot.yml new file mode 100644 index 00000000..b74947c1 --- /dev/null +++ b/.github/workflows/cve-patch-bot.yml @@ -0,0 +1,54 @@ +name: CVE Patch Bot + +# Closes #599 — parses GitHub Security Advisories for the npm tree, applies +# the minimum non-vulnerable versions, runs the full regression suite and +# opens a security PR. Major-version fixes are listed for manual follow-up. +on: + schedule: + - cron: "0 5 * * 1" # weekly, Monday 05:00 UTC + workflow_dispatch: + inputs: + min-severity: + description: "Lowest severity to patch (low|moderate|high|critical)" + default: "low" + +permissions: + contents: write + pull-requests: write + +concurrency: + group: cve-patch-bot + cancel-in-progress: false + +jobs: + patch: + runs-on: ubuntu-latest + steps: + - uses: actions/checkout@v4 + + - uses: actions/setup-node@v4 + with: + node-version: 22.x + cache: npm + + - run: npm ci + + - name: Configure bot identity + run: | + git config user.name "helphone-security-bot" + git config user.email "41898282+github-actions[bot]@users.noreply.github.com" + + # PRs opened with the default GITHUB_TOKEN do not trigger CI; set a + # CVE_BOT_TOKEN secret (fine-grained PAT / GitHub App) so they do. + - name: Patch, verify and open PR + env: + GH_TOKEN: ${{ secrets.CVE_BOT_TOKEN || secrets.GITHUB_TOKEN }} + GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }} + run: | + node scripts/auto-patch-cve.js \ + --source github \ + --min-severity "${{ github.event.inputs.min-severity || 'low' }}" \ + --verify "npm test" \ + --verify "npm run build" \ + --verify "node scripts/license-compliance.js --no-write" \ + --open-pr --base "${{ github.event.repository.default_branch }}" diff --git a/.github/workflows/slsa-provenance.yml b/.github/workflows/slsa-provenance.yml index 4e00f2fd..5fbc1ea6 100644 --- a/.github/workflows/slsa-provenance.yml +++ b/.github/workflows/slsa-provenance.yml @@ -26,7 +26,18 @@ jobs: - run: npm ci - - run: npm run build + # #619 — refuse to release when the tag / recent commits are signed by + # a key that has since been revoked as compromised (live KRL lookup). + - name: Verify release signing keys + run: | + ARGS="--pinned --refresh --range HEAD --max 50" + if [ "${{ github.ref_type }}" = "tag" ]; then ARGS="$ARGS --tags ${{ github.ref_name }}"; fi + if [ "${{ vars.REQUIRE_SIGNED_RELEASES }}" = "true" ]; then ARGS="$ARGS --strict"; fi + node scripts/security/verify_maintainer_keys.js $ARGS + + # #586 — production build + licenses.json attribution manifest, so the + # manifest is covered by the signed digests below. + - run: npm run build:release # Digest manifest of every shipped file. This exact file is what gets # signed and logged in Rekor; the browser re-hashes it and its own entry diff --git a/.github/workflows/verify-keys.yml b/.github/workflows/verify-keys.yml new file mode 100644 index 00000000..2a5e01a1 --- /dev/null +++ b/.github/workflows/verify-keys.yml @@ -0,0 +1,61 @@ +name: Maintainer Key Verification + +# Closes #619 — validates OpenPGP signatures on commits, tags and pinned +# dependency maintainer keys against live key revocation data from +# keys.openpgp.org + keyserver.ubuntu.com, and evaluates web-of-trust +# certifications (config/maintainer-keys.json). +# +# The nightly run is the important one: a key revoked as COMPROMISED after a +# release invalidates every signature it made, so every release tag is +# re-checked against a freshly refreshed revocation list. +on: + push: + branches: [main, develop] + tags: ["v*"] + pull_request: + branches: [main, develop] + schedule: + - cron: "17 3 * * *" # nightly KRL refresh + workflow_dispatch: + +permissions: + contents: read + +jobs: + verify-keys: + runs-on: ubuntu-latest + steps: + - uses: actions/checkout@v4 + with: + fetch-depth: 0 # full history + tags + + - uses: actions/setup-node@v4 + with: + node-version: 22.x + + # Validated public keys are cached between runs; entries older than + # cacheTtlHours are refetched, and --refresh (nightly) forces a refetch. + - uses: actions/cache@v4 + with: + path: .cache/maintainer-keys + key: maintainer-keys-${{ github.run_id }} + restore-keys: maintainer-keys- + + - name: Pull request commits + if: github.event_name == 'pull_request' + run: node scripts/security/verify_maintainer_keys.js --pinned --range "origin/${{ github.base_ref }}..HEAD" + + - name: Pushed commits + if: github.event_name == 'push' && github.ref_type == 'branch' + run: node scripts/security/verify_maintainer_keys.js --pinned --range HEAD --max 50 + + - name: Release tag + if: github.event_name == 'push' && github.ref_type == 'tag' + run: | + STRICT="" + if [ "${{ vars.REQUIRE_SIGNED_RELEASES }}" = "true" ]; then STRICT="--strict"; fi + node scripts/security/verify_maintainer_keys.js --pinned --refresh --tags "${{ github.ref_name }}" $STRICT + + - name: Nightly revocation sweep (all release tags + pinned keys) + if: github.event_name == 'schedule' || github.event_name == 'workflow_dispatch' + run: node scripts/security/verify_maintainer_keys.js --pinned --refresh --tags "v*" --range HEAD --max 100 diff --git a/.gitignore b/.gitignore index 2a82cc42..e333ba21 100644 --- a/.gitignore +++ b/.gitignore @@ -45,3 +45,8 @@ src/wasm/**/target/ # Python tooling cache __pycache__/ *.py[cod] +/target/ +# CVE patch bot scratch output (#599) +.cve-patch-pr.md +# maintainer key cache (#619) +.cache/ diff --git a/Cargo.toml b/Cargo.toml index 22ea29bf..a5756512 100644 --- a/Cargo.toml +++ b/Cargo.toml @@ -5,7 +5,11 @@ [workspace] resolver = "2" -members = ["contracts/*"] +members = [ + "contracts/aegis_vault", + "contracts/helphone_dao", + "contracts/maintainer_vault", +] exclude = [ # Own workspace root. "contract", @@ -14,15 +18,11 @@ exclude = [ "src/wasm/telemetry_reader", ] +# Member crates' [profile.release] sections are ignored inside a workspace; +# the Soroban size/safety profile has to live at the root. # Member crates declare this same release profile; it is mirrored here because # Cargo only honours `[profile]` tables at the workspace root, so building from # the repo root must produce the same wasm artifact as building in a crate dir. -[workspace] -resolver = "2" -members = ["contracts/aegis_vault", "contracts/helphone_dao"] -# Standalone crates that keep their own lockfiles / workspaces. -exclude = ["contract", "contracts/emergency_vault", "contracts/maintainer_vault"] - [profile.release] opt-level = "z" lto = true @@ -30,6 +30,14 @@ codegen-units = 1 panic = "abort" strip = true overflow-checks = true +debug-assertions = false + +# #586: Cargo licenses are gated with the npm tree by +# scripts/license-compliance.js (via `cargo metadata --locked`); see +# docs/legal-compliance.md for the approved/denied policy. +[workspace.metadata.license-compliance] +gate = "node scripts/license-compliance.js --no-write" +manifest = "licenses.json" # --------------------------------------------------------------------------- # Version pinning guard (scripts/detect-api-drift.js) — Rust half. diff --git a/README.md b/README.md index d3cadf0f..f03a0c2b 100644 --- a/README.md +++ b/README.md @@ -2,6 +2,18 @@ HelPhone is a React + Vite community emergency response application built on Stellar. It combines wallet-gated help requests, Soroban smart contracts, local ZK privacy proofs, WebAuthn Passkeys, and automated contract storage state backups. +## The 3-minute story + +Someone is in trouble and needs help from nearby people — but broadcasting "I'm hurt, here is my exact address and my name" to a public blockchain is dangerous. HelPhone fixes that: + +1. **Emergency.** A person taps _Get help_ and picks what happened (lost, fallen, medical, danger…). +2. **Identity protected.** Their name and contact never leave the browser. Only a pseudonymous `Private request #N` is written on-chain. +3. **Location proven, not revealed.** The exact GPS coordinate is used as a _private witness_. A Noir ZK proof is generated **locally** to prove "I am inside this zone" without disclosing where. Only a coarse ~1 km point and a 3 km proof box go on-chain. +4. **Stellar verifies.** The proof fingerprint (nullifier) and transaction hash are recorded on Soroban testnet, visible in the live `ZK PRIVACY CHECKPOINT` panel. +5. **Double-claim blocked.** The nullifier is `Poseidon2(secret_id, campaign_id)` — one claim per user per campaign, so the same proof can't be replayed. + +Privacy here is real, not theater: see [`anonymizeLocation`](src/pages/Help.jsx) (coarsens coordinates) and `createRequest(..., '', '', ...)` in [`handleSubmit`](src/pages/Help.jsx) (empty name/contact on-chain). + --- ## Technical Subsystems & Architecture @@ -105,6 +117,7 @@ Configure `.env`: ```bash VITE_MAPBOX_TOKEN=... VITE_AEGIS_VAULT_ID=... +VITE_ZK_PROVER_URL=/zk SOROBAN_RPC_URL=https://soroban-testnet.stellar.org CONTRACT_ID=CC325F37QW7N2F5M3QGHL4A4O7J2K9L0M1N2O3P4Q5R6S7T8U9V0 ``` diff --git a/config/maintainer-keys.json b/config/maintainer-keys.json new file mode 100644 index 00000000..38074a6e --- /dev/null +++ b/config/maintainer-keys.json @@ -0,0 +1,18 @@ +{ + "$comment": "Maintainer key policy for scripts/security/verify_maintainer_keys.js (#619). See docs/security-runbook.md.", + "keyservers": ["https://keys.openpgp.org", "https://keyserver.ubuntu.com"], + "cacheDir": ".cache/maintainer-keys", + "cacheTtlHours": 6, + "minCertifications": 1, + "trustedKeys": [ + { + "fingerprint": "968479A1AFF927E37D1A566BB5690EEEBB952194", + "owner": "GitHub web-flow (merges and edits made in the GitHub UI, 2024+)" + }, + { + "fingerprint": "5DE3E0509C47EA3CF04A42D34AEE18F83AFDEB23", + "owner": "GitHub web-flow (expired 2024-01-16; still valid for older commits)" + } + ], + "dependencies": [] +} diff --git a/contracts/helphone_dao/src/lib.rs b/contracts/helphone_dao/src/lib.rs index 00804e98..07663449 100644 --- a/contracts/helphone_dao/src/lib.rs +++ b/contracts/helphone_dao/src/lib.rs @@ -3,10 +3,13 @@ mod oracle; use soroban_sdk::{ - contract, contracterror, contractevent, contractimpl, contracttype, symbol_short, Address, Env, - IntoVal, Symbol, Val, Vec as SorobanVec, + contract, contracterror, contractevent, contractimpl, contracttype, + symbol_short, Address, Env, IntoVal, Symbol, Val, Vec as SorobanVec, }; +pub mod sustainability; +use sustainability::{MaintainerGrant, SustainabilityStats}; + pub use oracle::{OracleAsset, PriceData, MAX_PRICE_AGE_SECS}; // ── Constants ────────────────────────────────────────────────────── @@ -130,14 +133,19 @@ pub enum DaoError { TimelockNotExpired = 10, ExecutionFailed = 11, ProposalLimitReached = 12, - QueueRequired = 13, - NotSecurityGuardian = 14, - InvalidSecurityThreshold = 15, - InsufficientSecurityApprovals = 16, - TimelockOverflow = 17, - ProposalNotQueued = 18, - TimelockExpired = 19, - SecurityEpochOverflow = 20, + SustainabilityNotConfigured = 13, + InvalidAmount = 14, + InsufficientReserve = 15, + GrantNotFound = 16, + GrantAlreadyDisbursed = 17, + QueueRequired = 18, + NotSecurityGuardian = 19, + InvalidSecurityThreshold = 20, + InsufficientSecurityApprovals = 21, + TimelockOverflow = 22, + ProposalNotQueued = 23, + TimelockExpired = 24, + SecurityEpochOverflow = 25, } // ── Events ───────────────────────────────────────────────────────── @@ -198,6 +206,21 @@ fn key_proposal_count() -> Symbol { } fn key_executed_set() -> Symbol { symbol_short!("execd") +fn key_voting_supply() -> Symbol { + symbol_short!("vsupply") +} + +fn require_admin(env: &Env, admin: &Address) -> Result<(), DaoError> { + let stored_admin: Address = env + .storage() + .instance() + .get(&key_admin()) + .ok_or(DaoError::NotAdmin)?; + if *admin != stored_admin { + return Err(DaoError::NotAdmin); + } + admin.require_auth(); + Ok(()) } #[contract] @@ -582,6 +605,15 @@ impl HelPhoneDao { } .publish(&env); + // Grant proposals pay out immediately when the reserve covers them; + // otherwise the grant stays Pending for a later `disburse_grant`. + if sustainability::get_grant(&env, proposal_id).is_some() { + match sustainability::disburse(&env, proposal_id) { + Ok(_) | Err(DaoError::InsufficientReserve) => {} + Err(e) => return Err(e), + } + } + Ok(()) } @@ -803,10 +835,94 @@ impl HelPhoneDao { /// Read: get list of executed proposal IDs. pub fn get_executed_proposals(env: Env) -> SorobanVec { - env.storage() - .instance() - .get(&key_executed_set()) - .unwrap_or(SorobanVec::new(&env)) + env.storage().instance().get(&key_executed_set()).unwrap_or(SorobanVec::new(&env)) + } + + /// Read: voting supply used as the quorum denominator for new proposals. + pub fn get_voting_supply(env: Env) -> i128 { + env.storage().instance().get(&key_voting_supply()).unwrap_or(0) + } + + /// Admin: set the governance token voting supply (quorum denominator). + pub fn set_voting_supply(env: Env, admin: Address, supply: i128) -> Result<(), DaoError> { + require_admin(&env, &admin)?; + if supply < 0 { + return Err(DaoError::InvalidAmount); + } + env.storage().instance().set(&key_voting_supply(), &supply); + Ok(()) + } + + // ── Open source sustainability reserve (#587) ────────────────── + + /// Admin: set the SAC token the sustainability reserve is held in. + pub fn configure_sustainability(env: Env, admin: Address, reserve_token: Address) -> Result<(), DaoError> { + require_admin(&env, &admin)?; + sustainability::set_token(&env, &reserve_token); + Ok(()) + } + + /// Route the 1% sustainability fee on `gross_amount` from `payer` into + /// the reserve. Returns the fee collected. + pub fn collect_sustainability_fee(env: Env, payer: Address, gross_amount: i128) -> Result { + payer.require_auth(); + sustainability::collect_fee(&env, &payer, gross_amount) + } + + /// Open a `FundAllocation` proposal granting `amount` of the reserve + /// token to the maintainer of `package`. Returns the proposal id. + pub fn propose_maintainer_grant( + env: Env, + proposer: Address, + maintainer: Address, + package: soroban_sdk::String, + amount: i128, + title: soroban_sdk::String, + description: soroban_sdk::String, + ) -> Result { + if amount <= 0 { + return Err(DaoError::InvalidAmount); + } + if !sustainability::is_configured(&env) { + return Err(DaoError::SustainabilityNotConfigured); + } + let proposal_id = Self::create_proposal( + env.clone(), + proposer, + title, + description, + ProposalType::FundAllocation, + soroban_sdk::Bytes::new(&env), + )?; + sustainability::record_grant(&env, proposal_id, maintainer, package, amount)?; + Ok(proposal_id) + } + + /// Permissionless: pay out a grant whose proposal has been executed but + /// was left Pending because the reserve was short at execution time. + pub fn disburse_grant(env: Env, proposal_id: u64) -> Result { + let proposal: Proposal = env + .storage().persistent().get(&DataKey::Proposal(proposal_id)) + .ok_or(DaoError::ProposalNotFound)?; + if proposal.status != ProposalStatus::Executed { + return Err(DaoError::NotPassed); + } + sustainability::disburse(&env, proposal_id) + } + + /// Read: grant attached to a proposal, if any. + pub fn get_maintainer_grant(env: Env, proposal_id: u64) -> Option { + sustainability::get_grant(&env, proposal_id) + } + + /// Read: lifetime grant total received by a maintainer. + pub fn get_maintainer_funding(env: Env, maintainer: Address) -> i128 { + sustainability::maintainer_total(&env, maintainer) + } + + /// Read: reserve and grant statistics for the sustainability dashboard. + pub fn get_sustainability_stats(env: Env) -> SustainabilityStats { + sustainability::stats(&env) } /// Admin: update the governance token address. diff --git a/contracts/helphone_dao/src/sustainability.rs b/contracts/helphone_dao/src/sustainability.rs new file mode 100644 index 00000000..903b54ed --- /dev/null +++ b/contracts/helphone_dao/src/sustainability.rs @@ -0,0 +1,229 @@ +//! Open Source Sustainability Reserve (#587). +//! +//! A fixed 1% (`SUSTAINABILITY_FEE_BPS`) cut of HelPhone protocol transactions +//! is pulled — in a Stellar Asset Contract (SAC) token — into a reserve held +//! by the DAO contract. Maintainers of critical, underfunded open source +//! dependencies receive grants from that reserve only after a +//! `FundAllocation` proposal naming them passes a DAO vote and clears the +//! execution timelock. +//! +//! Lifecycle of a grant: +//! propose_maintainer_grant -> cast_vote* -> execute_proposal +//! -> auto-disbursed if the reserve covers it, otherwise stays `Pending` +//! and anyone can retry `disburse_grant` once the reserve has grown. +//! +//! Entry points live in `lib.rs`; this module owns storage, accounting and +//! token movement. + +use soroban_sdk::{contractevent, contracttype, token, Address, Env, String}; + +use crate::DaoError; + +/// 1% of every gross protocol amount routed through `collect_fee`. +pub const SUSTAINABILITY_FEE_BPS: u32 = 100; +pub const BPS_DENOMINATOR: i128 = 10_000; + +#[derive(Clone, Debug, Eq, PartialEq)] +#[contracttype] +pub enum SustainabilityKey { + Token, + Reserve, + Collected, + Disbursed, + GrantsProposed, + GrantsDisbursed, + MaintainersFunded, + Grant(u64), // proposal_id -> MaintainerGrant + MaintainerTotal(Address), // maintainer -> lifetime amount received +} + +#[derive(Clone, Debug, Eq, PartialEq)] +#[contracttype] +pub enum GrantStatus { + Pending, + Disbursed, +} + +#[derive(Clone, Debug, Eq, PartialEq)] +#[contracttype] +pub struct MaintainerGrant { + pub proposal_id: u64, + pub maintainer: Address, + /// Dependency identifier, e.g. "npm:@stellar/stellar-sdk" or "cargo:soroban-sdk". + pub package: String, + pub amount: i128, + pub status: GrantStatus, + pub disbursed_at: u64, +} + +#[derive(Clone, Debug, Eq, PartialEq)] +#[contracttype] +pub struct SustainabilityStats { + pub token: Option
, + pub fee_bps: u32, + pub reserve: i128, + pub total_collected: i128, + pub total_disbursed: i128, + pub grants_proposed: u32, + pub grants_disbursed: u32, + pub maintainers_funded: u32, +} + +#[contractevent(topics = ["sus_fee"], data_format = "map")] +pub struct FeeCollectedEvent<'a> { + #[topic] + pub payer: &'a Address, + pub gross_amount: &'a i128, + pub fee: &'a i128, +} + +#[contractevent(topics = ["sus_grant"], data_format = "map")] +pub struct GrantDisbursedEvent<'a> { + #[topic] + pub proposal_id: &'a u64, + pub maintainer: &'a Address, + pub package: &'a String, + pub amount: &'a i128, +} + +fn get_i128(env: &Env, key: &SustainabilityKey) -> i128 { + env.storage().instance().get(key).unwrap_or(0) +} + +fn get_u32(env: &Env, key: &SustainabilityKey) -> u32 { + env.storage().instance().get(key).unwrap_or(0) +} + +fn token_client(env: &Env) -> Result, DaoError> { + let addr: Address = env + .storage() + .instance() + .get(&SustainabilityKey::Token) + .ok_or(DaoError::SustainabilityNotConfigured)?; + Ok(token::Client::new(env, &addr)) +} + +pub fn is_configured(env: &Env) -> bool { + env.storage().instance().has(&SustainabilityKey::Token) +} + +pub fn set_token(env: &Env, token: &Address) { + env.storage().instance().set(&SustainabilityKey::Token, token); +} + +/// Fee owed on `gross_amount` (rounds down; dust amounts pay nothing). +pub fn fee_for(gross_amount: i128) -> i128 { + gross_amount * SUSTAINABILITY_FEE_BPS as i128 / BPS_DENOMINATOR +} + +/// Pull the 1% sustainability fee on `gross_amount` from `payer` into the +/// reserve. Caller must have already required `payer`'s auth. +pub fn collect_fee(env: &Env, payer: &Address, gross_amount: i128) -> Result { + if gross_amount <= 0 { + return Err(DaoError::InvalidAmount); + } + let token = token_client(env)?; + let fee = fee_for(gross_amount); + if fee == 0 { + return Ok(0); + } + token.transfer(payer, &env.current_contract_address(), &fee); + + let s = env.storage().instance(); + s.set(&SustainabilityKey::Reserve, &(get_i128(env, &SustainabilityKey::Reserve) + fee)); + s.set(&SustainabilityKey::Collected, &(get_i128(env, &SustainabilityKey::Collected) + fee)); + + FeeCollectedEvent { payer, gross_amount: &gross_amount, fee: &fee }.publish(env); + Ok(fee) +} + +/// Attach a grant request to a freshly created `FundAllocation` proposal. +pub fn record_grant( + env: &Env, + proposal_id: u64, + maintainer: Address, + package: String, + amount: i128, +) -> Result<(), DaoError> { + if amount <= 0 { + return Err(DaoError::InvalidAmount); + } + if !is_configured(env) { + return Err(DaoError::SustainabilityNotConfigured); + } + let grant = MaintainerGrant { + proposal_id, + maintainer, + package, + amount, + status: GrantStatus::Pending, + disbursed_at: 0, + }; + env.storage().persistent().set(&SustainabilityKey::Grant(proposal_id), &grant); + env.storage().instance().set( + &SustainabilityKey::GrantsProposed, + &(get_u32(env, &SustainabilityKey::GrantsProposed) + 1), + ); + Ok(()) +} + +pub fn get_grant(env: &Env, proposal_id: u64) -> Option { + env.storage().persistent().get(&SustainabilityKey::Grant(proposal_id)) +} + +/// Pay out a grant from the reserve. The caller is responsible for checking +/// that the backing proposal has been executed. +pub fn disburse(env: &Env, proposal_id: u64) -> Result { + let mut grant = get_grant(env, proposal_id).ok_or(DaoError::GrantNotFound)?; + if grant.status == GrantStatus::Disbursed { + return Err(DaoError::GrantAlreadyDisbursed); + } + let reserve = get_i128(env, &SustainabilityKey::Reserve); + if grant.amount > reserve { + return Err(DaoError::InsufficientReserve); + } + + token_client(env)?.transfer(&env.current_contract_address(), &grant.maintainer, &grant.amount); + + grant.status = GrantStatus::Disbursed; + grant.disbursed_at = env.ledger().timestamp(); + env.storage().persistent().set(&SustainabilityKey::Grant(proposal_id), &grant); + + let total_key = SustainabilityKey::MaintainerTotal(grant.maintainer.clone()); + let prior: i128 = env.storage().persistent().get(&total_key).unwrap_or(0); + env.storage().persistent().set(&total_key, &(prior + grant.amount)); + + let s = env.storage().instance(); + s.set(&SustainabilityKey::Reserve, &(reserve - grant.amount)); + s.set(&SustainabilityKey::Disbursed, &(get_i128(env, &SustainabilityKey::Disbursed) + grant.amount)); + s.set(&SustainabilityKey::GrantsDisbursed, &(get_u32(env, &SustainabilityKey::GrantsDisbursed) + 1)); + if prior == 0 { + s.set(&SustainabilityKey::MaintainersFunded, &(get_u32(env, &SustainabilityKey::MaintainersFunded) + 1)); + } + + GrantDisbursedEvent { + proposal_id: &proposal_id, + maintainer: &grant.maintainer, + package: &grant.package, + amount: &grant.amount, + } + .publish(env); + Ok(grant.amount) +} + +pub fn maintainer_total(env: &Env, maintainer: Address) -> i128 { + env.storage().persistent().get(&SustainabilityKey::MaintainerTotal(maintainer)).unwrap_or(0) +} + +pub fn stats(env: &Env) -> SustainabilityStats { + SustainabilityStats { + token: env.storage().instance().get(&SustainabilityKey::Token), + fee_bps: SUSTAINABILITY_FEE_BPS, + reserve: get_i128(env, &SustainabilityKey::Reserve), + total_collected: get_i128(env, &SustainabilityKey::Collected), + total_disbursed: get_i128(env, &SustainabilityKey::Disbursed), + grants_proposed: get_u32(env, &SustainabilityKey::GrantsProposed), + grants_disbursed: get_u32(env, &SustainabilityKey::GrantsDisbursed), + maintainers_funded: get_u32(env, &SustainabilityKey::MaintainersFunded), + } +} diff --git a/contracts/helphone_dao/src/test.rs b/contracts/helphone_dao/src/test.rs index 20f9e68a..fe8efc4e 100644 --- a/contracts/helphone_dao/src/test.rs +++ b/contracts/helphone_dao/src/test.rs @@ -1,19 +1,55 @@ #![cfg(test)] use super::*; -use soroban_sdk::{testutils::Address as _, Address, Env, String, Vec as SorobanVec}; +use soroban_sdk::{ + testutils::{Address as _, Ledger}, + token::{self, StellarAssetClient}, + Address, Env, String, Vec as SorobanVec, +}; const T0: u64 = 1_000_000; -// ── Mocks ────────────────────────────────────────────────────────── -/// SEP-40 style oracle whose prices are set directly by the tests. -#[contract] -struct MockOracle; +struct Setup<'a> { + dao: HelPhoneDaoClient<'a>, + admin: Address, + gov: token::Client<'a>, + reserve: token::Client<'a>, +} + +fn setup(env: &Env) -> Setup<'_> { + env.mock_all_auths(); + let admin = Address::generate(env); + let gov = env.register_stellar_asset_contract_v2(admin.clone()).address(); + let reserve = env.register_stellar_asset_contract_v2(admin.clone()).address(); + let id = env.register(HelPhoneDao, (admin.clone(), gov.clone())); + Setup { + dao: HelPhoneDaoClient::new(env, &id), + admin, + gov: token::Client::new(env, &gov), + reserve: token::Client::new(env, &reserve), + } +} + +fn mint(env: &Env, token: &token::Client, to: &Address, amount: i128) { + StellarAssetClient::new(env, &token.address).mint(to, &amount); +} + +fn s(env: &Env, v: &str) -> String { + String::from_str(env, v) +} + +/// Voter holding the whole voting supply, so any For vote passes quorum. +fn voter(env: &Env, t: &Setup) -> Address { + let v = Address::generate(env); + mint(env, &t.gov, &v, 1_000); + t.dao.set_voting_supply(&t.admin, &1_000); + v +} -#[contracttype] -enum OracleKey { - Price(OracleAsset), +fn pass_timelock(env: &Env) { + let now = env.ledger().timestamp(); + env.ledger().set_timestamp(now + VOTING_PERIOD_SECS + EXECUTION_DELAY_SECS + 1); } #[contractimpl] @@ -74,6 +110,22 @@ fn sac(env: &Env) -> Address { #[test] fn constructor_sets_admin_and_token() { + let env = Env::default(); + let t = setup(&env); + assert_eq!(t.dao.get_admin(), Some(t.admin.clone())); + assert_eq!(t.dao.get_governance_token(), Some(t.gov.address.clone())); + assert_eq!(t.dao.get_proposal_count(), 0); +} + +#[test] +fn governance_params_are_correct() { + let env = Env::default(); + let t = setup(&env); + let (voting_period, execution_delay, quorum, pass_threshold) = t.dao.get_governance_params(); +} + +#[test] +fn reads_initial_config_ctx() { let c = ctx(); assert_eq!(c.dao.get_admin(), Some(c.admin.clone())); assert_eq!(c.dao.get_governance_token(), Some(c.gov.clone())); @@ -252,7 +304,133 @@ fn quote_requires_an_oracle() { } #[test] -fn proposal_status_values() { +fn collects_one_percent_into_reserve() { + let env = Env::default(); + let t = setup(&env); + t.dao.configure_sustainability(&t.admin, &t.reserve.address); + let payer = Address::generate(&env); + mint(&env, &t.reserve, &payer, 1_000_000); + + assert_eq!(t.dao.collect_sustainability_fee(&payer, &250_000), 2_500); + assert_eq!(t.dao.collect_sustainability_fee(&payer, &99), 0); // below 1 unit of fee + assert_eq!(t.reserve.balance(&t.dao.address), 2_500); + assert_eq!(t.reserve.balance(&payer), 997_500); + + let st = t.dao.get_sustainability_stats(); + assert_eq!(st.fee_bps, 100); + assert_eq!((st.reserve, st.total_collected, st.total_disbursed), (2_500, 2_500, 0)); + assert_eq!(st.token, Some(t.reserve.address.clone())); +} + +#[test] +fn passed_grant_is_disbursed_on_execution() { + let env = Env::default(); + let t = setup(&env); + t.dao.configure_sustainability(&t.admin, &t.reserve.address); + let payer = Address::generate(&env); + mint(&env, &t.reserve, &payer, 10_000_000); + t.dao.collect_sustainability_fee(&payer, &10_000_000); // reserve = 100_000 + + let v = voter(&env, &t); + let maintainer = Address::generate(&env); + let pid = t.dao.propose_maintainer_grant( + &v, + &maintainer, + &s(&env, "npm:@stellar/stellar-sdk"), + &40_000, + &s(&env, "Fund stellar-sdk"), + &s(&env, "Critical dependency with a single maintainer"), + ); + assert_eq!(t.dao.get_proposal(&pid).unwrap().proposal_type, ProposalType::FundAllocation); + + t.dao.cast_vote(&v, &pid, &VoteDirection::For); + pass_timelock(&env); + t.dao.execute_proposal(&pid); + + assert_eq!(t.reserve.balance(&maintainer), 40_000); + let grant = t.dao.get_maintainer_grant(&pid).unwrap(); + assert_eq!(grant.status, sustainability::GrantStatus::Disbursed); + assert_eq!(t.dao.get_maintainer_funding(&maintainer), 40_000); + + let st = t.dao.get_sustainability_stats(); + assert_eq!((st.reserve, st.total_disbursed), (60_000, 40_000)); + assert_eq!((st.grants_proposed, st.grants_disbursed, st.maintainers_funded), (1, 1, 1)); + assert_eq!(t.dao.try_disburse_grant(&pid), Err(Ok(DaoError::GrantAlreadyDisbursed))); +} + +#[test] +fn underfunded_grant_stays_pending_until_reserve_grows() { + let env = Env::default(); + let t = setup(&env); + t.dao.configure_sustainability(&t.admin, &t.reserve.address); + let payer = Address::generate(&env); + mint(&env, &t.reserve, &payer, 10_000_000); + + let v = voter(&env, &t); + let maintainer = Address::generate(&env); + let pid = t.dao.propose_maintainer_grant( + &v, &maintainer, &s(&env, "cargo:soroban-sdk"), &5_000, &s(&env, "t"), &s(&env, "d"), + ); + t.dao.cast_vote(&v, &pid, &VoteDirection::For); + pass_timelock(&env); + t.dao.execute_proposal(&pid); // reserve is empty: execution still succeeds + + assert_eq!(t.dao.get_proposal(&pid).unwrap().status, ProposalStatus::Executed); + assert_eq!(t.dao.get_maintainer_grant(&pid).unwrap().status, sustainability::GrantStatus::Pending); + assert_eq!(t.dao.try_disburse_grant(&pid), Err(Ok(DaoError::InsufficientReserve))); + + t.dao.collect_sustainability_fee(&payer, &500_000); // reserve = 5_000 + assert_eq!(t.dao.disburse_grant(&pid), 5_000); + assert_eq!(t.reserve.balance(&maintainer), 5_000); +} + +#[test] +fn rejected_grant_cannot_be_disbursed() { + let env = Env::default(); + let t = setup(&env); + t.dao.configure_sustainability(&t.admin, &t.reserve.address); + let v = voter(&env, &t); + let pid = t.dao.propose_maintainer_grant( + &v, &Address::generate(&env), &s(&env, "npm:x"), &1, &s(&env, "t"), &s(&env, "d"), + ); + t.dao.cast_vote(&v, &pid, &VoteDirection::Against); + pass_timelock(&env); + + assert_eq!(t.dao.try_execute_proposal(&pid), Err(Ok(DaoError::NotPassed))); + assert_eq!(t.dao.try_disburse_grant(&pid), Err(Ok(DaoError::NotPassed))); +} + +#[test] +fn rejects_bad_sustainability_inputs() { + let env = Env::default(); + let t = setup(&env); + let payer = Address::generate(&env); + let who = Address::generate(&env); + + assert_eq!( + t.dao.try_collect_sustainability_fee(&payer, &1_000), + Err(Ok(DaoError::SustainabilityNotConfigured)) + ); + assert_eq!( + t.dao.try_propose_maintainer_grant(&who, &who, &s(&env, "p"), &1, &s(&env, "t"), &s(&env, "d")), + Err(Ok(DaoError::SustainabilityNotConfigured)) + ); + assert_eq!( + t.dao.try_configure_sustainability(&who, &t.reserve.address), + Err(Ok(DaoError::NotAdmin)) + ); + + t.dao.configure_sustainability(&t.admin, &t.reserve.address); + assert_eq!(t.dao.try_collect_sustainability_fee(&payer, &0), Err(Ok(DaoError::InvalidAmount))); + assert_eq!( + t.dao.try_propose_maintainer_grant(&who, &who, &s(&env, "p"), &0, &s(&env, "t"), &s(&env, "d")), + Err(Ok(DaoError::InvalidAmount)) + ); + assert_eq!(t.dao.try_disburse_grant(&42), Err(Ok(DaoError::ProposalNotFound))); +} + +#[test] +fn fn proposal_status_values() { assert_eq!(ProposalStatus::Active, ProposalStatus::Active); assert_eq!(ProposalStatus::Passed, ProposalStatus::Passed); assert_eq!(ProposalStatus::Failed, ProposalStatus::Failed); diff --git a/contracts/helphone_dao/test_snapshots/test/collects_one_percent_into_reserve.1.json b/contracts/helphone_dao/test_snapshots/test/collects_one_percent_into_reserve.1.json new file mode 100644 index 00000000..57735ec6 --- /dev/null +++ b/contracts/helphone_dao/test_snapshots/test/collects_one_percent_into_reserve.1.json @@ -0,0 +1,745 @@ +{ + "generators": { + "address": 5, + "nonce": 0, + "mux_id": 0 + }, + "auth": [ + [], + [ + [ + "GAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAEGWF", + { + "function": { + "contract_fn": { + "contract_address": "CBEPDNVYXQGWB5YUBXKJWYJA7OXTZW5LFLNO5JRRGE6Z6C5OSUZPCCEL", + "function_name": "set_admin", + "args": [ + { + "address": "CAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAD2KM" + } + ] + } + }, + "sub_invocations": [] + } + ] + ], + [], + [ + [ + "GAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAGO6V", + { + "function": { + "contract_fn": { + "contract_address": "CBUSYNQKASUYFWYC3M2GUEDMX4AIVWPALDBYJPNK6554BREHTGZ2IUNF", + "function_name": "set_admin", + "args": [ + { + "address": "CAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAD2KM" + } + ] + } + }, + "sub_invocations": [] + } + ] + ], + [], + [ + [ + "CAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAD2KM", + { + "function": { + "contract_fn": { + "contract_address": "CAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAITA4", + "function_name": "configure_sustainability", + "args": [ + { + "address": "CAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAD2KM" + }, + { + "address": "CBUSYNQKASUYFWYC3M2GUEDMX4AIVWPALDBYJPNK6554BREHTGZ2IUNF" + } + ] + } + }, + "sub_invocations": [] + } + ] + ], + [ + [ + "CAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAD2KM", + { + "function": { + "contract_fn": { + "contract_address": "CBUSYNQKASUYFWYC3M2GUEDMX4AIVWPALDBYJPNK6554BREHTGZ2IUNF", + "function_name": "mint", + "args": [ + { + "address": "CAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAK3IM" + }, + { + "i128": "1000000" + } + ] + } + }, + "sub_invocations": [] + } + ] + ], + [ + [ + "CAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAK3IM", + { + "function": { + "contract_fn": { + "contract_address": "CAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAITA4", + "function_name": "collect_sustainability_fee", + "args": [ + { + "address": "CAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAK3IM" + }, + { + "i128": "250000" + } + ] + } + }, + "sub_invocations": [ + { + "function": { + "contract_fn": { + "contract_address": "CBUSYNQKASUYFWYC3M2GUEDMX4AIVWPALDBYJPNK6554BREHTGZ2IUNF", + "function_name": "transfer", + "args": [ + { + "address": "CAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAK3IM" + }, + { + "address": "CAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAITA4" + }, + { + "i128": "2500" + } + ] + } + }, + "sub_invocations": [] + } + ] + } + ] + ], + [ + [ + "CAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAK3IM", + { + "function": { + "contract_fn": { + "contract_address": "CAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAITA4", + "function_name": "collect_sustainability_fee", + "args": [ + { + "address": "CAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAK3IM" + }, + { + "i128": "99" + } + ] + } + }, + "sub_invocations": [] + } + ] + ], + [], + [], + [] + ], + "ledger": { + "protocol_version": 26, + "sequence_number": 0, + "timestamp": 0, + "network_id": "0000000000000000000000000000000000000000000000000000000000000000", + "base_reserve": 0, + "min_persistent_entry_ttl": 4096, + "min_temp_entry_ttl": 16, + "max_entry_ttl": 6312000, + "ledger_entries": [ + { + "entry": { + "last_modified_ledger_seq": 0, + "data": { + "account": { + "account_id": "GAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAEGWF", + "balance": "0", + "seq_num": "0", + "num_sub_entries": 0, + "inflation_dest": null, + "flags": 0, + "home_domain": "", + "thresholds": "01010101", + "signers": [], + "ext": "v0" + } + }, + "ext": "v0" + }, + "live_until": null + }, + { + "entry": { + "last_modified_ledger_seq": 0, + "data": { + "account": { + "account_id": "GAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAGO6V", + "balance": "0", + "seq_num": "0", + "num_sub_entries": 0, + "inflation_dest": null, + "flags": 0, + "home_domain": "", + "thresholds": "01010101", + "signers": [], + "ext": "v0" + } + }, + "ext": "v0" + }, + "live_until": null + }, + { + "entry": { + "last_modified_ledger_seq": 0, + "data": { + "contract_data": { + "ext": "v0", + "contract": "GAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAEGWF", + "key": { + "ledger_key_nonce": { + "nonce": "801925984706572462" + } + }, + "durability": "temporary", + "val": "void" + } + }, + "ext": "v0" + }, + "live_until": 6311999 + }, + { + "entry": { + "last_modified_ledger_seq": 0, + "data": { + "contract_data": { + "ext": "v0", + "contract": "GAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAGO6V", + "key": { + "ledger_key_nonce": { + "nonce": "5541220902715666415" + } + }, + "durability": "temporary", + "val": "void" + } + }, + "ext": "v0" + }, + "live_until": 6311999 + }, + { + "entry": { + "last_modified_ledger_seq": 0, + "data": { + "contract_data": { + "ext": "v0", + "contract": "CAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAD2KM", + "key": { + "ledger_key_nonce": { + "nonce": "1033654523790656264" + } + }, + "durability": "temporary", + "val": "void" + } + }, + "ext": "v0" + }, + "live_until": 6311999 + }, + { + "entry": { + "last_modified_ledger_seq": 0, + "data": { + "contract_data": { + "ext": "v0", + "contract": "CAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAD2KM", + "key": { + "ledger_key_nonce": { + "nonce": "4837995959683129791" + } + }, + "durability": "temporary", + "val": "void" + } + }, + "ext": "v0" + }, + "live_until": 6311999 + }, + { + "entry": { + "last_modified_ledger_seq": 0, + "data": { + "contract_data": { + "ext": "v0", + "contract": "CAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAITA4", + "key": "ledger_key_contract_instance", + "durability": "persistent", + "val": { + "contract_instance": { + "executable": { + "wasm": "e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855" + }, + "storage": [ + { + "key": { + "symbol": "admin" + }, + "val": { + "address": "CAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAD2KM" + } + }, + { + "key": { + "symbol": "pcount" + }, + "val": { + "u64": "0" + } + }, + { + "key": { + "symbol": "token" + }, + "val": { + "address": "CBEPDNVYXQGWB5YUBXKJWYJA7OXTZW5LFLNO5JRRGE6Z6C5OSUZPCCEL" + } + }, + { + "key": { + "vec": [ + { + "symbol": "Collected" + } + ] + }, + "val": { + "i128": "2500" + } + }, + { + "key": { + "vec": [ + { + "symbol": "Reserve" + } + ] + }, + "val": { + "i128": "2500" + } + }, + { + "key": { + "vec": [ + { + "symbol": "Token" + } + ] + }, + "val": { + "address": "CBUSYNQKASUYFWYC3M2GUEDMX4AIVWPALDBYJPNK6554BREHTGZ2IUNF" + } + } + ] + } + } + } + }, + "ext": "v0" + }, + "live_until": 4095 + }, + { + "entry": { + "last_modified_ledger_seq": 0, + "data": { + "contract_data": { + "ext": "v0", + "contract": "CAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAK3IM", + "key": { + "ledger_key_nonce": { + "nonce": "2032731177588607455" + } + }, + "durability": "temporary", + "val": "void" + } + }, + "ext": "v0" + }, + "live_until": 6311999 + }, + { + "entry": { + "last_modified_ledger_seq": 0, + "data": { + "contract_data": { + "ext": "v0", + "contract": "CAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAK3IM", + "key": { + "ledger_key_nonce": { + "nonce": "4270020994084947596" + } + }, + "durability": "temporary", + "val": "void" + } + }, + "ext": "v0" + }, + "live_until": 6311999 + }, + { + "entry": { + "last_modified_ledger_seq": 0, + "data": { + "contract_data": { + "ext": "v0", + "contract": "CBEPDNVYXQGWB5YUBXKJWYJA7OXTZW5LFLNO5JRRGE6Z6C5OSUZPCCEL", + "key": "ledger_key_contract_instance", + "durability": "persistent", + "val": { + "contract_instance": { + "executable": "stellar_asset", + "storage": [ + { + "key": { + "symbol": "METADATA" + }, + "val": { + "map": [ + { + "key": { + "symbol": "decimal" + }, + "val": { + "u32": 7 + } + }, + { + "key": { + "symbol": "name" + }, + "val": { + "string": "aaa:GAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAEGWF" + } + }, + { + "key": { + "symbol": "symbol" + }, + "val": { + "string": "aaa" + } + } + ] + } + }, + { + "key": { + "vec": [ + { + "symbol": "Admin" + } + ] + }, + "val": { + "address": "CAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAD2KM" + } + }, + { + "key": { + "vec": [ + { + "symbol": "AssetInfo" + } + ] + }, + "val": { + "vec": [ + { + "symbol": "AlphaNum4" + }, + { + "map": [ + { + "key": { + "symbol": "asset_code" + }, + "val": { + "string": "aaa\\0" + } + }, + { + "key": { + "symbol": "issuer" + }, + "val": { + "bytes": "0000000000000000000000000000000000000000000000000000000000000002" + } + } + ] + } + ] + } + } + ] + } + } + } + }, + "ext": "v0" + }, + "live_until": 120960 + }, + { + "entry": { + "last_modified_ledger_seq": 0, + "data": { + "contract_data": { + "ext": "v0", + "contract": "CBUSYNQKASUYFWYC3M2GUEDMX4AIVWPALDBYJPNK6554BREHTGZ2IUNF", + "key": { + "vec": [ + { + "symbol": "Balance" + }, + { + "address": "CAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAITA4" + } + ] + }, + "durability": "persistent", + "val": { + "map": [ + { + "key": { + "symbol": "amount" + }, + "val": { + "i128": "2500" + } + }, + { + "key": { + "symbol": "authorized" + }, + "val": { + "bool": true + } + }, + { + "key": { + "symbol": "clawback" + }, + "val": { + "bool": false + } + } + ] + } + } + }, + "ext": "v0" + }, + "live_until": 518400 + }, + { + "entry": { + "last_modified_ledger_seq": 0, + "data": { + "contract_data": { + "ext": "v0", + "contract": "CBUSYNQKASUYFWYC3M2GUEDMX4AIVWPALDBYJPNK6554BREHTGZ2IUNF", + "key": { + "vec": [ + { + "symbol": "Balance" + }, + { + "address": "CAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAK3IM" + } + ] + }, + "durability": "persistent", + "val": { + "map": [ + { + "key": { + "symbol": "amount" + }, + "val": { + "i128": "997500" + } + }, + { + "key": { + "symbol": "authorized" + }, + "val": { + "bool": true + } + }, + { + "key": { + "symbol": "clawback" + }, + "val": { + "bool": false + } + } + ] + } + } + }, + "ext": "v0" + }, + "live_until": 518400 + }, + { + "entry": { + "last_modified_ledger_seq": 0, + "data": { + "contract_data": { + "ext": "v0", + "contract": "CBUSYNQKASUYFWYC3M2GUEDMX4AIVWPALDBYJPNK6554BREHTGZ2IUNF", + "key": "ledger_key_contract_instance", + "durability": "persistent", + "val": { + "contract_instance": { + "executable": "stellar_asset", + "storage": [ + { + "key": { + "symbol": "METADATA" + }, + "val": { + "map": [ + { + "key": { + "symbol": "decimal" + }, + "val": { + "u32": 7 + } + }, + { + "key": { + "symbol": "name" + }, + "val": { + "string": "aaa:GAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAGO6V" + } + }, + { + "key": { + "symbol": "symbol" + }, + "val": { + "string": "aaa" + } + } + ] + } + }, + { + "key": { + "vec": [ + { + "symbol": "Admin" + } + ] + }, + "val": { + "address": "CAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAD2KM" + } + }, + { + "key": { + "vec": [ + { + "symbol": "AssetInfo" + } + ] + }, + "val": { + "vec": [ + { + "symbol": "AlphaNum4" + }, + { + "map": [ + { + "key": { + "symbol": "asset_code" + }, + "val": { + "string": "aaa\\0" + } + }, + { + "key": { + "symbol": "issuer" + }, + "val": { + "bytes": "0000000000000000000000000000000000000000000000000000000000000003" + } + } + ] + } + ] + } + } + ] + } + } + } + }, + "ext": "v0" + }, + "live_until": 120960 + }, + { + "entry": { + "last_modified_ledger_seq": 0, + "data": { + "contract_code": { + "ext": "v0", + "hash": "e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855", + "code": "" + } + }, + "ext": "v0" + }, + "live_until": 4095 + } + ] + }, + "events": [] +} \ No newline at end of file diff --git a/contracts/helphone_dao/test_snapshots/test/constructor_sets_admin_and_token.1.json b/contracts/helphone_dao/test_snapshots/test/constructor_sets_admin_and_token.1.json new file mode 100644 index 00000000..35fb67ea --- /dev/null +++ b/contracts/helphone_dao/test_snapshots/test/constructor_sets_admin_and_token.1.json @@ -0,0 +1,416 @@ +{ + "generators": { + "address": 4, + "nonce": 0, + "mux_id": 0 + }, + "auth": [ + [], + [ + [ + "GAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAEGWF", + { + "function": { + "contract_fn": { + "contract_address": "CBEPDNVYXQGWB5YUBXKJWYJA7OXTZW5LFLNO5JRRGE6Z6C5OSUZPCCEL", + "function_name": "set_admin", + "args": [ + { + "address": "CAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAD2KM" + } + ] + } + }, + "sub_invocations": [] + } + ] + ], + [], + [ + [ + "GAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAGO6V", + { + "function": { + "contract_fn": { + "contract_address": "CBUSYNQKASUYFWYC3M2GUEDMX4AIVWPALDBYJPNK6554BREHTGZ2IUNF", + "function_name": "set_admin", + "args": [ + { + "address": "CAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAD2KM" + } + ] + } + }, + "sub_invocations": [] + } + ] + ], + [], + [], + [], + [] + ], + "ledger": { + "protocol_version": 26, + "sequence_number": 0, + "timestamp": 0, + "network_id": "0000000000000000000000000000000000000000000000000000000000000000", + "base_reserve": 0, + "min_persistent_entry_ttl": 4096, + "min_temp_entry_ttl": 16, + "max_entry_ttl": 6312000, + "ledger_entries": [ + { + "entry": { + "last_modified_ledger_seq": 0, + "data": { + "account": { + "account_id": "GAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAEGWF", + "balance": "0", + "seq_num": "0", + "num_sub_entries": 0, + "inflation_dest": null, + "flags": 0, + "home_domain": "", + "thresholds": "01010101", + "signers": [], + "ext": "v0" + } + }, + "ext": "v0" + }, + "live_until": null + }, + { + "entry": { + "last_modified_ledger_seq": 0, + "data": { + "account": { + "account_id": "GAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAGO6V", + "balance": "0", + "seq_num": "0", + "num_sub_entries": 0, + "inflation_dest": null, + "flags": 0, + "home_domain": "", + "thresholds": "01010101", + "signers": [], + "ext": "v0" + } + }, + "ext": "v0" + }, + "live_until": null + }, + { + "entry": { + "last_modified_ledger_seq": 0, + "data": { + "contract_data": { + "ext": "v0", + "contract": "GAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAEGWF", + "key": { + "ledger_key_nonce": { + "nonce": "801925984706572462" + } + }, + "durability": "temporary", + "val": "void" + } + }, + "ext": "v0" + }, + "live_until": 6311999 + }, + { + "entry": { + "last_modified_ledger_seq": 0, + "data": { + "contract_data": { + "ext": "v0", + "contract": "GAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAGO6V", + "key": { + "ledger_key_nonce": { + "nonce": "5541220902715666415" + } + }, + "durability": "temporary", + "val": "void" + } + }, + "ext": "v0" + }, + "live_until": 6311999 + }, + { + "entry": { + "last_modified_ledger_seq": 0, + "data": { + "contract_data": { + "ext": "v0", + "contract": "CAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAITA4", + "key": "ledger_key_contract_instance", + "durability": "persistent", + "val": { + "contract_instance": { + "executable": { + "wasm": "e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855" + }, + "storage": [ + { + "key": { + "symbol": "admin" + }, + "val": { + "address": "CAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAD2KM" + } + }, + { + "key": { + "symbol": "pcount" + }, + "val": { + "u64": "0" + } + }, + { + "key": { + "symbol": "token" + }, + "val": { + "address": "CBEPDNVYXQGWB5YUBXKJWYJA7OXTZW5LFLNO5JRRGE6Z6C5OSUZPCCEL" + } + } + ] + } + } + } + }, + "ext": "v0" + }, + "live_until": 4095 + }, + { + "entry": { + "last_modified_ledger_seq": 0, + "data": { + "contract_data": { + "ext": "v0", + "contract": "CBEPDNVYXQGWB5YUBXKJWYJA7OXTZW5LFLNO5JRRGE6Z6C5OSUZPCCEL", + "key": "ledger_key_contract_instance", + "durability": "persistent", + "val": { + "contract_instance": { + "executable": "stellar_asset", + "storage": [ + { + "key": { + "symbol": "METADATA" + }, + "val": { + "map": [ + { + "key": { + "symbol": "decimal" + }, + "val": { + "u32": 7 + } + }, + { + "key": { + "symbol": "name" + }, + "val": { + "string": "aaa:GAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAEGWF" + } + }, + { + "key": { + "symbol": "symbol" + }, + "val": { + "string": "aaa" + } + } + ] + } + }, + { + "key": { + "vec": [ + { + "symbol": "Admin" + } + ] + }, + "val": { + "address": "CAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAD2KM" + } + }, + { + "key": { + "vec": [ + { + "symbol": "AssetInfo" + } + ] + }, + "val": { + "vec": [ + { + "symbol": "AlphaNum4" + }, + { + "map": [ + { + "key": { + "symbol": "asset_code" + }, + "val": { + "string": "aaa\\0" + } + }, + { + "key": { + "symbol": "issuer" + }, + "val": { + "bytes": "0000000000000000000000000000000000000000000000000000000000000002" + } + } + ] + } + ] + } + } + ] + } + } + } + }, + "ext": "v0" + }, + "live_until": 120960 + }, + { + "entry": { + "last_modified_ledger_seq": 0, + "data": { + "contract_data": { + "ext": "v0", + "contract": "CBUSYNQKASUYFWYC3M2GUEDMX4AIVWPALDBYJPNK6554BREHTGZ2IUNF", + "key": "ledger_key_contract_instance", + "durability": "persistent", + "val": { + "contract_instance": { + "executable": "stellar_asset", + "storage": [ + { + "key": { + "symbol": "METADATA" + }, + "val": { + "map": [ + { + "key": { + "symbol": "decimal" + }, + "val": { + "u32": 7 + } + }, + { + "key": { + "symbol": "name" + }, + "val": { + "string": "aaa:GAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAGO6V" + } + }, + { + "key": { + "symbol": "symbol" + }, + "val": { + "string": "aaa" + } + } + ] + } + }, + { + "key": { + "vec": [ + { + "symbol": "Admin" + } + ] + }, + "val": { + "address": "CAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAD2KM" + } + }, + { + "key": { + "vec": [ + { + "symbol": "AssetInfo" + } + ] + }, + "val": { + "vec": [ + { + "symbol": "AlphaNum4" + }, + { + "map": [ + { + "key": { + "symbol": "asset_code" + }, + "val": { + "string": "aaa\\0" + } + }, + { + "key": { + "symbol": "issuer" + }, + "val": { + "bytes": "0000000000000000000000000000000000000000000000000000000000000003" + } + } + ] + } + ] + } + } + ] + } + } + } + }, + "ext": "v0" + }, + "live_until": 120960 + }, + { + "entry": { + "last_modified_ledger_seq": 0, + "data": { + "contract_code": { + "ext": "v0", + "hash": "e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855", + "code": "" + } + }, + "ext": "v0" + }, + "live_until": 4095 + } + ] + }, + "events": [] +} \ No newline at end of file diff --git a/contracts/helphone_dao/test_snapshots/test/governance_params_are_correct.1.json b/contracts/helphone_dao/test_snapshots/test/governance_params_are_correct.1.json new file mode 100644 index 00000000..e08bf586 --- /dev/null +++ b/contracts/helphone_dao/test_snapshots/test/governance_params_are_correct.1.json @@ -0,0 +1,414 @@ +{ + "generators": { + "address": 4, + "nonce": 0, + "mux_id": 0 + }, + "auth": [ + [], + [ + [ + "GAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAEGWF", + { + "function": { + "contract_fn": { + "contract_address": "CBEPDNVYXQGWB5YUBXKJWYJA7OXTZW5LFLNO5JRRGE6Z6C5OSUZPCCEL", + "function_name": "set_admin", + "args": [ + { + "address": "CAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAD2KM" + } + ] + } + }, + "sub_invocations": [] + } + ] + ], + [], + [ + [ + "GAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAGO6V", + { + "function": { + "contract_fn": { + "contract_address": "CBUSYNQKASUYFWYC3M2GUEDMX4AIVWPALDBYJPNK6554BREHTGZ2IUNF", + "function_name": "set_admin", + "args": [ + { + "address": "CAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAD2KM" + } + ] + } + }, + "sub_invocations": [] + } + ] + ], + [], + [] + ], + "ledger": { + "protocol_version": 26, + "sequence_number": 0, + "timestamp": 0, + "network_id": "0000000000000000000000000000000000000000000000000000000000000000", + "base_reserve": 0, + "min_persistent_entry_ttl": 4096, + "min_temp_entry_ttl": 16, + "max_entry_ttl": 6312000, + "ledger_entries": [ + { + "entry": { + "last_modified_ledger_seq": 0, + "data": { + "account": { + "account_id": "GAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAEGWF", + "balance": "0", + "seq_num": "0", + "num_sub_entries": 0, + "inflation_dest": null, + "flags": 0, + "home_domain": "", + "thresholds": "01010101", + "signers": [], + "ext": "v0" + } + }, + "ext": "v0" + }, + "live_until": null + }, + { + "entry": { + "last_modified_ledger_seq": 0, + "data": { + "account": { + "account_id": "GAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAGO6V", + "balance": "0", + "seq_num": "0", + "num_sub_entries": 0, + "inflation_dest": null, + "flags": 0, + "home_domain": "", + "thresholds": "01010101", + "signers": [], + "ext": "v0" + } + }, + "ext": "v0" + }, + "live_until": null + }, + { + "entry": { + "last_modified_ledger_seq": 0, + "data": { + "contract_data": { + "ext": "v0", + "contract": "GAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAEGWF", + "key": { + "ledger_key_nonce": { + "nonce": "801925984706572462" + } + }, + "durability": "temporary", + "val": "void" + } + }, + "ext": "v0" + }, + "live_until": 6311999 + }, + { + "entry": { + "last_modified_ledger_seq": 0, + "data": { + "contract_data": { + "ext": "v0", + "contract": "GAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAGO6V", + "key": { + "ledger_key_nonce": { + "nonce": "5541220902715666415" + } + }, + "durability": "temporary", + "val": "void" + } + }, + "ext": "v0" + }, + "live_until": 6311999 + }, + { + "entry": { + "last_modified_ledger_seq": 0, + "data": { + "contract_data": { + "ext": "v0", + "contract": "CAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAITA4", + "key": "ledger_key_contract_instance", + "durability": "persistent", + "val": { + "contract_instance": { + "executable": { + "wasm": "e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855" + }, + "storage": [ + { + "key": { + "symbol": "admin" + }, + "val": { + "address": "CAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAD2KM" + } + }, + { + "key": { + "symbol": "pcount" + }, + "val": { + "u64": "0" + } + }, + { + "key": { + "symbol": "token" + }, + "val": { + "address": "CBEPDNVYXQGWB5YUBXKJWYJA7OXTZW5LFLNO5JRRGE6Z6C5OSUZPCCEL" + } + } + ] + } + } + } + }, + "ext": "v0" + }, + "live_until": 4095 + }, + { + "entry": { + "last_modified_ledger_seq": 0, + "data": { + "contract_data": { + "ext": "v0", + "contract": "CBEPDNVYXQGWB5YUBXKJWYJA7OXTZW5LFLNO5JRRGE6Z6C5OSUZPCCEL", + "key": "ledger_key_contract_instance", + "durability": "persistent", + "val": { + "contract_instance": { + "executable": "stellar_asset", + "storage": [ + { + "key": { + "symbol": "METADATA" + }, + "val": { + "map": [ + { + "key": { + "symbol": "decimal" + }, + "val": { + "u32": 7 + } + }, + { + "key": { + "symbol": "name" + }, + "val": { + "string": "aaa:GAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAEGWF" + } + }, + { + "key": { + "symbol": "symbol" + }, + "val": { + "string": "aaa" + } + } + ] + } + }, + { + "key": { + "vec": [ + { + "symbol": "Admin" + } + ] + }, + "val": { + "address": "CAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAD2KM" + } + }, + { + "key": { + "vec": [ + { + "symbol": "AssetInfo" + } + ] + }, + "val": { + "vec": [ + { + "symbol": "AlphaNum4" + }, + { + "map": [ + { + "key": { + "symbol": "asset_code" + }, + "val": { + "string": "aaa\\0" + } + }, + { + "key": { + "symbol": "issuer" + }, + "val": { + "bytes": "0000000000000000000000000000000000000000000000000000000000000002" + } + } + ] + } + ] + } + } + ] + } + } + } + }, + "ext": "v0" + }, + "live_until": 120960 + }, + { + "entry": { + "last_modified_ledger_seq": 0, + "data": { + "contract_data": { + "ext": "v0", + "contract": "CBUSYNQKASUYFWYC3M2GUEDMX4AIVWPALDBYJPNK6554BREHTGZ2IUNF", + "key": "ledger_key_contract_instance", + "durability": "persistent", + "val": { + "contract_instance": { + "executable": "stellar_asset", + "storage": [ + { + "key": { + "symbol": "METADATA" + }, + "val": { + "map": [ + { + "key": { + "symbol": "decimal" + }, + "val": { + "u32": 7 + } + }, + { + "key": { + "symbol": "name" + }, + "val": { + "string": "aaa:GAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAGO6V" + } + }, + { + "key": { + "symbol": "symbol" + }, + "val": { + "string": "aaa" + } + } + ] + } + }, + { + "key": { + "vec": [ + { + "symbol": "Admin" + } + ] + }, + "val": { + "address": "CAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAD2KM" + } + }, + { + "key": { + "vec": [ + { + "symbol": "AssetInfo" + } + ] + }, + "val": { + "vec": [ + { + "symbol": "AlphaNum4" + }, + { + "map": [ + { + "key": { + "symbol": "asset_code" + }, + "val": { + "string": "aaa\\0" + } + }, + { + "key": { + "symbol": "issuer" + }, + "val": { + "bytes": "0000000000000000000000000000000000000000000000000000000000000003" + } + } + ] + } + ] + } + } + ] + } + } + } + }, + "ext": "v0" + }, + "live_until": 120960 + }, + { + "entry": { + "last_modified_ledger_seq": 0, + "data": { + "contract_code": { + "ext": "v0", + "hash": "e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855", + "code": "" + } + }, + "ext": "v0" + }, + "live_until": 4095 + } + ] + }, + "events": [] +} \ No newline at end of file diff --git a/contracts/helphone_dao/test_snapshots/test/passed_grant_is_disbursed_on_execution.1.json b/contracts/helphone_dao/test_snapshots/test/passed_grant_is_disbursed_on_execution.1.json new file mode 100644 index 00000000..7da1ac8b --- /dev/null +++ b/contracts/helphone_dao/test_snapshots/test/passed_grant_is_disbursed_on_execution.1.json @@ -0,0 +1,1451 @@ +{ + "generators": { + "address": 7, + "nonce": 0, + "mux_id": 0 + }, + "auth": [ + [], + [ + [ + "GAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAEGWF", + { + "function": { + "contract_fn": { + "contract_address": "CBEPDNVYXQGWB5YUBXKJWYJA7OXTZW5LFLNO5JRRGE6Z6C5OSUZPCCEL", + "function_name": "set_admin", + "args": [ + { + "address": "CAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAD2KM" + } + ] + } + }, + "sub_invocations": [] + } + ] + ], + [], + [ + [ + "GAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAGO6V", + { + "function": { + "contract_fn": { + "contract_address": "CBUSYNQKASUYFWYC3M2GUEDMX4AIVWPALDBYJPNK6554BREHTGZ2IUNF", + "function_name": "set_admin", + "args": [ + { + "address": "CAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAD2KM" + } + ] + } + }, + "sub_invocations": [] + } + ] + ], + [], + [ + [ + "CAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAD2KM", + { + "function": { + "contract_fn": { + "contract_address": "CAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAITA4", + "function_name": "configure_sustainability", + "args": [ + { + "address": "CAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAD2KM" + }, + { + "address": "CBUSYNQKASUYFWYC3M2GUEDMX4AIVWPALDBYJPNK6554BREHTGZ2IUNF" + } + ] + } + }, + "sub_invocations": [] + } + ] + ], + [ + [ + "CAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAD2KM", + { + "function": { + "contract_fn": { + "contract_address": "CBUSYNQKASUYFWYC3M2GUEDMX4AIVWPALDBYJPNK6554BREHTGZ2IUNF", + "function_name": "mint", + "args": [ + { + "address": "CAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAK3IM" + }, + { + "i128": "10000000" + } + ] + } + }, + "sub_invocations": [] + } + ] + ], + [ + [ + "CAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAK3IM", + { + "function": { + "contract_fn": { + "contract_address": "CAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAITA4", + "function_name": "collect_sustainability_fee", + "args": [ + { + "address": "CAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAK3IM" + }, + { + "i128": "10000000" + } + ] + } + }, + "sub_invocations": [ + { + "function": { + "contract_fn": { + "contract_address": "CBUSYNQKASUYFWYC3M2GUEDMX4AIVWPALDBYJPNK6554BREHTGZ2IUNF", + "function_name": "transfer", + "args": [ + { + "address": "CAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAK3IM" + }, + { + "address": "CAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAITA4" + }, + { + "i128": "100000" + } + ] + } + }, + "sub_invocations": [] + } + ] + } + ] + ], + [ + [ + "CAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAD2KM", + { + "function": { + "contract_fn": { + "contract_address": "CBEPDNVYXQGWB5YUBXKJWYJA7OXTZW5LFLNO5JRRGE6Z6C5OSUZPCCEL", + "function_name": "mint", + "args": [ + { + "address": "CAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAMDR4" + }, + { + "i128": "1000" + } + ] + } + }, + "sub_invocations": [] + } + ] + ], + [ + [ + "CAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAD2KM", + { + "function": { + "contract_fn": { + "contract_address": "CAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAITA4", + "function_name": "set_voting_supply", + "args": [ + { + "address": "CAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAD2KM" + }, + { + "i128": "1000" + } + ] + } + }, + "sub_invocations": [] + } + ] + ], + [ + [ + "CAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAMDR4", + { + "function": { + "contract_fn": { + "contract_address": "CAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAITA4", + "function_name": "propose_maintainer_grant", + "args": [ + { + "address": "CAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAMDR4" + }, + { + "address": "CAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAOLZM" + }, + { + "string": "npm:@stellar/stellar-sdk" + }, + { + "i128": "40000" + }, + { + "string": "Fund stellar-sdk" + }, + { + "string": "Critical dependency with a single maintainer" + } + ] + } + }, + "sub_invocations": [] + } + ] + ], + [], + [ + [ + "CAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAMDR4", + { + "function": { + "contract_fn": { + "contract_address": "CAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAITA4", + "function_name": "cast_vote", + "args": [ + { + "address": "CAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAMDR4" + }, + { + "u64": "1" + }, + { + "vec": [ + { + "symbol": "For" + } + ] + } + ] + } + }, + "sub_invocations": [] + } + ] + ], + [], + [], + [], + [], + [], + [] + ], + "ledger": { + "protocol_version": 26, + "sequence_number": 0, + "timestamp": 345601, + "network_id": "0000000000000000000000000000000000000000000000000000000000000000", + "base_reserve": 0, + "min_persistent_entry_ttl": 4096, + "min_temp_entry_ttl": 16, + "max_entry_ttl": 6312000, + "ledger_entries": [ + { + "entry": { + "last_modified_ledger_seq": 0, + "data": { + "account": { + "account_id": "GAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAEGWF", + "balance": "0", + "seq_num": "0", + "num_sub_entries": 0, + "inflation_dest": null, + "flags": 0, + "home_domain": "", + "thresholds": "01010101", + "signers": [], + "ext": "v0" + } + }, + "ext": "v0" + }, + "live_until": null + }, + { + "entry": { + "last_modified_ledger_seq": 0, + "data": { + "account": { + "account_id": "GAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAGO6V", + "balance": "0", + "seq_num": "0", + "num_sub_entries": 0, + "inflation_dest": null, + "flags": 0, + "home_domain": "", + "thresholds": "01010101", + "signers": [], + "ext": "v0" + } + }, + "ext": "v0" + }, + "live_until": null + }, + { + "entry": { + "last_modified_ledger_seq": 0, + "data": { + "contract_data": { + "ext": "v0", + "contract": "GAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAEGWF", + "key": { + "ledger_key_nonce": { + "nonce": "801925984706572462" + } + }, + "durability": "temporary", + "val": "void" + } + }, + "ext": "v0" + }, + "live_until": 6311999 + }, + { + "entry": { + "last_modified_ledger_seq": 0, + "data": { + "contract_data": { + "ext": "v0", + "contract": "GAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAGO6V", + "key": { + "ledger_key_nonce": { + "nonce": "5541220902715666415" + } + }, + "durability": "temporary", + "val": "void" + } + }, + "ext": "v0" + }, + "live_until": 6311999 + }, + { + "entry": { + "last_modified_ledger_seq": 0, + "data": { + "contract_data": { + "ext": "v0", + "contract": "CAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAD2KM", + "key": { + "ledger_key_nonce": { + "nonce": "1033654523790656264" + } + }, + "durability": "temporary", + "val": "void" + } + }, + "ext": "v0" + }, + "live_until": 6311999 + }, + { + "entry": { + "last_modified_ledger_seq": 0, + "data": { + "contract_data": { + "ext": "v0", + "contract": "CAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAD2KM", + "key": { + "ledger_key_nonce": { + "nonce": "4270020994084947596" + } + }, + "durability": "temporary", + "val": "void" + } + }, + "ext": "v0" + }, + "live_until": 6311999 + }, + { + "entry": { + "last_modified_ledger_seq": 0, + "data": { + "contract_data": { + "ext": "v0", + "contract": "CAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAD2KM", + "key": { + "ledger_key_nonce": { + "nonce": "4837995959683129791" + } + }, + "durability": "temporary", + "val": "void" + } + }, + "ext": "v0" + }, + "live_until": 6311999 + }, + { + "entry": { + "last_modified_ledger_seq": 0, + "data": { + "contract_data": { + "ext": "v0", + "contract": "CAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAD2KM", + "key": { + "ledger_key_nonce": { + "nonce": "8370022561469687789" + } + }, + "durability": "temporary", + "val": "void" + } + }, + "ext": "v0" + }, + "live_until": 6311999 + }, + { + "entry": { + "last_modified_ledger_seq": 0, + "data": { + "contract_data": { + "ext": "v0", + "contract": "CAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAITA4", + "key": { + "vec": [ + { + "symbol": "Grant" + }, + { + "u64": "1" + } + ] + }, + "durability": "persistent", + "val": { + "map": [ + { + "key": { + "symbol": "amount" + }, + "val": { + "i128": "40000" + } + }, + { + "key": { + "symbol": "disbursed_at" + }, + "val": { + "u64": "345601" + } + }, + { + "key": { + "symbol": "maintainer" + }, + "val": { + "address": "CAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAOLZM" + } + }, + { + "key": { + "symbol": "package" + }, + "val": { + "string": "npm:@stellar/stellar-sdk" + } + }, + { + "key": { + "symbol": "proposal_id" + }, + "val": { + "u64": "1" + } + }, + { + "key": { + "symbol": "status" + }, + "val": { + "vec": [ + { + "symbol": "Disbursed" + } + ] + } + } + ] + } + } + }, + "ext": "v0" + }, + "live_until": 4095 + }, + { + "entry": { + "last_modified_ledger_seq": 0, + "data": { + "contract_data": { + "ext": "v0", + "contract": "CAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAITA4", + "key": { + "vec": [ + { + "symbol": "MaintainerTotal" + }, + { + "address": "CAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAOLZM" + } + ] + }, + "durability": "persistent", + "val": { + "i128": "40000" + } + } + }, + "ext": "v0" + }, + "live_until": 4095 + }, + { + "entry": { + "last_modified_ledger_seq": 0, + "data": { + "contract_data": { + "ext": "v0", + "contract": "CAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAITA4", + "key": { + "vec": [ + { + "symbol": "Proposal" + }, + { + "u64": "1" + } + ] + }, + "durability": "persistent", + "val": { + "map": [ + { + "key": { + "symbol": "abstain_votes" + }, + "val": { + "i128": "0" + } + }, + { + "key": { + "symbol": "against_votes" + }, + "val": { + "i128": "0" + } + }, + { + "key": { + "symbol": "created_at" + }, + "val": { + "u64": "0" + } + }, + { + "key": { + "symbol": "description" + }, + "val": { + "string": "Critical dependency with a single maintainer" + } + }, + { + "key": { + "symbol": "executable_payload" + }, + "val": { + "bytes": "" + } + }, + { + "key": { + "symbol": "for_votes" + }, + "val": { + "i128": "1000" + } + }, + { + "key": { + "symbol": "id" + }, + "val": { + "u64": "1" + } + }, + { + "key": { + "symbol": "proposal_type" + }, + "val": { + "vec": [ + { + "symbol": "FundAllocation" + } + ] + } + }, + { + "key": { + "symbol": "proposer" + }, + "val": { + "address": "CAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAMDR4" + } + }, + { + "key": { + "symbol": "status" + }, + "val": { + "vec": [ + { + "symbol": "Executed" + } + ] + } + }, + { + "key": { + "symbol": "title" + }, + "val": { + "string": "Fund stellar-sdk" + } + }, + { + "key": { + "symbol": "voting_ends" + }, + "val": { + "u64": "259200" + } + }, + { + "key": { + "symbol": "voting_starts" + }, + "val": { + "u64": "0" + } + } + ] + } + } + }, + "ext": "v0" + }, + "live_until": 4095 + }, + { + "entry": { + "last_modified_ledger_seq": 0, + "data": { + "contract_data": { + "ext": "v0", + "contract": "CAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAITA4", + "key": { + "vec": [ + { + "symbol": "TokenSnapshot" + }, + { + "u64": "1" + } + ] + }, + "durability": "persistent", + "val": { + "map": [ + { + "key": { + "symbol": "snapshot_ledger" + }, + "val": { + "u32": 0 + } + }, + { + "key": { + "symbol": "total_supply" + }, + "val": { + "i128": "1000" + } + } + ] + } + } + }, + "ext": "v0" + }, + "live_until": 4095 + }, + { + "entry": { + "last_modified_ledger_seq": 0, + "data": { + "contract_data": { + "ext": "v0", + "contract": "CAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAITA4", + "key": { + "vec": [ + { + "symbol": "TotalSupplyAt" + }, + { + "u64": "1" + } + ] + }, + "durability": "persistent", + "val": { + "i128": "1000" + } + } + }, + "ext": "v0" + }, + "live_until": 4095 + }, + { + "entry": { + "last_modified_ledger_seq": 0, + "data": { + "contract_data": { + "ext": "v0", + "contract": "CAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAITA4", + "key": { + "vec": [ + { + "symbol": "Vote" + }, + { + "u64": "1" + }, + { + "address": "CAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAMDR4" + } + ] + }, + "durability": "persistent", + "val": { + "map": [ + { + "key": { + "symbol": "direction" + }, + "val": { + "vec": [ + { + "symbol": "For" + } + ] + } + }, + { + "key": { + "symbol": "voted_at" + }, + "val": { + "u64": "0" + } + }, + { + "key": { + "symbol": "voter" + }, + "val": { + "address": "CAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAMDR4" + } + }, + { + "key": { + "symbol": "weight" + }, + "val": { + "i128": "1000" + } + } + ] + } + } + }, + "ext": "v0" + }, + "live_until": 4095 + }, + { + "entry": { + "last_modified_ledger_seq": 0, + "data": { + "contract_data": { + "ext": "v0", + "contract": "CAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAITA4", + "key": "ledger_key_contract_instance", + "durability": "persistent", + "val": { + "contract_instance": { + "executable": { + "wasm": "e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855" + }, + "storage": [ + { + "key": { + "symbol": "admin" + }, + "val": { + "address": "CAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAD2KM" + } + }, + { + "key": { + "symbol": "execd" + }, + "val": { + "vec": [ + { + "u64": "1" + } + ] + } + }, + { + "key": { + "symbol": "pcount" + }, + "val": { + "u64": "1" + } + }, + { + "key": { + "symbol": "token" + }, + "val": { + "address": "CBEPDNVYXQGWB5YUBXKJWYJA7OXTZW5LFLNO5JRRGE6Z6C5OSUZPCCEL" + } + }, + { + "key": { + "symbol": "vsupply" + }, + "val": { + "i128": "1000" + } + }, + { + "key": { + "vec": [ + { + "symbol": "Collected" + } + ] + }, + "val": { + "i128": "100000" + } + }, + { + "key": { + "vec": [ + { + "symbol": "Disbursed" + } + ] + }, + "val": { + "i128": "40000" + } + }, + { + "key": { + "vec": [ + { + "symbol": "GrantsDisbursed" + } + ] + }, + "val": { + "u32": 1 + } + }, + { + "key": { + "vec": [ + { + "symbol": "GrantsProposed" + } + ] + }, + "val": { + "u32": 1 + } + }, + { + "key": { + "vec": [ + { + "symbol": "MaintainersFunded" + } + ] + }, + "val": { + "u32": 1 + } + }, + { + "key": { + "vec": [ + { + "symbol": "Reserve" + } + ] + }, + "val": { + "i128": "60000" + } + }, + { + "key": { + "vec": [ + { + "symbol": "Token" + } + ] + }, + "val": { + "address": "CBUSYNQKASUYFWYC3M2GUEDMX4AIVWPALDBYJPNK6554BREHTGZ2IUNF" + } + } + ] + } + } + } + }, + "ext": "v0" + }, + "live_until": 4095 + }, + { + "entry": { + "last_modified_ledger_seq": 0, + "data": { + "contract_data": { + "ext": "v0", + "contract": "CAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAK3IM", + "key": { + "ledger_key_nonce": { + "nonce": "2032731177588607455" + } + }, + "durability": "temporary", + "val": "void" + } + }, + "ext": "v0" + }, + "live_until": 6311999 + }, + { + "entry": { + "last_modified_ledger_seq": 0, + "data": { + "contract_data": { + "ext": "v0", + "contract": "CAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAMDR4", + "key": { + "ledger_key_nonce": { + "nonce": "5806905060045992000" + } + }, + "durability": "temporary", + "val": "void" + } + }, + "ext": "v0" + }, + "live_until": 6311999 + }, + { + "entry": { + "last_modified_ledger_seq": 0, + "data": { + "contract_data": { + "ext": "v0", + "contract": "CAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAMDR4", + "key": { + "ledger_key_nonce": { + "nonce": "6277191135259896685" + } + }, + "durability": "temporary", + "val": "void" + } + }, + "ext": "v0" + }, + "live_until": 6311999 + }, + { + "entry": { + "last_modified_ledger_seq": 0, + "data": { + "contract_data": { + "ext": "v0", + "contract": "CBEPDNVYXQGWB5YUBXKJWYJA7OXTZW5LFLNO5JRRGE6Z6C5OSUZPCCEL", + "key": { + "vec": [ + { + "symbol": "Balance" + }, + { + "address": "CAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAMDR4" + } + ] + }, + "durability": "persistent", + "val": { + "map": [ + { + "key": { + "symbol": "amount" + }, + "val": { + "i128": "1000" + } + }, + { + "key": { + "symbol": "authorized" + }, + "val": { + "bool": true + } + }, + { + "key": { + "symbol": "clawback" + }, + "val": { + "bool": false + } + } + ] + } + } + }, + "ext": "v0" + }, + "live_until": 518400 + }, + { + "entry": { + "last_modified_ledger_seq": 0, + "data": { + "contract_data": { + "ext": "v0", + "contract": "CBEPDNVYXQGWB5YUBXKJWYJA7OXTZW5LFLNO5JRRGE6Z6C5OSUZPCCEL", + "key": "ledger_key_contract_instance", + "durability": "persistent", + "val": { + "contract_instance": { + "executable": "stellar_asset", + "storage": [ + { + "key": { + "symbol": "METADATA" + }, + "val": { + "map": [ + { + "key": { + "symbol": "decimal" + }, + "val": { + "u32": 7 + } + }, + { + "key": { + "symbol": "name" + }, + "val": { + "string": "aaa:GAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAEGWF" + } + }, + { + "key": { + "symbol": "symbol" + }, + "val": { + "string": "aaa" + } + } + ] + } + }, + { + "key": { + "vec": [ + { + "symbol": "Admin" + } + ] + }, + "val": { + "address": "CAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAD2KM" + } + }, + { + "key": { + "vec": [ + { + "symbol": "AssetInfo" + } + ] + }, + "val": { + "vec": [ + { + "symbol": "AlphaNum4" + }, + { + "map": [ + { + "key": { + "symbol": "asset_code" + }, + "val": { + "string": "aaa\\0" + } + }, + { + "key": { + "symbol": "issuer" + }, + "val": { + "bytes": "0000000000000000000000000000000000000000000000000000000000000002" + } + } + ] + } + ] + } + } + ] + } + } + } + }, + "ext": "v0" + }, + "live_until": 120960 + }, + { + "entry": { + "last_modified_ledger_seq": 0, + "data": { + "contract_data": { + "ext": "v0", + "contract": "CBUSYNQKASUYFWYC3M2GUEDMX4AIVWPALDBYJPNK6554BREHTGZ2IUNF", + "key": { + "vec": [ + { + "symbol": "Balance" + }, + { + "address": "CAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAITA4" + } + ] + }, + "durability": "persistent", + "val": { + "map": [ + { + "key": { + "symbol": "amount" + }, + "val": { + "i128": "60000" + } + }, + { + "key": { + "symbol": "authorized" + }, + "val": { + "bool": true + } + }, + { + "key": { + "symbol": "clawback" + }, + "val": { + "bool": false + } + } + ] + } + } + }, + "ext": "v0" + }, + "live_until": 518400 + }, + { + "entry": { + "last_modified_ledger_seq": 0, + "data": { + "contract_data": { + "ext": "v0", + "contract": "CBUSYNQKASUYFWYC3M2GUEDMX4AIVWPALDBYJPNK6554BREHTGZ2IUNF", + "key": { + "vec": [ + { + "symbol": "Balance" + }, + { + "address": "CAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAK3IM" + } + ] + }, + "durability": "persistent", + "val": { + "map": [ + { + "key": { + "symbol": "amount" + }, + "val": { + "i128": "9900000" + } + }, + { + "key": { + "symbol": "authorized" + }, + "val": { + "bool": true + } + }, + { + "key": { + "symbol": "clawback" + }, + "val": { + "bool": false + } + } + ] + } + } + }, + "ext": "v0" + }, + "live_until": 518400 + }, + { + "entry": { + "last_modified_ledger_seq": 0, + "data": { + "contract_data": { + "ext": "v0", + "contract": "CBUSYNQKASUYFWYC3M2GUEDMX4AIVWPALDBYJPNK6554BREHTGZ2IUNF", + "key": { + "vec": [ + { + "symbol": "Balance" + }, + { + "address": "CAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAOLZM" + } + ] + }, + "durability": "persistent", + "val": { + "map": [ + { + "key": { + "symbol": "amount" + }, + "val": { + "i128": "40000" + } + }, + { + "key": { + "symbol": "authorized" + }, + "val": { + "bool": true + } + }, + { + "key": { + "symbol": "clawback" + }, + "val": { + "bool": false + } + } + ] + } + } + }, + "ext": "v0" + }, + "live_until": 518400 + }, + { + "entry": { + "last_modified_ledger_seq": 0, + "data": { + "contract_data": { + "ext": "v0", + "contract": "CBUSYNQKASUYFWYC3M2GUEDMX4AIVWPALDBYJPNK6554BREHTGZ2IUNF", + "key": "ledger_key_contract_instance", + "durability": "persistent", + "val": { + "contract_instance": { + "executable": "stellar_asset", + "storage": [ + { + "key": { + "symbol": "METADATA" + }, + "val": { + "map": [ + { + "key": { + "symbol": "decimal" + }, + "val": { + "u32": 7 + } + }, + { + "key": { + "symbol": "name" + }, + "val": { + "string": "aaa:GAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAGO6V" + } + }, + { + "key": { + "symbol": "symbol" + }, + "val": { + "string": "aaa" + } + } + ] + } + }, + { + "key": { + "vec": [ + { + "symbol": "Admin" + } + ] + }, + "val": { + "address": "CAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAD2KM" + } + }, + { + "key": { + "vec": [ + { + "symbol": "AssetInfo" + } + ] + }, + "val": { + "vec": [ + { + "symbol": "AlphaNum4" + }, + { + "map": [ + { + "key": { + "symbol": "asset_code" + }, + "val": { + "string": "aaa\\0" + } + }, + { + "key": { + "symbol": "issuer" + }, + "val": { + "bytes": "0000000000000000000000000000000000000000000000000000000000000003" + } + } + ] + } + ] + } + } + ] + } + } + } + }, + "ext": "v0" + }, + "live_until": 120960 + }, + { + "entry": { + "last_modified_ledger_seq": 0, + "data": { + "contract_code": { + "ext": "v0", + "hash": "e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855", + "code": "" + } + }, + "ext": "v0" + }, + "live_until": 4095 + } + ] + }, + "events": [] +} \ No newline at end of file diff --git a/contracts/helphone_dao/test_snapshots/test/rejected_grant_cannot_be_disbursed.1.json b/contracts/helphone_dao/test_snapshots/test/rejected_grant_cannot_be_disbursed.1.json new file mode 100644 index 00000000..16bb070f --- /dev/null +++ b/contracts/helphone_dao/test_snapshots/test/rejected_grant_cannot_be_disbursed.1.json @@ -0,0 +1,1086 @@ +{ + "generators": { + "address": 6, + "nonce": 0, + "mux_id": 0 + }, + "auth": [ + [], + [ + [ + "GAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAEGWF", + { + "function": { + "contract_fn": { + "contract_address": "CBEPDNVYXQGWB5YUBXKJWYJA7OXTZW5LFLNO5JRRGE6Z6C5OSUZPCCEL", + "function_name": "set_admin", + "args": [ + { + "address": "CAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAD2KM" + } + ] + } + }, + "sub_invocations": [] + } + ] + ], + [], + [ + [ + "GAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAGO6V", + { + "function": { + "contract_fn": { + "contract_address": "CBUSYNQKASUYFWYC3M2GUEDMX4AIVWPALDBYJPNK6554BREHTGZ2IUNF", + "function_name": "set_admin", + "args": [ + { + "address": "CAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAD2KM" + } + ] + } + }, + "sub_invocations": [] + } + ] + ], + [], + [ + [ + "CAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAD2KM", + { + "function": { + "contract_fn": { + "contract_address": "CAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAITA4", + "function_name": "configure_sustainability", + "args": [ + { + "address": "CAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAD2KM" + }, + { + "address": "CBUSYNQKASUYFWYC3M2GUEDMX4AIVWPALDBYJPNK6554BREHTGZ2IUNF" + } + ] + } + }, + "sub_invocations": [] + } + ] + ], + [ + [ + "CAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAD2KM", + { + "function": { + "contract_fn": { + "contract_address": "CBEPDNVYXQGWB5YUBXKJWYJA7OXTZW5LFLNO5JRRGE6Z6C5OSUZPCCEL", + "function_name": "mint", + "args": [ + { + "address": "CAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAK3IM" + }, + { + "i128": "1000" + } + ] + } + }, + "sub_invocations": [] + } + ] + ], + [ + [ + "CAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAD2KM", + { + "function": { + "contract_fn": { + "contract_address": "CAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAITA4", + "function_name": "set_voting_supply", + "args": [ + { + "address": "CAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAD2KM" + }, + { + "i128": "1000" + } + ] + } + }, + "sub_invocations": [] + } + ] + ], + [ + [ + "CAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAK3IM", + { + "function": { + "contract_fn": { + "contract_address": "CAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAITA4", + "function_name": "propose_maintainer_grant", + "args": [ + { + "address": "CAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAK3IM" + }, + { + "address": "CAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAMDR4" + }, + { + "string": "npm:x" + }, + { + "i128": "1" + }, + { + "string": "t" + }, + { + "string": "d" + } + ] + } + }, + "sub_invocations": [] + } + ] + ], + [ + [ + "CAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAK3IM", + { + "function": { + "contract_fn": { + "contract_address": "CAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAITA4", + "function_name": "cast_vote", + "args": [ + { + "address": "CAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAK3IM" + }, + { + "u64": "1" + }, + { + "vec": [ + { + "symbol": "Against" + } + ] + } + ] + } + }, + "sub_invocations": [] + } + ] + ], + [], + [] + ], + "ledger": { + "protocol_version": 26, + "sequence_number": 0, + "timestamp": 345601, + "network_id": "0000000000000000000000000000000000000000000000000000000000000000", + "base_reserve": 0, + "min_persistent_entry_ttl": 4096, + "min_temp_entry_ttl": 16, + "max_entry_ttl": 6312000, + "ledger_entries": [ + { + "entry": { + "last_modified_ledger_seq": 0, + "data": { + "account": { + "account_id": "GAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAEGWF", + "balance": "0", + "seq_num": "0", + "num_sub_entries": 0, + "inflation_dest": null, + "flags": 0, + "home_domain": "", + "thresholds": "01010101", + "signers": [], + "ext": "v0" + } + }, + "ext": "v0" + }, + "live_until": null + }, + { + "entry": { + "last_modified_ledger_seq": 0, + "data": { + "account": { + "account_id": "GAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAGO6V", + "balance": "0", + "seq_num": "0", + "num_sub_entries": 0, + "inflation_dest": null, + "flags": 0, + "home_domain": "", + "thresholds": "01010101", + "signers": [], + "ext": "v0" + } + }, + "ext": "v0" + }, + "live_until": null + }, + { + "entry": { + "last_modified_ledger_seq": 0, + "data": { + "contract_data": { + "ext": "v0", + "contract": "GAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAEGWF", + "key": { + "ledger_key_nonce": { + "nonce": "801925984706572462" + } + }, + "durability": "temporary", + "val": "void" + } + }, + "ext": "v0" + }, + "live_until": 6311999 + }, + { + "entry": { + "last_modified_ledger_seq": 0, + "data": { + "contract_data": { + "ext": "v0", + "contract": "GAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAGO6V", + "key": { + "ledger_key_nonce": { + "nonce": "5541220902715666415" + } + }, + "durability": "temporary", + "val": "void" + } + }, + "ext": "v0" + }, + "live_until": 6311999 + }, + { + "entry": { + "last_modified_ledger_seq": 0, + "data": { + "contract_data": { + "ext": "v0", + "contract": "CAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAD2KM", + "key": { + "ledger_key_nonce": { + "nonce": "1033654523790656264" + } + }, + "durability": "temporary", + "val": "void" + } + }, + "ext": "v0" + }, + "live_until": 6311999 + }, + { + "entry": { + "last_modified_ledger_seq": 0, + "data": { + "contract_data": { + "ext": "v0", + "contract": "CAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAD2KM", + "key": { + "ledger_key_nonce": { + "nonce": "2032731177588607455" + } + }, + "durability": "temporary", + "val": "void" + } + }, + "ext": "v0" + }, + "live_until": 6311999 + }, + { + "entry": { + "last_modified_ledger_seq": 0, + "data": { + "contract_data": { + "ext": "v0", + "contract": "CAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAD2KM", + "key": { + "ledger_key_nonce": { + "nonce": "4837995959683129791" + } + }, + "durability": "temporary", + "val": "void" + } + }, + "ext": "v0" + }, + "live_until": 6311999 + }, + { + "entry": { + "last_modified_ledger_seq": 0, + "data": { + "contract_data": { + "ext": "v0", + "contract": "CAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAITA4", + "key": { + "vec": [ + { + "symbol": "Grant" + }, + { + "u64": "1" + } + ] + }, + "durability": "persistent", + "val": { + "map": [ + { + "key": { + "symbol": "amount" + }, + "val": { + "i128": "1" + } + }, + { + "key": { + "symbol": "disbursed_at" + }, + "val": { + "u64": "0" + } + }, + { + "key": { + "symbol": "maintainer" + }, + "val": { + "address": "CAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAMDR4" + } + }, + { + "key": { + "symbol": "package" + }, + "val": { + "string": "npm:x" + } + }, + { + "key": { + "symbol": "proposal_id" + }, + "val": { + "u64": "1" + } + }, + { + "key": { + "symbol": "status" + }, + "val": { + "vec": [ + { + "symbol": "Pending" + } + ] + } + } + ] + } + } + }, + "ext": "v0" + }, + "live_until": 4095 + }, + { + "entry": { + "last_modified_ledger_seq": 0, + "data": { + "contract_data": { + "ext": "v0", + "contract": "CAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAITA4", + "key": { + "vec": [ + { + "symbol": "Proposal" + }, + { + "u64": "1" + } + ] + }, + "durability": "persistent", + "val": { + "map": [ + { + "key": { + "symbol": "abstain_votes" + }, + "val": { + "i128": "0" + } + }, + { + "key": { + "symbol": "against_votes" + }, + "val": { + "i128": "1000" + } + }, + { + "key": { + "symbol": "created_at" + }, + "val": { + "u64": "0" + } + }, + { + "key": { + "symbol": "description" + }, + "val": { + "string": "d" + } + }, + { + "key": { + "symbol": "executable_payload" + }, + "val": { + "bytes": "" + } + }, + { + "key": { + "symbol": "for_votes" + }, + "val": { + "i128": "0" + } + }, + { + "key": { + "symbol": "id" + }, + "val": { + "u64": "1" + } + }, + { + "key": { + "symbol": "proposal_type" + }, + "val": { + "vec": [ + { + "symbol": "FundAllocation" + } + ] + } + }, + { + "key": { + "symbol": "proposer" + }, + "val": { + "address": "CAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAK3IM" + } + }, + { + "key": { + "symbol": "status" + }, + "val": { + "vec": [ + { + "symbol": "Active" + } + ] + } + }, + { + "key": { + "symbol": "title" + }, + "val": { + "string": "t" + } + }, + { + "key": { + "symbol": "voting_ends" + }, + "val": { + "u64": "259200" + } + }, + { + "key": { + "symbol": "voting_starts" + }, + "val": { + "u64": "0" + } + } + ] + } + } + }, + "ext": "v0" + }, + "live_until": 4095 + }, + { + "entry": { + "last_modified_ledger_seq": 0, + "data": { + "contract_data": { + "ext": "v0", + "contract": "CAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAITA4", + "key": { + "vec": [ + { + "symbol": "TokenSnapshot" + }, + { + "u64": "1" + } + ] + }, + "durability": "persistent", + "val": { + "map": [ + { + "key": { + "symbol": "snapshot_ledger" + }, + "val": { + "u32": 0 + } + }, + { + "key": { + "symbol": "total_supply" + }, + "val": { + "i128": "1000" + } + } + ] + } + } + }, + "ext": "v0" + }, + "live_until": 4095 + }, + { + "entry": { + "last_modified_ledger_seq": 0, + "data": { + "contract_data": { + "ext": "v0", + "contract": "CAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAITA4", + "key": { + "vec": [ + { + "symbol": "TotalSupplyAt" + }, + { + "u64": "1" + } + ] + }, + "durability": "persistent", + "val": { + "i128": "1000" + } + } + }, + "ext": "v0" + }, + "live_until": 4095 + }, + { + "entry": { + "last_modified_ledger_seq": 0, + "data": { + "contract_data": { + "ext": "v0", + "contract": "CAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAITA4", + "key": { + "vec": [ + { + "symbol": "Vote" + }, + { + "u64": "1" + }, + { + "address": "CAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAK3IM" + } + ] + }, + "durability": "persistent", + "val": { + "map": [ + { + "key": { + "symbol": "direction" + }, + "val": { + "vec": [ + { + "symbol": "Against" + } + ] + } + }, + { + "key": { + "symbol": "voted_at" + }, + "val": { + "u64": "0" + } + }, + { + "key": { + "symbol": "voter" + }, + "val": { + "address": "CAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAK3IM" + } + }, + { + "key": { + "symbol": "weight" + }, + "val": { + "i128": "1000" + } + } + ] + } + } + }, + "ext": "v0" + }, + "live_until": 4095 + }, + { + "entry": { + "last_modified_ledger_seq": 0, + "data": { + "contract_data": { + "ext": "v0", + "contract": "CAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAITA4", + "key": "ledger_key_contract_instance", + "durability": "persistent", + "val": { + "contract_instance": { + "executable": { + "wasm": "e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855" + }, + "storage": [ + { + "key": { + "symbol": "admin" + }, + "val": { + "address": "CAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAD2KM" + } + }, + { + "key": { + "symbol": "pcount" + }, + "val": { + "u64": "1" + } + }, + { + "key": { + "symbol": "token" + }, + "val": { + "address": "CBEPDNVYXQGWB5YUBXKJWYJA7OXTZW5LFLNO5JRRGE6Z6C5OSUZPCCEL" + } + }, + { + "key": { + "symbol": "vsupply" + }, + "val": { + "i128": "1000" + } + }, + { + "key": { + "vec": [ + { + "symbol": "GrantsProposed" + } + ] + }, + "val": { + "u32": 1 + } + }, + { + "key": { + "vec": [ + { + "symbol": "Token" + } + ] + }, + "val": { + "address": "CBUSYNQKASUYFWYC3M2GUEDMX4AIVWPALDBYJPNK6554BREHTGZ2IUNF" + } + } + ] + } + } + } + }, + "ext": "v0" + }, + "live_until": 4095 + }, + { + "entry": { + "last_modified_ledger_seq": 0, + "data": { + "contract_data": { + "ext": "v0", + "contract": "CAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAK3IM", + "key": { + "ledger_key_nonce": { + "nonce": "4270020994084947596" + } + }, + "durability": "temporary", + "val": "void" + } + }, + "ext": "v0" + }, + "live_until": 6311999 + }, + { + "entry": { + "last_modified_ledger_seq": 0, + "data": { + "contract_data": { + "ext": "v0", + "contract": "CAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAK3IM", + "key": { + "ledger_key_nonce": { + "nonce": "8370022561469687789" + } + }, + "durability": "temporary", + "val": "void" + } + }, + "ext": "v0" + }, + "live_until": 6311999 + }, + { + "entry": { + "last_modified_ledger_seq": 0, + "data": { + "contract_data": { + "ext": "v0", + "contract": "CBEPDNVYXQGWB5YUBXKJWYJA7OXTZW5LFLNO5JRRGE6Z6C5OSUZPCCEL", + "key": { + "vec": [ + { + "symbol": "Balance" + }, + { + "address": "CAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAK3IM" + } + ] + }, + "durability": "persistent", + "val": { + "map": [ + { + "key": { + "symbol": "amount" + }, + "val": { + "i128": "1000" + } + }, + { + "key": { + "symbol": "authorized" + }, + "val": { + "bool": true + } + }, + { + "key": { + "symbol": "clawback" + }, + "val": { + "bool": false + } + } + ] + } + } + }, + "ext": "v0" + }, + "live_until": 518400 + }, + { + "entry": { + "last_modified_ledger_seq": 0, + "data": { + "contract_data": { + "ext": "v0", + "contract": "CBEPDNVYXQGWB5YUBXKJWYJA7OXTZW5LFLNO5JRRGE6Z6C5OSUZPCCEL", + "key": "ledger_key_contract_instance", + "durability": "persistent", + "val": { + "contract_instance": { + "executable": "stellar_asset", + "storage": [ + { + "key": { + "symbol": "METADATA" + }, + "val": { + "map": [ + { + "key": { + "symbol": "decimal" + }, + "val": { + "u32": 7 + } + }, + { + "key": { + "symbol": "name" + }, + "val": { + "string": "aaa:GAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAEGWF" + } + }, + { + "key": { + "symbol": "symbol" + }, + "val": { + "string": "aaa" + } + } + ] + } + }, + { + "key": { + "vec": [ + { + "symbol": "Admin" + } + ] + }, + "val": { + "address": "CAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAD2KM" + } + }, + { + "key": { + "vec": [ + { + "symbol": "AssetInfo" + } + ] + }, + "val": { + "vec": [ + { + "symbol": "AlphaNum4" + }, + { + "map": [ + { + "key": { + "symbol": "asset_code" + }, + "val": { + "string": "aaa\\0" + } + }, + { + "key": { + "symbol": "issuer" + }, + "val": { + "bytes": "0000000000000000000000000000000000000000000000000000000000000002" + } + } + ] + } + ] + } + } + ] + } + } + } + }, + "ext": "v0" + }, + "live_until": 120960 + }, + { + "entry": { + "last_modified_ledger_seq": 0, + "data": { + "contract_data": { + "ext": "v0", + "contract": "CBUSYNQKASUYFWYC3M2GUEDMX4AIVWPALDBYJPNK6554BREHTGZ2IUNF", + "key": "ledger_key_contract_instance", + "durability": "persistent", + "val": { + "contract_instance": { + "executable": "stellar_asset", + "storage": [ + { + "key": { + "symbol": "METADATA" + }, + "val": { + "map": [ + { + "key": { + "symbol": "decimal" + }, + "val": { + "u32": 7 + } + }, + { + "key": { + "symbol": "name" + }, + "val": { + "string": "aaa:GAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAGO6V" + } + }, + { + "key": { + "symbol": "symbol" + }, + "val": { + "string": "aaa" + } + } + ] + } + }, + { + "key": { + "vec": [ + { + "symbol": "Admin" + } + ] + }, + "val": { + "address": "CAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAD2KM" + } + }, + { + "key": { + "vec": [ + { + "symbol": "AssetInfo" + } + ] + }, + "val": { + "vec": [ + { + "symbol": "AlphaNum4" + }, + { + "map": [ + { + "key": { + "symbol": "asset_code" + }, + "val": { + "string": "aaa\\0" + } + }, + { + "key": { + "symbol": "issuer" + }, + "val": { + "bytes": "0000000000000000000000000000000000000000000000000000000000000003" + } + } + ] + } + ] + } + } + ] + } + } + } + }, + "ext": "v0" + }, + "live_until": 120960 + }, + { + "entry": { + "last_modified_ledger_seq": 0, + "data": { + "contract_code": { + "ext": "v0", + "hash": "e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855", + "code": "" + } + }, + "ext": "v0" + }, + "live_until": 4095 + } + ] + }, + "events": [] +} \ No newline at end of file diff --git a/contracts/helphone_dao/test_snapshots/test/rejects_bad_sustainability_inputs.1.json b/contracts/helphone_dao/test_snapshots/test/rejects_bad_sustainability_inputs.1.json new file mode 100644 index 00000000..0870dd72 --- /dev/null +++ b/contracts/helphone_dao/test_snapshots/test/rejects_bad_sustainability_inputs.1.json @@ -0,0 +1,473 @@ +{ + "generators": { + "address": 6, + "nonce": 0, + "mux_id": 0 + }, + "auth": [ + [], + [ + [ + "GAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAEGWF", + { + "function": { + "contract_fn": { + "contract_address": "CBEPDNVYXQGWB5YUBXKJWYJA7OXTZW5LFLNO5JRRGE6Z6C5OSUZPCCEL", + "function_name": "set_admin", + "args": [ + { + "address": "CAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAD2KM" + } + ] + } + }, + "sub_invocations": [] + } + ] + ], + [], + [ + [ + "GAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAGO6V", + { + "function": { + "contract_fn": { + "contract_address": "CBUSYNQKASUYFWYC3M2GUEDMX4AIVWPALDBYJPNK6554BREHTGZ2IUNF", + "function_name": "set_admin", + "args": [ + { + "address": "CAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAD2KM" + } + ] + } + }, + "sub_invocations": [] + } + ] + ], + [], + [], + [], + [], + [ + [ + "CAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAD2KM", + { + "function": { + "contract_fn": { + "contract_address": "CAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAITA4", + "function_name": "configure_sustainability", + "args": [ + { + "address": "CAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAD2KM" + }, + { + "address": "CBUSYNQKASUYFWYC3M2GUEDMX4AIVWPALDBYJPNK6554BREHTGZ2IUNF" + } + ] + } + }, + "sub_invocations": [] + } + ] + ], + [], + [], + [] + ], + "ledger": { + "protocol_version": 26, + "sequence_number": 0, + "timestamp": 0, + "network_id": "0000000000000000000000000000000000000000000000000000000000000000", + "base_reserve": 0, + "min_persistent_entry_ttl": 4096, + "min_temp_entry_ttl": 16, + "max_entry_ttl": 6312000, + "ledger_entries": [ + { + "entry": { + "last_modified_ledger_seq": 0, + "data": { + "account": { + "account_id": "GAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAEGWF", + "balance": "0", + "seq_num": "0", + "num_sub_entries": 0, + "inflation_dest": null, + "flags": 0, + "home_domain": "", + "thresholds": "01010101", + "signers": [], + "ext": "v0" + } + }, + "ext": "v0" + }, + "live_until": null + }, + { + "entry": { + "last_modified_ledger_seq": 0, + "data": { + "account": { + "account_id": "GAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAGO6V", + "balance": "0", + "seq_num": "0", + "num_sub_entries": 0, + "inflation_dest": null, + "flags": 0, + "home_domain": "", + "thresholds": "01010101", + "signers": [], + "ext": "v0" + } + }, + "ext": "v0" + }, + "live_until": null + }, + { + "entry": { + "last_modified_ledger_seq": 0, + "data": { + "contract_data": { + "ext": "v0", + "contract": "GAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAEGWF", + "key": { + "ledger_key_nonce": { + "nonce": "801925984706572462" + } + }, + "durability": "temporary", + "val": "void" + } + }, + "ext": "v0" + }, + "live_until": 6311999 + }, + { + "entry": { + "last_modified_ledger_seq": 0, + "data": { + "contract_data": { + "ext": "v0", + "contract": "GAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAGO6V", + "key": { + "ledger_key_nonce": { + "nonce": "5541220902715666415" + } + }, + "durability": "temporary", + "val": "void" + } + }, + "ext": "v0" + }, + "live_until": 6311999 + }, + { + "entry": { + "last_modified_ledger_seq": 0, + "data": { + "contract_data": { + "ext": "v0", + "contract": "CAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAD2KM", + "key": { + "ledger_key_nonce": { + "nonce": "4837995959683129791" + } + }, + "durability": "temporary", + "val": "void" + } + }, + "ext": "v0" + }, + "live_until": 6311999 + }, + { + "entry": { + "last_modified_ledger_seq": 0, + "data": { + "contract_data": { + "ext": "v0", + "contract": "CAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAITA4", + "key": "ledger_key_contract_instance", + "durability": "persistent", + "val": { + "contract_instance": { + "executable": { + "wasm": "e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855" + }, + "storage": [ + { + "key": { + "symbol": "admin" + }, + "val": { + "address": "CAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAD2KM" + } + }, + { + "key": { + "symbol": "pcount" + }, + "val": { + "u64": "0" + } + }, + { + "key": { + "symbol": "token" + }, + "val": { + "address": "CBEPDNVYXQGWB5YUBXKJWYJA7OXTZW5LFLNO5JRRGE6Z6C5OSUZPCCEL" + } + }, + { + "key": { + "vec": [ + { + "symbol": "Token" + } + ] + }, + "val": { + "address": "CBUSYNQKASUYFWYC3M2GUEDMX4AIVWPALDBYJPNK6554BREHTGZ2IUNF" + } + } + ] + } + } + } + }, + "ext": "v0" + }, + "live_until": 4095 + }, + { + "entry": { + "last_modified_ledger_seq": 0, + "data": { + "contract_data": { + "ext": "v0", + "contract": "CBEPDNVYXQGWB5YUBXKJWYJA7OXTZW5LFLNO5JRRGE6Z6C5OSUZPCCEL", + "key": "ledger_key_contract_instance", + "durability": "persistent", + "val": { + "contract_instance": { + "executable": "stellar_asset", + "storage": [ + { + "key": { + "symbol": "METADATA" + }, + "val": { + "map": [ + { + "key": { + "symbol": "decimal" + }, + "val": { + "u32": 7 + } + }, + { + "key": { + "symbol": "name" + }, + "val": { + "string": "aaa:GAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAEGWF" + } + }, + { + "key": { + "symbol": "symbol" + }, + "val": { + "string": "aaa" + } + } + ] + } + }, + { + "key": { + "vec": [ + { + "symbol": "Admin" + } + ] + }, + "val": { + "address": "CAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAD2KM" + } + }, + { + "key": { + "vec": [ + { + "symbol": "AssetInfo" + } + ] + }, + "val": { + "vec": [ + { + "symbol": "AlphaNum4" + }, + { + "map": [ + { + "key": { + "symbol": "asset_code" + }, + "val": { + "string": "aaa\\0" + } + }, + { + "key": { + "symbol": "issuer" + }, + "val": { + "bytes": "0000000000000000000000000000000000000000000000000000000000000002" + } + } + ] + } + ] + } + } + ] + } + } + } + }, + "ext": "v0" + }, + "live_until": 120960 + }, + { + "entry": { + "last_modified_ledger_seq": 0, + "data": { + "contract_data": { + "ext": "v0", + "contract": "CBUSYNQKASUYFWYC3M2GUEDMX4AIVWPALDBYJPNK6554BREHTGZ2IUNF", + "key": "ledger_key_contract_instance", + "durability": "persistent", + "val": { + "contract_instance": { + "executable": "stellar_asset", + "storage": [ + { + "key": { + "symbol": "METADATA" + }, + "val": { + "map": [ + { + "key": { + "symbol": "decimal" + }, + "val": { + "u32": 7 + } + }, + { + "key": { + "symbol": "name" + }, + "val": { + "string": "aaa:GAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAGO6V" + } + }, + { + "key": { + "symbol": "symbol" + }, + "val": { + "string": "aaa" + } + } + ] + } + }, + { + "key": { + "vec": [ + { + "symbol": "Admin" + } + ] + }, + "val": { + "address": "CAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAD2KM" + } + }, + { + "key": { + "vec": [ + { + "symbol": "AssetInfo" + } + ] + }, + "val": { + "vec": [ + { + "symbol": "AlphaNum4" + }, + { + "map": [ + { + "key": { + "symbol": "asset_code" + }, + "val": { + "string": "aaa\\0" + } + }, + { + "key": { + "symbol": "issuer" + }, + "val": { + "bytes": "0000000000000000000000000000000000000000000000000000000000000003" + } + } + ] + } + ] + } + } + ] + } + } + } + }, + "ext": "v0" + }, + "live_until": 120960 + }, + { + "entry": { + "last_modified_ledger_seq": 0, + "data": { + "contract_code": { + "ext": "v0", + "hash": "e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855", + "code": "" + } + }, + "ext": "v0" + }, + "live_until": 4095 + } + ] + }, + "events": [] +} \ No newline at end of file diff --git a/contracts/helphone_dao/test_snapshots/test/underfunded_grant_stays_pending_until_reserve_grows.1.json b/contracts/helphone_dao/test_snapshots/test/underfunded_grant_stays_pending_until_reserve_grows.1.json new file mode 100644 index 00000000..456608a4 --- /dev/null +++ b/contracts/helphone_dao/test_snapshots/test/underfunded_grant_stays_pending_until_reserve_grows.1.json @@ -0,0 +1,1450 @@ +{ + "generators": { + "address": 7, + "nonce": 0, + "mux_id": 0 + }, + "auth": [ + [], + [ + [ + "GAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAEGWF", + { + "function": { + "contract_fn": { + "contract_address": "CBEPDNVYXQGWB5YUBXKJWYJA7OXTZW5LFLNO5JRRGE6Z6C5OSUZPCCEL", + "function_name": "set_admin", + "args": [ + { + "address": "CAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAD2KM" + } + ] + } + }, + "sub_invocations": [] + } + ] + ], + [], + [ + [ + "GAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAGO6V", + { + "function": { + "contract_fn": { + "contract_address": "CBUSYNQKASUYFWYC3M2GUEDMX4AIVWPALDBYJPNK6554BREHTGZ2IUNF", + "function_name": "set_admin", + "args": [ + { + "address": "CAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAD2KM" + } + ] + } + }, + "sub_invocations": [] + } + ] + ], + [], + [ + [ + "CAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAD2KM", + { + "function": { + "contract_fn": { + "contract_address": "CAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAITA4", + "function_name": "configure_sustainability", + "args": [ + { + "address": "CAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAD2KM" + }, + { + "address": "CBUSYNQKASUYFWYC3M2GUEDMX4AIVWPALDBYJPNK6554BREHTGZ2IUNF" + } + ] + } + }, + "sub_invocations": [] + } + ] + ], + [ + [ + "CAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAD2KM", + { + "function": { + "contract_fn": { + "contract_address": "CBUSYNQKASUYFWYC3M2GUEDMX4AIVWPALDBYJPNK6554BREHTGZ2IUNF", + "function_name": "mint", + "args": [ + { + "address": "CAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAK3IM" + }, + { + "i128": "10000000" + } + ] + } + }, + "sub_invocations": [] + } + ] + ], + [ + [ + "CAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAD2KM", + { + "function": { + "contract_fn": { + "contract_address": "CBEPDNVYXQGWB5YUBXKJWYJA7OXTZW5LFLNO5JRRGE6Z6C5OSUZPCCEL", + "function_name": "mint", + "args": [ + { + "address": "CAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAMDR4" + }, + { + "i128": "1000" + } + ] + } + }, + "sub_invocations": [] + } + ] + ], + [ + [ + "CAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAD2KM", + { + "function": { + "contract_fn": { + "contract_address": "CAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAITA4", + "function_name": "set_voting_supply", + "args": [ + { + "address": "CAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAD2KM" + }, + { + "i128": "1000" + } + ] + } + }, + "sub_invocations": [] + } + ] + ], + [ + [ + "CAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAMDR4", + { + "function": { + "contract_fn": { + "contract_address": "CAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAITA4", + "function_name": "propose_maintainer_grant", + "args": [ + { + "address": "CAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAMDR4" + }, + { + "address": "CAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAOLZM" + }, + { + "string": "cargo:soroban-sdk" + }, + { + "i128": "5000" + }, + { + "string": "t" + }, + { + "string": "d" + } + ] + } + }, + "sub_invocations": [] + } + ] + ], + [ + [ + "CAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAMDR4", + { + "function": { + "contract_fn": { + "contract_address": "CAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAITA4", + "function_name": "cast_vote", + "args": [ + { + "address": "CAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAMDR4" + }, + { + "u64": "1" + }, + { + "vec": [ + { + "symbol": "For" + } + ] + } + ] + } + }, + "sub_invocations": [] + } + ] + ], + [], + [], + [], + [], + [ + [ + "CAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAK3IM", + { + "function": { + "contract_fn": { + "contract_address": "CAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAITA4", + "function_name": "collect_sustainability_fee", + "args": [ + { + "address": "CAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAK3IM" + }, + { + "i128": "500000" + } + ] + } + }, + "sub_invocations": [ + { + "function": { + "contract_fn": { + "contract_address": "CBUSYNQKASUYFWYC3M2GUEDMX4AIVWPALDBYJPNK6554BREHTGZ2IUNF", + "function_name": "transfer", + "args": [ + { + "address": "CAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAK3IM" + }, + { + "address": "CAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAITA4" + }, + { + "i128": "5000" + } + ] + } + }, + "sub_invocations": [] + } + ] + } + ] + ], + [], + [] + ], + "ledger": { + "protocol_version": 26, + "sequence_number": 0, + "timestamp": 345601, + "network_id": "0000000000000000000000000000000000000000000000000000000000000000", + "base_reserve": 0, + "min_persistent_entry_ttl": 4096, + "min_temp_entry_ttl": 16, + "max_entry_ttl": 6312000, + "ledger_entries": [ + { + "entry": { + "last_modified_ledger_seq": 0, + "data": { + "account": { + "account_id": "GAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAEGWF", + "balance": "0", + "seq_num": "0", + "num_sub_entries": 0, + "inflation_dest": null, + "flags": 0, + "home_domain": "", + "thresholds": "01010101", + "signers": [], + "ext": "v0" + } + }, + "ext": "v0" + }, + "live_until": null + }, + { + "entry": { + "last_modified_ledger_seq": 0, + "data": { + "account": { + "account_id": "GAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAGO6V", + "balance": "0", + "seq_num": "0", + "num_sub_entries": 0, + "inflation_dest": null, + "flags": 0, + "home_domain": "", + "thresholds": "01010101", + "signers": [], + "ext": "v0" + } + }, + "ext": "v0" + }, + "live_until": null + }, + { + "entry": { + "last_modified_ledger_seq": 0, + "data": { + "contract_data": { + "ext": "v0", + "contract": "GAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAEGWF", + "key": { + "ledger_key_nonce": { + "nonce": "801925984706572462" + } + }, + "durability": "temporary", + "val": "void" + } + }, + "ext": "v0" + }, + "live_until": 6311999 + }, + { + "entry": { + "last_modified_ledger_seq": 0, + "data": { + "contract_data": { + "ext": "v0", + "contract": "GAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAGO6V", + "key": { + "ledger_key_nonce": { + "nonce": "5541220902715666415" + } + }, + "durability": "temporary", + "val": "void" + } + }, + "ext": "v0" + }, + "live_until": 6311999 + }, + { + "entry": { + "last_modified_ledger_seq": 0, + "data": { + "contract_data": { + "ext": "v0", + "contract": "CAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAD2KM", + "key": { + "ledger_key_nonce": { + "nonce": "1033654523790656264" + } + }, + "durability": "temporary", + "val": "void" + } + }, + "ext": "v0" + }, + "live_until": 6311999 + }, + { + "entry": { + "last_modified_ledger_seq": 0, + "data": { + "contract_data": { + "ext": "v0", + "contract": "CAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAD2KM", + "key": { + "ledger_key_nonce": { + "nonce": "2032731177588607455" + } + }, + "durability": "temporary", + "val": "void" + } + }, + "ext": "v0" + }, + "live_until": 6311999 + }, + { + "entry": { + "last_modified_ledger_seq": 0, + "data": { + "contract_data": { + "ext": "v0", + "contract": "CAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAD2KM", + "key": { + "ledger_key_nonce": { + "nonce": "4270020994084947596" + } + }, + "durability": "temporary", + "val": "void" + } + }, + "ext": "v0" + }, + "live_until": 6311999 + }, + { + "entry": { + "last_modified_ledger_seq": 0, + "data": { + "contract_data": { + "ext": "v0", + "contract": "CAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAD2KM", + "key": { + "ledger_key_nonce": { + "nonce": "4837995959683129791" + } + }, + "durability": "temporary", + "val": "void" + } + }, + "ext": "v0" + }, + "live_until": 6311999 + }, + { + "entry": { + "last_modified_ledger_seq": 0, + "data": { + "contract_data": { + "ext": "v0", + "contract": "CAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAITA4", + "key": { + "vec": [ + { + "symbol": "Grant" + }, + { + "u64": "1" + } + ] + }, + "durability": "persistent", + "val": { + "map": [ + { + "key": { + "symbol": "amount" + }, + "val": { + "i128": "5000" + } + }, + { + "key": { + "symbol": "disbursed_at" + }, + "val": { + "u64": "345601" + } + }, + { + "key": { + "symbol": "maintainer" + }, + "val": { + "address": "CAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAOLZM" + } + }, + { + "key": { + "symbol": "package" + }, + "val": { + "string": "cargo:soroban-sdk" + } + }, + { + "key": { + "symbol": "proposal_id" + }, + "val": { + "u64": "1" + } + }, + { + "key": { + "symbol": "status" + }, + "val": { + "vec": [ + { + "symbol": "Disbursed" + } + ] + } + } + ] + } + } + }, + "ext": "v0" + }, + "live_until": 4095 + }, + { + "entry": { + "last_modified_ledger_seq": 0, + "data": { + "contract_data": { + "ext": "v0", + "contract": "CAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAITA4", + "key": { + "vec": [ + { + "symbol": "MaintainerTotal" + }, + { + "address": "CAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAOLZM" + } + ] + }, + "durability": "persistent", + "val": { + "i128": "5000" + } + } + }, + "ext": "v0" + }, + "live_until": 4095 + }, + { + "entry": { + "last_modified_ledger_seq": 0, + "data": { + "contract_data": { + "ext": "v0", + "contract": "CAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAITA4", + "key": { + "vec": [ + { + "symbol": "Proposal" + }, + { + "u64": "1" + } + ] + }, + "durability": "persistent", + "val": { + "map": [ + { + "key": { + "symbol": "abstain_votes" + }, + "val": { + "i128": "0" + } + }, + { + "key": { + "symbol": "against_votes" + }, + "val": { + "i128": "0" + } + }, + { + "key": { + "symbol": "created_at" + }, + "val": { + "u64": "0" + } + }, + { + "key": { + "symbol": "description" + }, + "val": { + "string": "d" + } + }, + { + "key": { + "symbol": "executable_payload" + }, + "val": { + "bytes": "" + } + }, + { + "key": { + "symbol": "for_votes" + }, + "val": { + "i128": "1000" + } + }, + { + "key": { + "symbol": "id" + }, + "val": { + "u64": "1" + } + }, + { + "key": { + "symbol": "proposal_type" + }, + "val": { + "vec": [ + { + "symbol": "FundAllocation" + } + ] + } + }, + { + "key": { + "symbol": "proposer" + }, + "val": { + "address": "CAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAMDR4" + } + }, + { + "key": { + "symbol": "status" + }, + "val": { + "vec": [ + { + "symbol": "Executed" + } + ] + } + }, + { + "key": { + "symbol": "title" + }, + "val": { + "string": "t" + } + }, + { + "key": { + "symbol": "voting_ends" + }, + "val": { + "u64": "259200" + } + }, + { + "key": { + "symbol": "voting_starts" + }, + "val": { + "u64": "0" + } + } + ] + } + } + }, + "ext": "v0" + }, + "live_until": 4095 + }, + { + "entry": { + "last_modified_ledger_seq": 0, + "data": { + "contract_data": { + "ext": "v0", + "contract": "CAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAITA4", + "key": { + "vec": [ + { + "symbol": "TokenSnapshot" + }, + { + "u64": "1" + } + ] + }, + "durability": "persistent", + "val": { + "map": [ + { + "key": { + "symbol": "snapshot_ledger" + }, + "val": { + "u32": 0 + } + }, + { + "key": { + "symbol": "total_supply" + }, + "val": { + "i128": "1000" + } + } + ] + } + } + }, + "ext": "v0" + }, + "live_until": 4095 + }, + { + "entry": { + "last_modified_ledger_seq": 0, + "data": { + "contract_data": { + "ext": "v0", + "contract": "CAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAITA4", + "key": { + "vec": [ + { + "symbol": "TotalSupplyAt" + }, + { + "u64": "1" + } + ] + }, + "durability": "persistent", + "val": { + "i128": "1000" + } + } + }, + "ext": "v0" + }, + "live_until": 4095 + }, + { + "entry": { + "last_modified_ledger_seq": 0, + "data": { + "contract_data": { + "ext": "v0", + "contract": "CAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAITA4", + "key": { + "vec": [ + { + "symbol": "Vote" + }, + { + "u64": "1" + }, + { + "address": "CAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAMDR4" + } + ] + }, + "durability": "persistent", + "val": { + "map": [ + { + "key": { + "symbol": "direction" + }, + "val": { + "vec": [ + { + "symbol": "For" + } + ] + } + }, + { + "key": { + "symbol": "voted_at" + }, + "val": { + "u64": "0" + } + }, + { + "key": { + "symbol": "voter" + }, + "val": { + "address": "CAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAMDR4" + } + }, + { + "key": { + "symbol": "weight" + }, + "val": { + "i128": "1000" + } + } + ] + } + } + }, + "ext": "v0" + }, + "live_until": 4095 + }, + { + "entry": { + "last_modified_ledger_seq": 0, + "data": { + "contract_data": { + "ext": "v0", + "contract": "CAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAITA4", + "key": "ledger_key_contract_instance", + "durability": "persistent", + "val": { + "contract_instance": { + "executable": { + "wasm": "e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855" + }, + "storage": [ + { + "key": { + "symbol": "admin" + }, + "val": { + "address": "CAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAD2KM" + } + }, + { + "key": { + "symbol": "execd" + }, + "val": { + "vec": [ + { + "u64": "1" + } + ] + } + }, + { + "key": { + "symbol": "pcount" + }, + "val": { + "u64": "1" + } + }, + { + "key": { + "symbol": "token" + }, + "val": { + "address": "CBEPDNVYXQGWB5YUBXKJWYJA7OXTZW5LFLNO5JRRGE6Z6C5OSUZPCCEL" + } + }, + { + "key": { + "symbol": "vsupply" + }, + "val": { + "i128": "1000" + } + }, + { + "key": { + "vec": [ + { + "symbol": "Collected" + } + ] + }, + "val": { + "i128": "5000" + } + }, + { + "key": { + "vec": [ + { + "symbol": "Disbursed" + } + ] + }, + "val": { + "i128": "5000" + } + }, + { + "key": { + "vec": [ + { + "symbol": "GrantsDisbursed" + } + ] + }, + "val": { + "u32": 1 + } + }, + { + "key": { + "vec": [ + { + "symbol": "GrantsProposed" + } + ] + }, + "val": { + "u32": 1 + } + }, + { + "key": { + "vec": [ + { + "symbol": "MaintainersFunded" + } + ] + }, + "val": { + "u32": 1 + } + }, + { + "key": { + "vec": [ + { + "symbol": "Reserve" + } + ] + }, + "val": { + "i128": "0" + } + }, + { + "key": { + "vec": [ + { + "symbol": "Token" + } + ] + }, + "val": { + "address": "CBUSYNQKASUYFWYC3M2GUEDMX4AIVWPALDBYJPNK6554BREHTGZ2IUNF" + } + } + ] + } + } + } + }, + "ext": "v0" + }, + "live_until": 4095 + }, + { + "entry": { + "last_modified_ledger_seq": 0, + "data": { + "contract_data": { + "ext": "v0", + "contract": "CAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAK3IM", + "key": { + "ledger_key_nonce": { + "nonce": "5806905060045992000" + } + }, + "durability": "temporary", + "val": "void" + } + }, + "ext": "v0" + }, + "live_until": 6311999 + }, + { + "entry": { + "last_modified_ledger_seq": 0, + "data": { + "contract_data": { + "ext": "v0", + "contract": "CAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAMDR4", + "key": { + "ledger_key_nonce": { + "nonce": "6277191135259896685" + } + }, + "durability": "temporary", + "val": "void" + } + }, + "ext": "v0" + }, + "live_until": 6311999 + }, + { + "entry": { + "last_modified_ledger_seq": 0, + "data": { + "contract_data": { + "ext": "v0", + "contract": "CAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAMDR4", + "key": { + "ledger_key_nonce": { + "nonce": "8370022561469687789" + } + }, + "durability": "temporary", + "val": "void" + } + }, + "ext": "v0" + }, + "live_until": 6311999 + }, + { + "entry": { + "last_modified_ledger_seq": 0, + "data": { + "contract_data": { + "ext": "v0", + "contract": "CBEPDNVYXQGWB5YUBXKJWYJA7OXTZW5LFLNO5JRRGE6Z6C5OSUZPCCEL", + "key": { + "vec": [ + { + "symbol": "Balance" + }, + { + "address": "CAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAMDR4" + } + ] + }, + "durability": "persistent", + "val": { + "map": [ + { + "key": { + "symbol": "amount" + }, + "val": { + "i128": "1000" + } + }, + { + "key": { + "symbol": "authorized" + }, + "val": { + "bool": true + } + }, + { + "key": { + "symbol": "clawback" + }, + "val": { + "bool": false + } + } + ] + } + } + }, + "ext": "v0" + }, + "live_until": 518400 + }, + { + "entry": { + "last_modified_ledger_seq": 0, + "data": { + "contract_data": { + "ext": "v0", + "contract": "CBEPDNVYXQGWB5YUBXKJWYJA7OXTZW5LFLNO5JRRGE6Z6C5OSUZPCCEL", + "key": "ledger_key_contract_instance", + "durability": "persistent", + "val": { + "contract_instance": { + "executable": "stellar_asset", + "storage": [ + { + "key": { + "symbol": "METADATA" + }, + "val": { + "map": [ + { + "key": { + "symbol": "decimal" + }, + "val": { + "u32": 7 + } + }, + { + "key": { + "symbol": "name" + }, + "val": { + "string": "aaa:GAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAEGWF" + } + }, + { + "key": { + "symbol": "symbol" + }, + "val": { + "string": "aaa" + } + } + ] + } + }, + { + "key": { + "vec": [ + { + "symbol": "Admin" + } + ] + }, + "val": { + "address": "CAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAD2KM" + } + }, + { + "key": { + "vec": [ + { + "symbol": "AssetInfo" + } + ] + }, + "val": { + "vec": [ + { + "symbol": "AlphaNum4" + }, + { + "map": [ + { + "key": { + "symbol": "asset_code" + }, + "val": { + "string": "aaa\\0" + } + }, + { + "key": { + "symbol": "issuer" + }, + "val": { + "bytes": "0000000000000000000000000000000000000000000000000000000000000002" + } + } + ] + } + ] + } + } + ] + } + } + } + }, + "ext": "v0" + }, + "live_until": 120960 + }, + { + "entry": { + "last_modified_ledger_seq": 0, + "data": { + "contract_data": { + "ext": "v0", + "contract": "CBUSYNQKASUYFWYC3M2GUEDMX4AIVWPALDBYJPNK6554BREHTGZ2IUNF", + "key": { + "vec": [ + { + "symbol": "Balance" + }, + { + "address": "CAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAITA4" + } + ] + }, + "durability": "persistent", + "val": { + "map": [ + { + "key": { + "symbol": "amount" + }, + "val": { + "i128": "0" + } + }, + { + "key": { + "symbol": "authorized" + }, + "val": { + "bool": true + } + }, + { + "key": { + "symbol": "clawback" + }, + "val": { + "bool": false + } + } + ] + } + } + }, + "ext": "v0" + }, + "live_until": 518400 + }, + { + "entry": { + "last_modified_ledger_seq": 0, + "data": { + "contract_data": { + "ext": "v0", + "contract": "CBUSYNQKASUYFWYC3M2GUEDMX4AIVWPALDBYJPNK6554BREHTGZ2IUNF", + "key": { + "vec": [ + { + "symbol": "Balance" + }, + { + "address": "CAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAK3IM" + } + ] + }, + "durability": "persistent", + "val": { + "map": [ + { + "key": { + "symbol": "amount" + }, + "val": { + "i128": "9995000" + } + }, + { + "key": { + "symbol": "authorized" + }, + "val": { + "bool": true + } + }, + { + "key": { + "symbol": "clawback" + }, + "val": { + "bool": false + } + } + ] + } + } + }, + "ext": "v0" + }, + "live_until": 518400 + }, + { + "entry": { + "last_modified_ledger_seq": 0, + "data": { + "contract_data": { + "ext": "v0", + "contract": "CBUSYNQKASUYFWYC3M2GUEDMX4AIVWPALDBYJPNK6554BREHTGZ2IUNF", + "key": { + "vec": [ + { + "symbol": "Balance" + }, + { + "address": "CAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAOLZM" + } + ] + }, + "durability": "persistent", + "val": { + "map": [ + { + "key": { + "symbol": "amount" + }, + "val": { + "i128": "5000" + } + }, + { + "key": { + "symbol": "authorized" + }, + "val": { + "bool": true + } + }, + { + "key": { + "symbol": "clawback" + }, + "val": { + "bool": false + } + } + ] + } + } + }, + "ext": "v0" + }, + "live_until": 518400 + }, + { + "entry": { + "last_modified_ledger_seq": 0, + "data": { + "contract_data": { + "ext": "v0", + "contract": "CBUSYNQKASUYFWYC3M2GUEDMX4AIVWPALDBYJPNK6554BREHTGZ2IUNF", + "key": "ledger_key_contract_instance", + "durability": "persistent", + "val": { + "contract_instance": { + "executable": "stellar_asset", + "storage": [ + { + "key": { + "symbol": "METADATA" + }, + "val": { + "map": [ + { + "key": { + "symbol": "decimal" + }, + "val": { + "u32": 7 + } + }, + { + "key": { + "symbol": "name" + }, + "val": { + "string": "aaa:GAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAGO6V" + } + }, + { + "key": { + "symbol": "symbol" + }, + "val": { + "string": "aaa" + } + } + ] + } + }, + { + "key": { + "vec": [ + { + "symbol": "Admin" + } + ] + }, + "val": { + "address": "CAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAD2KM" + } + }, + { + "key": { + "vec": [ + { + "symbol": "AssetInfo" + } + ] + }, + "val": { + "vec": [ + { + "symbol": "AlphaNum4" + }, + { + "map": [ + { + "key": { + "symbol": "asset_code" + }, + "val": { + "string": "aaa\\0" + } + }, + { + "key": { + "symbol": "issuer" + }, + "val": { + "bytes": "0000000000000000000000000000000000000000000000000000000000000003" + } + } + ] + } + ] + } + } + ] + } + } + } + }, + "ext": "v0" + }, + "live_until": 120960 + }, + { + "entry": { + "last_modified_ledger_seq": 0, + "data": { + "contract_code": { + "ext": "v0", + "hash": "e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855", + "code": "" + } + }, + "ext": "v0" + }, + "live_until": 4095 + } + ] + }, + "events": [] +} \ No newline at end of file diff --git a/docs/legal-compliance.md b/docs/legal-compliance.md new file mode 100644 index 00000000..52e8be9a --- /dev/null +++ b/docs/legal-compliance.md @@ -0,0 +1,77 @@ +# Legal Compliance: Open Source Licenses + +HelPhone's code is permissively licensed (MIT / Apache-2.0). Any dependency +we ship has to be compatible with that. This page describes the license gate +that enforces it (#586) and what to do when the gate fails. + +## What runs + +| Where | Command | Effect | +| --- | --- | --- | +| CI `supply-chain` job (every PR/push) | `node scripts/license-compliance.js --no-write` | Fails the build on an unapproved copyleft license | +| Release pipeline (`slsa-provenance.yml`) | `npm run build:release` | Writes `dist/licenses.json`, which is covered by the signed digests | +| Locally | `npm run licenses:generate` | Regenerates the committed `licenses.json` | +| Locally | `npm run security:license-gate` | Runs the same check as CI without writing files | + +`scripts/license-compliance.js` has no runtime dependencies. It reads: + +- **npm:** every entry in `package-lock.json`, direct and transitive. The + license comes from the lockfile, or from the installed + `node_modules//package.json` when the lockfile omits it. That is the + same source `license-checker` uses. Workspace links (`server/`) are our own + code and are skipped. +- **Cargo:** `cargo metadata --locked` for the root workspace (`contracts/*`) + and for `contract/`. Only registry and git crates count; path crates are our + own code. + +## Policy + +Each license is evaluated as an SPDX expression. `OR` takes the most +permissive branch, `AND` takes the most restrictive term, and a `WITH` +exception keeps a permissive license approved. + +| Category | Licenses | Gate | +| --- | --- | --- | +| **approved** | MIT, MIT-0, ISC, Apache-2.0, BSD-2/3-Clause, 0BSD, BlueOak-1.0.0, CC0-1.0, CC-BY-3.0/4.0, Unlicense, Zlib, BSL-1.0, Python-2.0, Unicode-3.0, Unicode-DFS-2016, WTFPL | pass | +| **review** | Weak copyleft (LGPL, MPL, EPL, CDDL), `SEE LICENSE IN …`, `UNKNOWN`, anything non-SPDX | warning; fails with `--strict` | +| **denied** | GPL, AGPL, SSPL, EUPL, OSL, RPL, CPAL, Sleepycat, CC-BY-NC/SA/ND | **fails CI** | + +Dev-only dependencies are gated too. Build and test tooling runs in CI and +release infrastructure, and AGPL/SSPL obligations can apply there. + +## Exceptions + +`LICENSE_EXCEPTIONS` in `scripts/license-compliance.js` lists the denied +packages that have been legally reviewed, each with a justification: + +| Package | License | Why it's allowed | +| --- | --- | --- | +| `@lobstrco/signer-extension-api` | GPL-3.0 | Transitive dependency of `@creit-tech/stellar-wallets-kit`. It is a messaging shim to the LOBSTR browser extension. Tracked for replacement (#625). | + +To add an exception: + +1. Get written sign-off from a maintainer who owns legal review. +2. Add `":": ""` to + `LICENSE_EXCEPTIONS`. +3. Run `npm run licenses:generate` and commit the updated `licenses.json` in + the same PR. + +## When the gate fails + +``` +DENIED: npm:some-lib@2.1.0 (AGPL-3.0) +license-compliance: FAIL — 1 copyleft license(s) not approved for this permissive codebase +``` + +1. Find what pulled it in: `npm explain some-lib`, or `cargo tree -i some-lib`. +2. Prefer a permissively licensed alternative, or pin a version released + before the license change. +3. If neither is possible, go through the exception process above. + +## Attribution manifest (`licenses.json`) + +`licenses.json` lists every third-party package with its ecosystem, name, +version, SPDX license, category and repository (when known), plus a summary +and the policy in force. The output is deterministic, with no timestamps, so +diffs show only real dependency changes. `THIRD_PARTY_LICENSES.md` (#625, +npm only) is still the human-readable BOM. diff --git a/docs/security-runbook.md b/docs/security-runbook.md index e7e5b1cf..bdc6e2fc 100644 --- a/docs/security-runbook.md +++ b/docs/security-runbook.md @@ -28,6 +28,102 @@ Covers the typosquatting gate (#588) and the transitive vulnerability scanner (# / `cargo test --locked`; suggested `[patch]` entries go through the same reviewer flow as npm `overrides` — never commit either without review. +## License compliance gate (#586) + +- Script: `scripts/license-compliance.js` scans npm (`package-lock.json`) and + Cargo (`cargo metadata`) licenses and evaluates SPDX expressions. CI fails + on strong copyleft (GPL/AGPL/SSPL/…) that isn't listed in + `LICENSE_EXCEPTIONS`. +- `npm run security:license-gate` runs the same check as CI. + `npm run licenses:generate` regenerates `licenses.json`. +- Policy, exception process and triage: `docs/legal-compliance.md`. + +## CVE patch bot (#599) + +- Script: `scripts/auto-patch-cve.js`. It reads GitHub Security Advisories, + either through `npm audit` (the default, backed by the GitHub Advisory DB) + or the GitHub REST `/advisories?affects=` API (`--source github`). It then + plans the **minimum** fixed version for every vulnerable `name@version` in + the lockfile: the lowest published, non-deprecated, non-prerelease version + that no known advisory matches, preferring the same major. +- Strategy: + - For a direct dependency, the bot bumps the range in `package.json` or + `server/package.json` and keeps the existing `^`/`~` style. + - For a transitive dependency, it writes a root `overrides` floor + (`"pkg": "^fixed"`) when every installed copy is on the fixed major. + Otherwise it writes a version-keyed override (`"pkg@1.2.3": "1.2.4"`) so + copies on other majors stay untouched. + - Fixes that need a major bump are listed for a human. Pass `--allow-major` + to apply them. +- Modes: + - `npm run security:cve-patch` prints the plan only. + - `npm run security:cve-patch:apply` writes the manifests, runs + `npm install`, confirms that the lockfile and `npm audit` no longer report + the patched advisories, then runs every `--verify ` (default + `npm test`). If any step fails, it restores `package.json`, + `server/package.json` and `package-lock.json`. + - `--open-pr` also commits the change on `security/cve-patch-*`, pushes it, + and opens a PR with the advisory table, verification results and the + follow-up list. +- Automation: `.github/workflows/cve-patch-bot.yml` runs weekly and on + manual dispatch. PRs opened with `GITHUB_TOKEN` don't trigger CI, so set a + `CVE_BOT_TOKEN` secret (fine-grained PAT or GitHub App) to get checks on + bot PRs. CI's `supply-chain` job runs the plan in report-only mode and fails + only on critical advisories. +- Triage for a bot PR: + 1. Review the advisory links. + 2. Check that the version moves are patch or minor. + 3. Merge. + 4. Handle "Needs manual follow-up" items as separate PRs, for example a + dependency upgrade that removes the vulnerable package. + +## Maintainer key revocation & web of trust (#619) + +- Script: `scripts/security/verify_maintainer_keys.js`, configured by + `config/maintainer-keys.json`. It verifies OpenPGP signatures on commits + (`--range`), annotated tags (`--tags `) and release artifacts + (`--artifact f --signature f.asc`) in-process. It includes an RFC 4880 + parser and uses node:crypto for RSA, EdDSA and ECDSA, so no gpg is needed. +- Revocation data is live. Keys are fetched from keys.openpgp.org and + keyserver.ubuntu.com, merged, and cached in `.cache/maintainer-keys/` for + `cacheTtlHours`. `--refresh` forces a refetch and `--offline` uses the cache + only. Revocation certificates are verified cryptographically, so a forged + one is ignored. +- Revocation rules (RFC 4880 §5.2.3.23): + + | Reason | Signatures before the revocation | Signatures after | + | --- | --- | --- | + | 0x02 key compromised / 0x00 no reason | **invalid** | invalid | + | 0x01 superseded / 0x03 retired | valid | invalid | + + This is the case the tool exists for. A release signed *before* anyone + discovered that the key was compromised still fails. +- Web of trust: a signer is trusted when it is a `trustedKeys` root, or when + it has at least `minCertifications` valid, unrevoked certifications from a + root. Certifications from a root that was itself revoked as compromised + don't count. The roots are the GitHub web-flow keys, which cover merges made + in the UI; add maintainer keys as the team adopts signing. +- `dependencies[]` pins critical upstream maintainers' key fingerprints + (`{ "name", "fingerprints": [...] }`). `--pinned` checks each key against + the live revocation lists: + - compromised: FAIL (re-verify every release that key signed) + - superseded: WARN (pin the successor key) +- Gates: + - Bad signatures, compromised keys and revoked trusted roots always fail. + - Unsigned, unknown-key, untrusted and SSH-signed objects warn, and fail + under `--strict`. +- Where it runs: + - CI `supply-chain`: PR commit range. + - `verify-keys.yml`: pushes, release tags, and a nightly `--refresh` sweep + of every `v*` tag and all pinned keys. + - `slsa-provenance.yml`: before release builds. Set the repository variable + `REQUIRE_SIGNED_RELEASES=true` to make release tags `--strict`. +- If it fails on a compromised key: + 1. Freeze releases. + 2. Identify every artifact signed by that fingerprint (the `signer` field in + `--json` output). + 3. Rebuild and re-sign them with a fresh key. + 4. Rotate `trustedKeys` / `dependencies[]`. ## Rate-limit whitelist for emergency services (#536) Verified emergency-service callers bypass the API rate limiter. Entries live in @@ -140,4 +236,4 @@ build pipeline runs: dependency installation and `npm run build`. fields. If it is a legitimate build vendor, add it to the allowlist with a reason in the same PR. If it is not explainable, treat the dependency as compromised: do not publish the artifact, pin the previous version, rotate - any secrets present in the build environment, and report upstream. + any secrets present in the build environment, and report upstream. \ No newline at end of file diff --git a/licenses.json b/licenses.json index dd70dc23..9ba7a27f 100644 --- a/licenses.json +++ b/licenses.json @@ -1,9736 +1,12408 @@ { - "generatedBy": "scripts/audit-deps.js (#540)", + "$comment": "Auto-generated by scripts/license-compliance.js (#586). Do not edit by hand; run `npm run licenses:generate`.", "policy": { - "approved": "MIT, Apache-2.0, BSD-*, ISC (and equivalent permissives)", - "denied": "GPL, AGPL, SSPL, EUPL, OSL, CPAL, RPL unless in EXCEPTIONS" + "projectLicenses": [ + "MIT", + "Apache-2.0" + ], + "approved": [ + "0BSD", + "Apache-2.0", + "BSD-2-Clause", + "BSD-3-Clause", + "BSL-1.0", + "BlueOak-1.0.0", + "CC-BY-3.0", + "CC-BY-4.0", + "CC0-1.0", + "ISC", + "MIT", + "MIT-0", + "Python-2.0", + "Unicode-3.0", + "Unicode-DFS-2016", + "Unlicense", + "WTFPL", + "Zlib" + ], + "denied": "strong/network copyleft: GPL, AGPL, SSPL, EUPL, OSL, RPL, CPAL, Sleepycat, CC-BY-NC/SA/ND", + "review": "weak copyleft (LGPL, MPL, EPL, CDDL) and unrecognised licenses", + "exceptions": { + "npm:@lobstrco/signer-extension-api": "GPL-3.0 via @creit-tech/stellar-wallets-kit; browser-extension messaging shim, tracked for replacement (#625)" + } }, "summary": { - "total": 1388, - "approved": 1337, - "review": 50, + "total": 1466, + "npm": 1181, + "cargo": 285, + "approved": 1421, + "review": 44, "excepted": 1, - "denied": 0 - }, - "exceptions": { - "node_modules/@lobstrco/signer-extension-api": "GPL-3.0 via stellar-wallets-kit transitive; tracked for replacement", - "node_modules/rpc-websockets": "LGPL-3.0-only transitive; review on next major bump" + "denied": 0, + "byLicense": { + "(Apache-2.0 AND BSD-3-Clause)": 1, + "(Apache-2.0 AND MIT)": 1, + "(MIT AND Zlib)": 1, + "(MIT OR Apache-2.0)": 3, + "(MIT OR Apache-2.0) AND Unicode-3.0": 2, + "(MIT OR CC0-1.0)": 2, + "0BSD": 2, + "Apache-2.0": 103, + "Apache-2.0 / MIT": 1, + "Apache-2.0 OR MIT": 31, + "Apache-2.0 WITH LLVM-exception": 2, + "Apache-2.0 WITH LLVM-exception OR Apache-2.0 OR MIT": 1, + "BlueOak-1.0.0": 8, + "BSD-2-Clause": 13, + "BSD-2-Clause OR Apache-2.0 OR MIT": 4, + "BSD-3-Clause": 31, + "CC-BY-4.0": 1, + "CC0-1.0": 1, + "GPL-3.0": 1, + "ISC": 52, + "LGPL-3.0-only": 1, + "MIT": 970, + "MIT OR Apache-2.0": 145, + "MIT OR Apache-2.0 OR BSD-1-Clause": 2, + "MIT OR Apache-2.0 OR Zlib": 1, + "MIT-0": 2, + "MIT/Apache-2.0": 26, + "MPL-2.0": 15, + "Python-2.0": 1, + "SEE LICENSE IN LICENSE.md": 20, + "SEE LICENSE IN LICENSE.txt": 1, + "UNKNOWN": 7, + "Unlicense": 2, + "Unlicense OR MIT": 8, + "Zlib OR Apache-2.0 OR MIT": 2, + "Zlib OR MIT OR Apache-2.0": 2 + } }, "packages": [ { - "lock": "package-lock.json", - "path": "node_modules/@adobe/css-tools", - "version": "4.5.0", - "license": "MIT", - "status": "approved" + "ecosystem": "cargo", + "name": "ahash", + "version": "0.8.12", + "license": "MIT OR Apache-2.0", + "category": "approved", + "repository": "https://github.com/tkaitchuck/ahash" }, { - "lock": "package-lock.json", - "path": "node_modules/@adraffy/ens-normalize", - "version": "1.11.1", - "license": "MIT", - "status": "approved" + "ecosystem": "cargo", + "name": "allocator-api2", + "version": "0.2.21", + "license": "MIT OR Apache-2.0", + "category": "approved", + "repository": "https://github.com/zakarumych/allocator-api2" }, { - "lock": "package-lock.json", - "path": "node_modules/@albedo-link/intent", - "version": "0.12.0", - "license": "MIT", - "status": "approved" + "ecosystem": "cargo", + "name": "android_system_properties", + "version": "0.1.5", + "license": "MIT/Apache-2.0", + "category": "approved", + "repository": "https://github.com/nical/android_system_properties" }, { - "lock": "package-lock.json", - "path": "node_modules/@apideck/better-ajv-errors", - "version": "0.3.7", - "license": "MIT", - "status": "approved" + "ecosystem": "cargo", + "name": "android_system_properties", + "version": "0.1.6", + "license": "MIT OR Apache-2.0", + "category": "approved", + "repository": "https://github.com/nical/android_system_properties" }, { - "lock": "package-lock.json", - "path": "node_modules/@asamuzakjp/css-color", - "version": "5.1.11", - "license": "MIT", - "status": "approved" + "ecosystem": "cargo", + "name": "arbitrary", + "version": "1.3.2", + "license": "MIT OR Apache-2.0", + "category": "approved", + "repository": "https://github.com/rust-fuzz/arbitrary/" }, { - "lock": "package-lock.json", - "path": "node_modules/@asamuzakjp/dom-selector", - "version": "7.1.1", - "license": "MIT", - "status": "approved" + "ecosystem": "cargo", + "name": "ark-bls12-381", + "version": "0.4.0", + "license": "MIT/Apache-2.0", + "category": "approved", + "repository": "https://github.com/arkworks-rs/curves" }, { - "lock": "package-lock.json", - "path": "node_modules/@asamuzakjp/generational-cache", - "version": "1.0.1", - "license": "MIT", - "status": "approved" + "ecosystem": "cargo", + "name": "ark-bls12-381", + "version": "0.5.0", + "license": "MIT OR Apache-2.0", + "category": "approved", + "repository": "https://github.com/arkworks-rs/algebra" }, { - "lock": "package-lock.json", - "path": "node_modules/@asamuzakjp/nwsapi", - "version": "2.3.9", - "license": "MIT", - "status": "approved" + "ecosystem": "cargo", + "name": "ark-bn254", + "version": "0.4.0", + "license": "MIT/Apache-2.0", + "category": "approved", + "repository": "https://github.com/arkworks-rs/curves" }, { - "lock": "package-lock.json", - "path": "node_modules/@aztec/bb.js", - "version": "0.87.9", - "license": "MIT", - "status": "approved" + "ecosystem": "cargo", + "name": "ark-bn254", + "version": "0.5.0", + "license": "MIT OR Apache-2.0", + "category": "approved", + "repository": "https://github.com/arkworks-rs/algebra" }, { - "lock": "package-lock.json", - "path": "node_modules/@aztec/bb.js/node_modules/commander", - "version": "12.1.0", - "license": "MIT", - "status": "approved" + "ecosystem": "cargo", + "name": "ark-ec", + "version": "0.4.2", + "license": "MIT/Apache-2.0", + "category": "approved", + "repository": "https://github.com/arkworks-rs/algebra" }, { - "lock": "package-lock.json", - "path": "node_modules/@aztec/bb.js/node_modules/pino", - "version": "9.14.0", - "license": "MIT", - "status": "approved" + "ecosystem": "cargo", + "name": "ark-ec", + "version": "0.5.0", + "license": "MIT OR Apache-2.0", + "category": "approved", + "repository": "https://github.com/arkworks-rs/algebra" }, { - "lock": "package-lock.json", - "path": "node_modules/@babel/code-frame", - "version": "7.29.7", - "license": "MIT", - "status": "approved" + "ecosystem": "cargo", + "name": "ark-ff", + "version": "0.4.2", + "license": "MIT/Apache-2.0", + "category": "approved", + "repository": "https://github.com/arkworks-rs/algebra" }, { - "lock": "package-lock.json", - "path": "node_modules/@babel/compat-data", - "version": "7.29.7", - "license": "MIT", - "status": "approved" + "ecosystem": "cargo", + "name": "ark-ff", + "version": "0.5.0", + "license": "MIT OR Apache-2.0", + "category": "approved", + "repository": "https://github.com/arkworks-rs/algebra" }, { - "lock": "package-lock.json", - "path": "node_modules/@babel/core", - "version": "7.29.7", - "license": "MIT", - "status": "approved" + "ecosystem": "cargo", + "name": "ark-ff-asm", + "version": "0.4.2", + "license": "MIT/Apache-2.0", + "category": "approved", + "repository": "https://github.com/arkworks-rs/algebra" }, { - "lock": "package-lock.json", - "path": "node_modules/@babel/core/node_modules/semver", - "version": "6.3.1", - "license": "ISC", - "status": "approved" + "ecosystem": "cargo", + "name": "ark-ff-asm", + "version": "0.5.0", + "license": "MIT OR Apache-2.0", + "category": "approved", + "repository": "https://github.com/arkworks-rs/algebra" }, { - "lock": "package-lock.json", - "path": "node_modules/@babel/generator", - "version": "7.29.8", - "license": "MIT", - "status": "approved" + "ecosystem": "cargo", + "name": "ark-ff-macros", + "version": "0.4.2", + "license": "MIT/Apache-2.0", + "category": "approved", + "repository": "https://github.com/arkworks-rs/algebra" }, { - "lock": "package-lock.json", - "path": "node_modules/@babel/helper-annotate-as-pure", - "version": "7.29.7", - "license": "MIT", - "status": "approved" + "ecosystem": "cargo", + "name": "ark-ff-macros", + "version": "0.5.0", + "license": "MIT OR Apache-2.0", + "category": "approved", + "repository": "https://github.com/arkworks-rs/algebra" }, { - "lock": "package-lock.json", - "path": "node_modules/@babel/helper-compilation-targets", - "version": "7.29.7", - "license": "MIT", - "status": "approved" + "ecosystem": "cargo", + "name": "ark-poly", + "version": "0.4.2", + "license": "MIT/Apache-2.0", + "category": "approved", + "repository": "https://github.com/arkworks-rs/algebra" }, { - "lock": "package-lock.json", - "path": "node_modules/@babel/helper-compilation-targets/node_modules/lru-cache", - "version": "5.1.1", - "license": "ISC", - "status": "approved" + "ecosystem": "cargo", + "name": "ark-poly", + "version": "0.5.0", + "license": "MIT OR Apache-2.0", + "category": "approved", + "repository": "https://github.com/arkworks-rs/algebra" }, { - "lock": "package-lock.json", - "path": "node_modules/@babel/helper-compilation-targets/node_modules/semver", - "version": "6.3.1", - "license": "ISC", - "status": "approved" + "ecosystem": "cargo", + "name": "ark-serialize", + "version": "0.4.2", + "license": "MIT/Apache-2.0", + "category": "approved", + "repository": "https://github.com/arkworks-rs/algebra" }, { - "lock": "package-lock.json", - "path": "node_modules/@babel/helper-create-class-features-plugin", - "version": "7.29.7", - "license": "MIT", - "status": "approved" + "ecosystem": "cargo", + "name": "ark-serialize", + "version": "0.5.0", + "license": "MIT OR Apache-2.0", + "category": "approved", + "repository": "https://github.com/arkworks-rs/algebra" }, { - "lock": "package-lock.json", - "path": "node_modules/@babel/helper-create-class-features-plugin/node_modules/semver", - "version": "6.3.1", - "license": "ISC", - "status": "approved" + "ecosystem": "cargo", + "name": "ark-serialize-derive", + "version": "0.4.2", + "license": "MIT/Apache-2.0", + "category": "approved", + "repository": "https://github.com/arkworks-rs/algebra" }, { - "lock": "package-lock.json", - "path": "node_modules/@babel/helper-create-regexp-features-plugin", - "version": "7.29.7", - "license": "MIT", - "status": "approved" + "ecosystem": "cargo", + "name": "ark-serialize-derive", + "version": "0.5.0", + "license": "MIT OR Apache-2.0", + "category": "approved", + "repository": "https://github.com/arkworks-rs/algebra" }, { - "lock": "package-lock.json", - "path": "node_modules/@babel/helper-create-regexp-features-plugin/node_modules/semver", - "version": "6.3.1", - "license": "ISC", - "status": "approved" + "ecosystem": "cargo", + "name": "ark-std", + "version": "0.4.0", + "license": "MIT/Apache-2.0", + "category": "approved", + "repository": "https://github.com/arkworks-rs/std" }, { - "lock": "package-lock.json", - "path": "node_modules/@babel/helper-define-polyfill-provider", - "version": "0.6.8", - "license": "MIT", - "status": "approved" + "ecosystem": "cargo", + "name": "ark-std", + "version": "0.5.0", + "license": "MIT/Apache-2.0", + "category": "approved", + "repository": "https://github.com/arkworks-rs/std" }, { - "lock": "package-lock.json", - "path": "node_modules/@babel/helper-globals", - "version": "7.29.7", - "license": "MIT", - "status": "approved" + "ecosystem": "cargo", + "name": "arrayvec", + "version": "0.7.8", + "license": "MIT OR Apache-2.0", + "category": "approved", + "repository": "https://github.com/bluss/arrayvec" }, { - "lock": "package-lock.json", - "path": "node_modules/@babel/helper-member-expression-to-functions", - "version": "7.29.7", - "license": "MIT", - "status": "approved" + "ecosystem": "cargo", + "name": "autocfg", + "version": "1.5.1", + "license": "Apache-2.0 OR MIT", + "category": "approved", + "repository": "https://github.com/cuviper/autocfg" }, { - "lock": "package-lock.json", - "path": "node_modules/@babel/helper-module-imports", - "version": "7.29.7", - "license": "MIT", - "status": "approved" + "ecosystem": "cargo", + "name": "base16ct", + "version": "0.2.0", + "license": "Apache-2.0 OR MIT", + "category": "approved", + "repository": "https://github.com/RustCrypto/formats/tree/master/base16ct" }, { - "lock": "package-lock.json", - "path": "node_modules/@babel/helper-module-transforms", - "version": "7.29.7", - "license": "MIT", - "status": "approved" + "ecosystem": "cargo", + "name": "base64", + "version": "0.22.1", + "license": "MIT OR Apache-2.0", + "category": "approved", + "repository": "https://github.com/marshallpierce/rust-base64" }, { - "lock": "package-lock.json", - "path": "node_modules/@babel/helper-optimise-call-expression", - "version": "7.29.7", - "license": "MIT", - "status": "approved" + "ecosystem": "cargo", + "name": "base64", + "version": "0.23.1", + "license": "MIT OR Apache-2.0", + "category": "approved", + "repository": "https://github.com/marshallpierce/rust-base64" }, { - "lock": "package-lock.json", - "path": "node_modules/@babel/helper-plugin-utils", - "version": "7.29.7", - "license": "MIT", - "status": "approved" + "ecosystem": "cargo", + "name": "base64ct", + "version": "1.8.3", + "license": "Apache-2.0 OR MIT", + "category": "approved", + "repository": "https://github.com/RustCrypto/formats" }, { - "lock": "package-lock.json", - "path": "node_modules/@babel/helper-remap-async-to-generator", - "version": "7.29.7", - "license": "MIT", - "status": "approved" + "ecosystem": "cargo", + "name": "bitflags", + "version": "1.3.2", + "license": "MIT/Apache-2.0", + "category": "approved", + "repository": "https://github.com/bitflags/bitflags" }, { - "lock": "package-lock.json", - "path": "node_modules/@babel/helper-replace-supers", - "version": "7.29.7", - "license": "MIT", - "status": "approved" + "ecosystem": "cargo", + "name": "block-buffer", + "version": "0.10.4", + "license": "MIT OR Apache-2.0", + "category": "approved", + "repository": "https://github.com/RustCrypto/utils" }, { - "lock": "package-lock.json", - "path": "node_modules/@babel/helper-skip-transparent-expression-wrappers", - "version": "7.29.7", - "license": "MIT", - "status": "approved" + "ecosystem": "cargo", + "name": "block-buffer", + "version": "0.12.1", + "license": "MIT OR Apache-2.0", + "category": "approved", + "repository": "https://github.com/RustCrypto/utils" }, { - "lock": "package-lock.json", - "path": "node_modules/@babel/helper-string-parser", - "version": "7.29.7", - "license": "MIT", - "status": "approved" + "ecosystem": "cargo", + "name": "bs58", + "version": "0.5.1", + "license": "MIT/Apache-2.0", + "category": "approved", + "repository": "https://github.com/Nullus157/bs58-rs" }, { - "lock": "package-lock.json", - "path": "node_modules/@babel/helper-validator-identifier", - "version": "7.29.7", - "license": "MIT", - "status": "approved" + "ecosystem": "cargo", + "name": "bumpalo", + "version": "3.20.3", + "license": "MIT OR Apache-2.0", + "category": "approved", + "repository": "https://github.com/fitzgen/bumpalo" }, { - "lock": "package-lock.json", - "path": "node_modules/@babel/helper-validator-option", - "version": "7.29.7", - "license": "MIT", - "status": "approved" + "ecosystem": "cargo", + "name": "byteorder", + "version": "1.5.0", + "license": "Unlicense OR MIT", + "category": "approved", + "repository": "https://github.com/BurntSushi/byteorder" }, { - "lock": "package-lock.json", - "path": "node_modules/@babel/helper-wrap-function", - "version": "7.29.7", - "license": "MIT", - "status": "approved" + "ecosystem": "cargo", + "name": "bytes-lit", + "version": "0.0.5", + "license": "Apache-2.0", + "category": "approved", + "repository": "https://github.com/stellar/bytes-lit" }, { - "lock": "package-lock.json", - "path": "node_modules/@babel/helpers", - "version": "7.29.7", - "license": "MIT", - "status": "approved" + "ecosystem": "cargo", + "name": "cc", + "version": "1.2.65", + "license": "MIT OR Apache-2.0", + "category": "approved", + "repository": "https://github.com/rust-lang/cc-rs" }, { - "lock": "package-lock.json", - "path": "node_modules/@babel/parser", - "version": "7.29.9", - "license": "MIT", - "status": "approved" + "ecosystem": "cargo", + "name": "cc", + "version": "1.4.7", + "license": "MIT OR Apache-2.0", + "category": "approved", + "repository": "https://github.com/rust-lang/cc-rs" }, { - "lock": "package-lock.json", - "path": "node_modules/@babel/plugin-bugfix-firefox-class-in-computed-class-key", - "version": "7.29.7", - "license": "MIT", - "status": "approved" + "ecosystem": "cargo", + "name": "cfg_eval", + "version": "0.1.2", + "license": "Zlib OR MIT OR Apache-2.0", + "category": "approved", + "repository": "https://github.com/danielhenrymantilla/cfg_eval.rs" }, { - "lock": "package-lock.json", - "path": "node_modules/@babel/plugin-bugfix-safari-class-field-initializer-scope", - "version": "7.29.7", - "license": "MIT", - "status": "approved" + "ecosystem": "cargo", + "name": "cfg-if", + "version": "1.0.4", + "license": "MIT OR Apache-2.0", + "category": "approved", + "repository": "https://github.com/rust-lang/cfg-if" }, { - "lock": "package-lock.json", - "path": "node_modules/@babel/plugin-bugfix-safari-id-destructuring-collision-in-function-expression", - "version": "7.29.7", - "license": "MIT", - "status": "approved" + "ecosystem": "cargo", + "name": "cfg-if", + "version": "1.0.5", + "license": "MIT OR Apache-2.0", + "category": "approved", + "repository": "https://github.com/rust-lang/cfg-if" }, { - "lock": "package-lock.json", - "path": "node_modules/@babel/plugin-bugfix-safari-rest-destructuring-rhs-array", - "version": "7.29.7", - "license": "MIT", - "status": "approved" + "ecosystem": "cargo", + "name": "chrono", + "version": "0.4.45", + "license": "MIT OR Apache-2.0", + "category": "approved", + "repository": "https://github.com/chronotope/chrono" }, { - "lock": "package-lock.json", - "path": "node_modules/@babel/plugin-bugfix-v8-spread-parameters-in-optional-chaining", - "version": "7.29.7", - "license": "MIT", - "status": "approved" + "ecosystem": "cargo", + "name": "const-oid", + "version": "0.9.6", + "license": "Apache-2.0 OR MIT", + "category": "approved", + "repository": "https://github.com/RustCrypto/formats/tree/master/const-oid" }, { - "lock": "package-lock.json", - "path": "node_modules/@babel/plugin-bugfix-v8-static-class-fields-redefine-readonly", - "version": "7.29.7", - "license": "MIT", - "status": "approved" + "ecosystem": "cargo", + "name": "core-foundation-sys", + "version": "0.8.7", + "license": "MIT OR Apache-2.0", + "category": "approved", + "repository": "https://github.com/servo/core-foundation-rs" }, { - "lock": "package-lock.json", - "path": "node_modules/@babel/plugin-proposal-private-property-in-object", - "version": "7.21.0-placeholder-for-preset-env.2", - "license": "MIT", - "status": "approved" + "ecosystem": "cargo", + "name": "cpufeatures", + "version": "0.2.17", + "license": "MIT OR Apache-2.0", + "category": "approved", + "repository": "https://github.com/RustCrypto/utils" }, { - "lock": "package-lock.json", - "path": "node_modules/@babel/plugin-syntax-import-assertions", - "version": "7.29.7", - "license": "MIT", - "status": "approved" + "ecosystem": "cargo", + "name": "cpufeatures", + "version": "0.3.1", + "license": "MIT OR Apache-2.0", + "category": "approved", + "repository": "https://github.com/RustCrypto/utils" }, { - "lock": "package-lock.json", - "path": "node_modules/@babel/plugin-syntax-import-attributes", - "version": "7.29.7", - "license": "MIT", - "status": "approved" + "ecosystem": "cargo", + "name": "crate-git-revision", + "version": "0.0.6", + "license": "Apache-2.0", + "category": "approved", + "repository": "https://github.com/stellar/crate-git-revision" }, { - "lock": "package-lock.json", - "path": "node_modules/@babel/plugin-syntax-unicode-sets-regex", - "version": "7.18.6", - "license": "MIT", - "status": "approved" + "ecosystem": "cargo", + "name": "crypto-bigint", + "version": "0.5.5", + "license": "Apache-2.0 OR MIT", + "category": "approved", + "repository": "https://github.com/RustCrypto/crypto-bigint" }, { - "lock": "package-lock.json", - "path": "node_modules/@babel/plugin-transform-arrow-functions", - "version": "7.29.7", - "license": "MIT", - "status": "approved" + "ecosystem": "cargo", + "name": "crypto-common", + "version": "0.1.6", + "license": "MIT OR Apache-2.0", + "category": "approved", + "repository": "https://github.com/RustCrypto/traits" }, { - "lock": "package-lock.json", - "path": "node_modules/@babel/plugin-transform-async-generator-functions", - "version": "7.29.7", - "license": "MIT", - "status": "approved" + "ecosystem": "cargo", + "name": "crypto-common", + "version": "0.2.2", + "license": "MIT OR Apache-2.0", + "category": "approved", + "repository": "https://github.com/RustCrypto/traits" }, { - "lock": "package-lock.json", - "path": "node_modules/@babel/plugin-transform-async-to-generator", - "version": "7.29.7", - "license": "MIT", - "status": "approved" + "ecosystem": "cargo", + "name": "ctor", + "version": "0.5.0", + "license": "Apache-2.0 OR MIT", + "category": "approved", + "repository": "https://github.com/mmastrac/rust-ctor" }, { - "lock": "package-lock.json", - "path": "node_modules/@babel/plugin-transform-block-scoped-functions", - "version": "7.29.7", - "license": "MIT", - "status": "approved" + "ecosystem": "cargo", + "name": "ctor-proc-macro", + "version": "0.0.6", + "license": "Apache-2.0 OR MIT", + "category": "approved", + "repository": "https://github.com/mmastrac/rust-ctor" }, { - "lock": "package-lock.json", - "path": "node_modules/@babel/plugin-transform-block-scoping", - "version": "7.29.7", - "license": "MIT", - "status": "approved" + "ecosystem": "cargo", + "name": "curve25519-dalek", + "version": "4.1.3", + "license": "BSD-3-Clause", + "category": "approved", + "repository": "https://github.com/dalek-cryptography/curve25519-dalek/tree/main/curve25519-dalek" }, { - "lock": "package-lock.json", - "path": "node_modules/@babel/plugin-transform-class-properties", - "version": "7.29.7", - "license": "MIT", - "status": "approved" + "ecosystem": "cargo", + "name": "curve25519-dalek", + "version": "5.0.0", + "license": "BSD-3-Clause", + "category": "approved", + "repository": "https://github.com/dalek-cryptography/curve25519-dalek/tree/main/curve25519-dalek" }, { - "lock": "package-lock.json", - "path": "node_modules/@babel/plugin-transform-class-static-block", - "version": "7.29.7", - "license": "MIT", - "status": "approved" + "ecosystem": "cargo", + "name": "curve25519-dalek-derive", + "version": "0.1.1", + "license": "MIT/Apache-2.0", + "category": "approved", + "repository": "https://github.com/dalek-cryptography/curve25519-dalek" }, { - "lock": "package-lock.json", - "path": "node_modules/@babel/plugin-transform-classes", - "version": "7.29.7", + "ecosystem": "cargo", + "name": "darling", + "version": "0.20.11", "license": "MIT", - "status": "approved" + "category": "approved", + "repository": "https://github.com/TedDriggs/darling" }, { - "lock": "package-lock.json", - "path": "node_modules/@babel/plugin-transform-computed-properties", - "version": "7.29.7", + "ecosystem": "cargo", + "name": "darling", + "version": "0.23.0", "license": "MIT", - "status": "approved" + "category": "approved", + "repository": "https://github.com/TedDriggs/darling" }, { - "lock": "package-lock.json", - "path": "node_modules/@babel/plugin-transform-destructuring", - "version": "7.29.7", + "ecosystem": "cargo", + "name": "darling", + "version": "0.24.1", "license": "MIT", - "status": "approved" + "category": "approved", + "repository": "https://github.com/TedDriggs/darling" }, { - "lock": "package-lock.json", - "path": "node_modules/@babel/plugin-transform-dotall-regex", - "version": "7.29.7", + "ecosystem": "cargo", + "name": "darling_core", + "version": "0.20.11", "license": "MIT", - "status": "approved" + "category": "approved", + "repository": "https://github.com/TedDriggs/darling" }, { - "lock": "package-lock.json", - "path": "node_modules/@babel/plugin-transform-duplicate-keys", - "version": "7.29.7", + "ecosystem": "cargo", + "name": "darling_core", + "version": "0.23.0", "license": "MIT", - "status": "approved" + "category": "approved", + "repository": "https://github.com/TedDriggs/darling" }, { - "lock": "package-lock.json", - "path": "node_modules/@babel/plugin-transform-duplicate-named-capturing-groups-regex", - "version": "7.29.7", + "ecosystem": "cargo", + "name": "darling_core", + "version": "0.24.1", "license": "MIT", - "status": "approved" + "category": "approved", + "repository": "https://github.com/TedDriggs/darling" }, { - "lock": "package-lock.json", - "path": "node_modules/@babel/plugin-transform-dynamic-import", - "version": "7.29.7", + "ecosystem": "cargo", + "name": "darling_macro", + "version": "0.20.11", "license": "MIT", - "status": "approved" + "category": "approved", + "repository": "https://github.com/TedDriggs/darling" }, { - "lock": "package-lock.json", - "path": "node_modules/@babel/plugin-transform-explicit-resource-management", - "version": "7.29.7", + "ecosystem": "cargo", + "name": "darling_macro", + "version": "0.23.0", "license": "MIT", - "status": "approved" + "category": "approved", + "repository": "https://github.com/TedDriggs/darling" }, { - "lock": "package-lock.json", - "path": "node_modules/@babel/plugin-transform-exponentiation-operator", - "version": "7.29.7", + "ecosystem": "cargo", + "name": "darling_macro", + "version": "0.24.1", "license": "MIT", - "status": "approved" + "category": "approved", + "repository": "https://github.com/TedDriggs/darling" }, { - "lock": "package-lock.json", - "path": "node_modules/@babel/plugin-transform-export-namespace-from", - "version": "7.29.7", + "ecosystem": "cargo", + "name": "data-encoding", + "version": "2.11.0", "license": "MIT", - "status": "approved" + "category": "approved", + "repository": "https://github.com/ia0/data-encoding" }, { - "lock": "package-lock.json", - "path": "node_modules/@babel/plugin-transform-for-of", - "version": "7.29.7", + "ecosystem": "cargo", + "name": "data-encoding", + "version": "2.11.1", "license": "MIT", - "status": "approved" + "category": "approved", + "repository": "https://github.com/ia0/data-encoding" }, { - "lock": "package-lock.json", - "path": "node_modules/@babel/plugin-transform-function-name", - "version": "7.29.7", - "license": "MIT", - "status": "approved" + "ecosystem": "cargo", + "name": "defmt", + "version": "1.1.1", + "license": "MIT OR Apache-2.0", + "category": "approved", + "repository": "https://github.com/knurling-rs/defmt" }, { - "lock": "package-lock.json", - "path": "node_modules/@babel/plugin-transform-json-strings", - "version": "7.29.7", - "license": "MIT", - "status": "approved" + "ecosystem": "cargo", + "name": "defmt-macros", + "version": "1.1.1", + "license": "MIT OR Apache-2.0", + "category": "approved", + "repository": "https://github.com/knurling-rs/defmt" }, { - "lock": "package-lock.json", - "path": "node_modules/@babel/plugin-transform-literals", - "version": "7.29.7", - "license": "MIT", - "status": "approved" + "ecosystem": "cargo", + "name": "defmt-parser", + "version": "1.0.0", + "license": "MIT OR Apache-2.0", + "category": "approved", + "repository": "https://github.com/knurling-rs/defmt" }, { - "lock": "package-lock.json", - "path": "node_modules/@babel/plugin-transform-logical-assignment-operators", - "version": "7.29.7", - "license": "MIT", - "status": "approved" + "ecosystem": "cargo", + "name": "der", + "version": "0.7.10", + "license": "Apache-2.0 OR MIT", + "category": "approved", + "repository": "https://github.com/RustCrypto/formats/tree/master/der" }, { - "lock": "package-lock.json", - "path": "node_modules/@babel/plugin-transform-member-expression-literals", - "version": "7.29.7", - "license": "MIT", - "status": "approved" + "ecosystem": "cargo", + "name": "deranged", + "version": "0.5.8", + "license": "MIT OR Apache-2.0", + "category": "approved", + "repository": "https://github.com/jhpratt/deranged" }, { - "lock": "package-lock.json", - "path": "node_modules/@babel/plugin-transform-modules-amd", - "version": "7.29.7", - "license": "MIT", - "status": "approved" + "ecosystem": "cargo", + "name": "derivative", + "version": "2.2.0", + "license": "MIT/Apache-2.0", + "category": "approved", + "repository": "https://github.com/mcarton/rust-derivative" }, { - "lock": "package-lock.json", - "path": "node_modules/@babel/plugin-transform-modules-commonjs", - "version": "7.29.7", - "license": "MIT", - "status": "approved" + "ecosystem": "cargo", + "name": "derive_arbitrary", + "version": "1.3.2", + "license": "MIT/Apache-2.0", + "category": "approved", + "repository": "https://github.com/rust-fuzz/arbitrary" }, { - "lock": "package-lock.json", - "path": "node_modules/@babel/plugin-transform-modules-systemjs", - "version": "7.29.8", - "license": "MIT", - "status": "approved" + "ecosystem": "cargo", + "name": "digest", + "version": "0.10.7", + "license": "MIT OR Apache-2.0", + "category": "approved", + "repository": "https://github.com/RustCrypto/traits" }, { - "lock": "package-lock.json", - "path": "node_modules/@babel/plugin-transform-modules-umd", - "version": "7.29.7", - "license": "MIT", - "status": "approved" + "ecosystem": "cargo", + "name": "digest", + "version": "0.11.3", + "license": "MIT OR Apache-2.0", + "category": "approved", + "repository": "https://github.com/RustCrypto/traits" }, { - "lock": "package-lock.json", - "path": "node_modules/@babel/plugin-transform-named-capturing-groups-regex", - "version": "7.29.7", - "license": "MIT", - "status": "approved" + "ecosystem": "cargo", + "name": "downcast-rs", + "version": "1.2.1", + "license": "MIT/Apache-2.0", + "category": "approved", + "repository": "https://github.com/marcianx/downcast-rs" }, { - "lock": "package-lock.json", - "path": "node_modules/@babel/plugin-transform-new-target", - "version": "7.29.7", - "license": "MIT", - "status": "approved" + "ecosystem": "cargo", + "name": "dtor", + "version": "0.1.1", + "license": "Apache-2.0 OR MIT", + "category": "approved", + "repository": "https://github.com/mmastrac/rust-ctor" }, { - "lock": "package-lock.json", - "path": "node_modules/@babel/plugin-transform-nullish-coalescing-operator", - "version": "7.29.7", - "license": "MIT", - "status": "approved" + "ecosystem": "cargo", + "name": "dtor-proc-macro", + "version": "0.0.6", + "license": "Apache-2.0 OR MIT", + "category": "approved", + "repository": "https://github.com/mmastrac/rust-ctor" }, { - "lock": "package-lock.json", - "path": "node_modules/@babel/plugin-transform-numeric-separator", - "version": "7.29.7", - "license": "MIT", - "status": "approved" + "ecosystem": "cargo", + "name": "dyn-clone", + "version": "1.0.20", + "license": "MIT OR Apache-2.0", + "category": "approved", + "repository": "https://github.com/dtolnay/dyn-clone" }, { - "lock": "package-lock.json", - "path": "node_modules/@babel/plugin-transform-object-rest-spread", - "version": "7.29.7", - "license": "MIT", - "status": "approved" + "ecosystem": "cargo", + "name": "ecdsa", + "version": "0.16.9", + "license": "Apache-2.0 OR MIT", + "category": "approved", + "repository": "https://github.com/RustCrypto/signatures/tree/master/ecdsa" }, { - "lock": "package-lock.json", - "path": "node_modules/@babel/plugin-transform-object-super", - "version": "7.29.7", - "license": "MIT", - "status": "approved" + "ecosystem": "cargo", + "name": "ed25519", + "version": "2.2.3", + "license": "Apache-2.0 OR MIT", + "category": "approved", + "repository": "https://github.com/RustCrypto/signatures/tree/master/ed25519" }, { - "lock": "package-lock.json", - "path": "node_modules/@babel/plugin-transform-optional-catch-binding", - "version": "7.29.7", - "license": "MIT", - "status": "approved" + "ecosystem": "cargo", + "name": "ed25519-dalek", + "version": "2.2.0", + "license": "BSD-3-Clause", + "category": "approved", + "repository": "https://github.com/dalek-cryptography/curve25519-dalek/tree/main/ed25519-dalek" }, { - "lock": "package-lock.json", - "path": "node_modules/@babel/plugin-transform-optional-chaining", - "version": "7.29.7", + "ecosystem": "cargo", + "name": "educe", + "version": "0.6.0", "license": "MIT", - "status": "approved" + "category": "approved", + "repository": "https://github.com/magiclen/educe" }, { - "lock": "package-lock.json", - "path": "node_modules/@babel/plugin-transform-parameters", - "version": "7.29.7", - "license": "MIT", - "status": "approved" + "ecosystem": "cargo", + "name": "either", + "version": "1.16.0", + "license": "MIT OR Apache-2.0", + "category": "approved", + "repository": "https://github.com/rayon-rs/either" }, { - "lock": "package-lock.json", - "path": "node_modules/@babel/plugin-transform-private-methods", - "version": "7.29.7", - "license": "MIT", - "status": "approved" + "ecosystem": "cargo", + "name": "either", + "version": "1.18.0", + "license": "MIT OR Apache-2.0", + "category": "approved", + "repository": "https://github.com/rayon-rs/either" }, { - "lock": "package-lock.json", - "path": "node_modules/@babel/plugin-transform-private-property-in-object", - "version": "7.29.7", - "license": "MIT", - "status": "approved" + "ecosystem": "cargo", + "name": "elliptic-curve", + "version": "0.13.8", + "license": "Apache-2.0 OR MIT", + "category": "approved", + "repository": "https://github.com/RustCrypto/traits/tree/master/elliptic-curve" }, { - "lock": "package-lock.json", - "path": "node_modules/@babel/plugin-transform-property-literals", - "version": "7.29.7", + "ecosystem": "cargo", + "name": "enum-ordinalize", + "version": "4.4.2", "license": "MIT", - "status": "approved" + "category": "approved", + "repository": "https://github.com/magiclen/enum-ordinalize" }, { - "lock": "package-lock.json", - "path": "node_modules/@babel/plugin-transform-regenerator", - "version": "7.29.8", + "ecosystem": "cargo", + "name": "enum-ordinalize-derive", + "version": "4.4.2", "license": "MIT", - "status": "approved" + "category": "approved", + "repository": "https://github.com/magiclen/enum-ordinalize" }, { - "lock": "package-lock.json", - "path": "node_modules/@babel/plugin-transform-regexp-modifiers", - "version": "7.29.7", - "license": "MIT", - "status": "approved" + "ecosystem": "cargo", + "name": "equivalent", + "version": "1.0.2", + "license": "Apache-2.0 OR MIT", + "category": "approved", + "repository": "https://github.com/indexmap-rs/equivalent" }, { - "lock": "package-lock.json", - "path": "node_modules/@babel/plugin-transform-reserved-words", - "version": "7.29.7", - "license": "MIT", - "status": "approved" + "ecosystem": "cargo", + "name": "escape-bytes", + "version": "0.1.1", + "license": "Apache-2.0", + "category": "approved", + "repository": "https://github.com/stellar/escape-bytes" }, { - "lock": "package-lock.json", - "path": "node_modules/@babel/plugin-transform-shorthand-properties", - "version": "7.29.7", - "license": "MIT", - "status": "approved" + "ecosystem": "cargo", + "name": "ethnum", + "version": "1.5.3", + "license": "MIT OR Apache-2.0", + "category": "approved", + "repository": "https://github.com/nlordell/ethnum-rs" }, { - "lock": "package-lock.json", - "path": "node_modules/@babel/plugin-transform-spread", - "version": "7.29.8", - "license": "MIT", - "status": "approved" + "ecosystem": "cargo", + "name": "ff", + "version": "0.13.1", + "license": "MIT/Apache-2.0", + "category": "approved", + "repository": "https://github.com/zkcrypto/ff" }, { - "lock": "package-lock.json", - "path": "node_modules/@babel/plugin-transform-sticky-regex", - "version": "7.29.7", - "license": "MIT", - "status": "approved" + "ecosystem": "cargo", + "name": "fiat-crypto", + "version": "0.2.9", + "license": "MIT OR Apache-2.0 OR BSD-1-Clause", + "category": "approved", + "repository": "https://github.com/mit-plv/fiat-crypto" }, { - "lock": "package-lock.json", - "path": "node_modules/@babel/plugin-transform-template-literals", - "version": "7.29.7", - "license": "MIT", - "status": "approved" + "ecosystem": "cargo", + "name": "fiat-crypto", + "version": "0.3.0", + "license": "MIT OR Apache-2.0 OR BSD-1-Clause", + "category": "approved", + "repository": "https://github.com/mit-plv/fiat-crypto" }, { - "lock": "package-lock.json", - "path": "node_modules/@babel/plugin-transform-typeof-symbol", - "version": "7.29.7", - "license": "MIT", - "status": "approved" + "ecosystem": "cargo", + "name": "find-msvc-tools", + "version": "0.1.13", + "license": "MIT OR Apache-2.0", + "category": "approved", + "repository": "https://github.com/rust-lang/cc-rs" }, { - "lock": "package-lock.json", - "path": "node_modules/@babel/plugin-transform-unicode-escapes", - "version": "7.29.7", - "license": "MIT", - "status": "approved" + "ecosystem": "cargo", + "name": "find-msvc-tools", + "version": "0.1.9", + "license": "MIT OR Apache-2.0", + "category": "approved", + "repository": "https://github.com/rust-lang/cc-rs" }, { - "lock": "package-lock.json", - "path": "node_modules/@babel/plugin-transform-unicode-property-regex", - "version": "7.29.7", - "license": "MIT", - "status": "approved" + "ecosystem": "cargo", + "name": "fnv", + "version": "1.0.7", + "license": "Apache-2.0 / MIT", + "category": "approved", + "repository": "https://github.com/servo/rust-fnv" }, { - "lock": "package-lock.json", - "path": "node_modules/@babel/plugin-transform-unicode-regex", - "version": "7.29.7", - "license": "MIT", - "status": "approved" + "ecosystem": "cargo", + "name": "futures-core", + "version": "0.3.32", + "license": "MIT OR Apache-2.0", + "category": "approved", + "repository": "https://github.com/rust-lang/futures-rs" }, { - "lock": "package-lock.json", - "path": "node_modules/@babel/plugin-transform-unicode-sets-regex", - "version": "7.29.7", - "license": "MIT", - "status": "approved" + "ecosystem": "cargo", + "name": "futures-core", + "version": "0.3.34", + "license": "MIT OR Apache-2.0", + "category": "approved", + "repository": "https://github.com/rust-lang/futures-rs" }, { - "lock": "package-lock.json", - "path": "node_modules/@babel/preset-env", - "version": "7.29.7", - "license": "MIT", - "status": "approved" + "ecosystem": "cargo", + "name": "futures-task", + "version": "0.3.32", + "license": "MIT OR Apache-2.0", + "category": "approved", + "repository": "https://github.com/rust-lang/futures-rs" }, { - "lock": "package-lock.json", - "path": "node_modules/@babel/preset-env/node_modules/semver", - "version": "6.3.1", - "license": "ISC", - "status": "approved" + "ecosystem": "cargo", + "name": "futures-task", + "version": "0.3.34", + "license": "MIT OR Apache-2.0", + "category": "approved", + "repository": "https://github.com/rust-lang/futures-rs" }, { - "lock": "package-lock.json", - "path": "node_modules/@babel/preset-modules", - "version": "0.1.6-no-external-plugins", - "license": "MIT", - "status": "approved" + "ecosystem": "cargo", + "name": "futures-util", + "version": "0.3.32", + "license": "MIT OR Apache-2.0", + "category": "approved", + "repository": "https://github.com/rust-lang/futures-rs" }, { - "lock": "package-lock.json", - "path": "node_modules/@babel/runtime", - "version": "7.29.7", - "license": "MIT", - "status": "approved" + "ecosystem": "cargo", + "name": "futures-util", + "version": "0.3.34", + "license": "MIT OR Apache-2.0", + "category": "approved", + "repository": "https://github.com/rust-lang/futures-rs" }, { - "lock": "package-lock.json", - "path": "node_modules/@babel/template", - "version": "7.29.7", + "ecosystem": "cargo", + "name": "generic-array", + "version": "0.14.9", "license": "MIT", - "status": "approved" + "category": "approved", + "repository": "https://github.com/fizyk20/generic-array.git" }, { - "lock": "package-lock.json", - "path": "node_modules/@babel/traverse", - "version": "7.29.8", - "license": "MIT", - "status": "approved" + "ecosystem": "cargo", + "name": "getrandom", + "version": "0.2.17", + "license": "MIT OR Apache-2.0", + "category": "approved", + "repository": "https://github.com/rust-random/getrandom" }, { - "lock": "package-lock.json", - "path": "node_modules/@babel/types", - "version": "7.29.8", - "license": "MIT", - "status": "approved" + "ecosystem": "cargo", + "name": "group", + "version": "0.13.0", + "license": "MIT/Apache-2.0", + "category": "approved", + "repository": "https://github.com/zkcrypto/group" }, { - "lock": "package-lock.json", - "path": "node_modules/@base-org/account", - "version": "2.4.0", + "ecosystem": "cargo", + "name": "hash32", + "version": "0.3.1", + "license": "MIT OR Apache-2.0", + "category": "approved", + "repository": "https://github.com/japaric/hash32" + }, + { + "ecosystem": "cargo", + "name": "hashbrown", + "version": "0.12.3", + "license": "MIT OR Apache-2.0", + "category": "approved", + "repository": "https://github.com/rust-lang/hashbrown" + }, + { + "ecosystem": "cargo", + "name": "hashbrown", + "version": "0.13.2", + "license": "MIT OR Apache-2.0", + "category": "approved", + "repository": "https://github.com/rust-lang/hashbrown" + }, + { + "ecosystem": "cargo", + "name": "hashbrown", + "version": "0.15.5", + "license": "MIT OR Apache-2.0", + "category": "approved", + "repository": "https://github.com/rust-lang/hashbrown" + }, + { + "ecosystem": "cargo", + "name": "hashbrown", + "version": "0.17.1", + "license": "MIT OR Apache-2.0", + "category": "approved", + "repository": "https://github.com/rust-lang/hashbrown" + }, + { + "ecosystem": "cargo", + "name": "heapless", + "version": "0.8.0", + "license": "MIT OR Apache-2.0", + "category": "approved", + "repository": "https://github.com/rust-embedded/heapless" + }, + { + "ecosystem": "cargo", + "name": "heck", + "version": "0.5.0", + "license": "MIT OR Apache-2.0", + "category": "approved", + "repository": "https://github.com/withoutboats/heck" + }, + { + "ecosystem": "cargo", + "name": "hex", + "version": "0.4.3", + "license": "MIT OR Apache-2.0", + "category": "approved", + "repository": "https://github.com/KokaKiwi/rust-hex" + }, + { + "ecosystem": "cargo", + "name": "hex-literal", + "version": "0.4.1", + "license": "MIT OR Apache-2.0", + "category": "approved", + "repository": "https://github.com/RustCrypto/utils" + }, + { + "ecosystem": "cargo", + "name": "hmac", + "version": "0.12.1", + "license": "MIT OR Apache-2.0", + "category": "approved", + "repository": "https://github.com/RustCrypto/MACs" + }, + { + "ecosystem": "cargo", + "name": "hybrid-array", + "version": "0.4.15", + "license": "MIT OR Apache-2.0", + "category": "approved", + "repository": "https://github.com/RustCrypto/hybrid-array" + }, + { + "ecosystem": "cargo", + "name": "iana-time-zone", + "version": "0.1.65", + "license": "MIT OR Apache-2.0", + "category": "approved", + "repository": "https://github.com/strawlab/iana-time-zone" + }, + { + "ecosystem": "cargo", + "name": "iana-time-zone-haiku", + "version": "0.1.2", + "license": "MIT OR Apache-2.0", + "category": "approved", + "repository": "https://github.com/strawlab/iana-time-zone" + }, + { + "ecosystem": "cargo", + "name": "ident_case", + "version": "1.0.1", + "license": "MIT/Apache-2.0", + "category": "approved", + "repository": "https://github.com/TedDriggs/ident_case" + }, + { + "ecosystem": "cargo", + "name": "indexmap", + "version": "1.9.3", + "license": "Apache-2.0 OR MIT", + "category": "approved", + "repository": "https://github.com/bluss/indexmap" + }, + { + "ecosystem": "cargo", + "name": "indexmap", + "version": "2.14.0", + "license": "Apache-2.0 OR MIT", + "category": "approved", + "repository": "https://github.com/indexmap-rs/indexmap" + }, + { + "ecosystem": "cargo", + "name": "indexmap", + "version": "2.14.2", + "license": "Apache-2.0 OR MIT", + "category": "approved", + "repository": "https://github.com/indexmap-rs/indexmap" + }, + { + "ecosystem": "cargo", + "name": "indexmap-nostd", + "version": "0.4.0", "license": "Apache-2.0", - "status": "approved" + "category": "approved", + "repository": "https://github.com/robbepop/indexmap-nostd" }, { - "lock": "package-lock.json", - "path": "node_modules/@base-org/account/node_modules/@noble/hashes", - "version": "1.4.0", - "license": "MIT", - "status": "approved" + "ecosystem": "cargo", + "name": "itertools", + "version": "0.10.5", + "license": "MIT/Apache-2.0", + "category": "approved", + "repository": "https://github.com/rust-itertools/itertools" }, { - "lock": "package-lock.json", - "path": "node_modules/@bramus/specificity", - "version": "2.4.2", - "license": "MIT", - "status": "approved" + "ecosystem": "cargo", + "name": "itertools", + "version": "0.13.0", + "license": "MIT OR Apache-2.0", + "category": "approved", + "repository": "https://github.com/rust-itertools/itertools" }, { - "lock": "package-lock.json", - "path": "node_modules/@bufbuild/protobuf", - "version": "2.12.1", - "license": "(Apache-2.0 AND BSD-3-Clause)", - "status": "approved" + "ecosystem": "cargo", + "name": "itoa", + "version": "1.0.18", + "license": "MIT OR Apache-2.0", + "category": "approved", + "repository": "https://github.com/dtolnay/itoa" }, { - "lock": "package-lock.json", - "path": "node_modules/@coinbase/cdp-sdk", - "version": "1.51.2", - "license": "MIT", - "status": "approved" + "ecosystem": "cargo", + "name": "jiff", + "version": "0.2.37", + "license": "Unlicense OR MIT", + "category": "approved", + "repository": "https://github.com/BurntSushi/jiff" }, { - "lock": "package-lock.json", - "path": "node_modules/@coinbase/cdp-sdk/node_modules/axios", - "version": "1.16.0", + "ecosystem": "cargo", + "name": "jiff-core", + "version": "0.1.1", + "license": "Unlicense OR MIT", + "category": "approved", + "repository": "https://github.com/BurntSushi/jiff" + }, + { + "ecosystem": "cargo", + "name": "jiff-static", + "version": "0.2.37", + "license": "Unlicense OR MIT", + "category": "approved", + "repository": "https://github.com/BurntSushi/jiff" + }, + { + "ecosystem": "cargo", + "name": "jiff-tzdb", + "version": "0.1.8", + "license": "Unlicense OR MIT", + "category": "approved", + "repository": "https://github.com/BurntSushi/jiff" + }, + { + "ecosystem": "cargo", + "name": "jiff-tzdb-platform", + "version": "0.1.3", + "license": "Unlicense OR MIT", + "category": "approved", + "repository": "https://github.com/BurntSushi/jiff" + }, + { + "ecosystem": "cargo", + "name": "js-sys", + "version": "0.3.102", + "license": "MIT OR Apache-2.0", + "category": "approved", + "repository": "https://github.com/wasm-bindgen/wasm-bindgen/tree/master/crates/js-sys" + }, + { + "ecosystem": "cargo", + "name": "js-sys", + "version": "0.3.105", + "license": "MIT OR Apache-2.0", + "category": "approved", + "repository": "https://github.com/wasm-bindgen/wasm-bindgen/tree/master/crates/js-sys" + }, + { + "ecosystem": "cargo", + "name": "k256", + "version": "0.13.4", + "license": "Apache-2.0 OR MIT", + "category": "approved", + "repository": "https://github.com/RustCrypto/elliptic-curves/tree/master/k256" + }, + { + "ecosystem": "cargo", + "name": "keccak", + "version": "0.1.6", + "license": "Apache-2.0 OR MIT", + "category": "approved", + "repository": "https://github.com/RustCrypto/sponges/tree/master/keccak" + }, + { + "ecosystem": "cargo", + "name": "libc", + "version": "0.2.186", + "license": "MIT OR Apache-2.0", + "category": "approved", + "repository": "https://github.com/rust-lang/libc" + }, + { + "ecosystem": "cargo", + "name": "libc", + "version": "0.2.189", + "license": "MIT OR Apache-2.0", + "category": "approved", + "repository": "https://github.com/rust-lang/libc" + }, + { + "ecosystem": "cargo", + "name": "libm", + "version": "0.2.16", "license": "MIT", - "status": "approved" + "category": "approved", + "repository": "https://github.com/rust-lang/compiler-builtins" }, { - "lock": "package-lock.json", - "path": "node_modules/@creit-tech/stellar-wallets-kit", - "version": "2.4.0", - "license": "UNKNOWN", - "status": "review" + "ecosystem": "cargo", + "name": "log", + "version": "0.4.33", + "license": "MIT OR Apache-2.0", + "category": "approved", + "repository": "https://github.com/rust-lang/log" }, { - "lock": "package-lock.json", - "path": "node_modules/@creit-tech/stellar-wallets-kit/node_modules/@msgpack/msgpack", - "version": "3.1.2", - "license": "ISC", - "status": "approved" + "ecosystem": "cargo", + "name": "log", + "version": "0.4.34", + "license": "MIT OR Apache-2.0", + "category": "approved", + "repository": "https://github.com/rust-lang/log" }, { - "lock": "package-lock.json", - "path": "node_modules/@creit-tech/stellar-wallets-kit/node_modules/@noble/curves", - "version": "1.9.7", + "ecosystem": "cargo", + "name": "macro-string", + "version": "0.1.4", + "license": "MIT OR Apache-2.0", + "category": "approved", + "repository": "https://github.com/dtolnay/macro-string" + }, + { + "ecosystem": "cargo", + "name": "memchr", + "version": "2.8.2", + "license": "Unlicense OR MIT", + "category": "approved", + "repository": "https://github.com/BurntSushi/memchr" + }, + { + "ecosystem": "cargo", + "name": "memchr", + "version": "2.8.3", + "license": "Unlicense OR MIT", + "category": "approved", + "repository": "https://github.com/BurntSushi/memchr" + }, + { + "ecosystem": "cargo", + "name": "num-bigint", + "version": "0.4.6", + "license": "MIT OR Apache-2.0", + "category": "approved", + "repository": "https://github.com/rust-num/num-bigint" + }, + { + "ecosystem": "cargo", + "name": "num-bigint", + "version": "0.4.8", + "license": "MIT OR Apache-2.0", + "category": "approved", + "repository": "https://github.com/rust-num/num-bigint" + }, + { + "ecosystem": "cargo", + "name": "num-conv", + "version": "0.2.2", + "license": "MIT OR Apache-2.0", + "category": "approved", + "repository": "https://github.com/jhpratt/num-conv" + }, + { + "ecosystem": "cargo", + "name": "num-derive", + "version": "0.4.2", + "license": "MIT OR Apache-2.0", + "category": "approved", + "repository": "https://github.com/rust-num/num-derive" + }, + { + "ecosystem": "cargo", + "name": "num-integer", + "version": "0.1.46", + "license": "MIT OR Apache-2.0", + "category": "approved", + "repository": "https://github.com/rust-num/num-integer" + }, + { + "ecosystem": "cargo", + "name": "num-integer", + "version": "0.1.47", + "license": "MIT OR Apache-2.0", + "category": "approved", + "repository": "https://github.com/rust-num/num-integer" + }, + { + "ecosystem": "cargo", + "name": "num-traits", + "version": "0.2.19", + "license": "MIT OR Apache-2.0", + "category": "approved", + "repository": "https://github.com/rust-num/num-traits" + }, + { + "ecosystem": "cargo", + "name": "once_cell", + "version": "1.21.4", + "license": "MIT OR Apache-2.0", + "category": "approved", + "repository": "https://github.com/matklad/once_cell" + }, + { + "ecosystem": "cargo", + "name": "p256", + "version": "0.13.2", + "license": "Apache-2.0 OR MIT", + "category": "approved", + "repository": "https://github.com/RustCrypto/elliptic-curves/tree/master/p256" + }, + { + "ecosystem": "cargo", + "name": "paste", + "version": "1.0.15", + "license": "MIT OR Apache-2.0", + "category": "approved", + "repository": "https://github.com/dtolnay/paste" + }, + { + "ecosystem": "cargo", + "name": "pin-project-lite", + "version": "0.2.17", + "license": "Apache-2.0 OR MIT", + "category": "approved", + "repository": "https://github.com/taiki-e/pin-project-lite" + }, + { + "ecosystem": "cargo", + "name": "pkcs8", + "version": "0.10.2", + "license": "Apache-2.0 OR MIT", + "category": "approved", + "repository": "https://github.com/RustCrypto/formats/tree/master/pkcs8" + }, + { + "ecosystem": "cargo", + "name": "portable-atomic", + "version": "1.15.0", + "license": "Apache-2.0 OR MIT", + "category": "approved", + "repository": "https://github.com/taiki-e/portable-atomic" + }, + { + "ecosystem": "cargo", + "name": "portable-atomic-util", + "version": "0.2.8", + "license": "Apache-2.0 OR MIT", + "category": "approved", + "repository": "https://github.com/taiki-e/portable-atomic-util" + }, + { + "ecosystem": "cargo", + "name": "powerfmt", + "version": "0.2.0", + "license": "MIT OR Apache-2.0", + "category": "approved", + "repository": "https://github.com/jhpratt/powerfmt" + }, + { + "ecosystem": "cargo", + "name": "ppv-lite86", + "version": "0.2.21", + "license": "MIT OR Apache-2.0", + "category": "approved", + "repository": "https://github.com/cryptocorrosion/cryptocorrosion" + }, + { + "ecosystem": "cargo", + "name": "prettyplease", + "version": "0.2.37", + "license": "MIT OR Apache-2.0", + "category": "approved", + "repository": "https://github.com/dtolnay/prettyplease" + }, + { + "ecosystem": "cargo", + "name": "primeorder", + "version": "0.13.6", + "license": "Apache-2.0 OR MIT", + "category": "approved", + "repository": "https://github.com/RustCrypto/elliptic-curves/tree/master/primeorder" + }, + { + "ecosystem": "cargo", + "name": "proc-macro2", + "version": "1.0.106", + "license": "MIT OR Apache-2.0", + "category": "approved", + "repository": "https://github.com/dtolnay/proc-macro2" + }, + { + "ecosystem": "cargo", + "name": "proc-macro2", + "version": "1.0.107", + "license": "MIT OR Apache-2.0", + "category": "approved", + "repository": "https://github.com/dtolnay/proc-macro2" + }, + { + "ecosystem": "cargo", + "name": "quote", + "version": "1.0.45", + "license": "MIT OR Apache-2.0", + "category": "approved", + "repository": "https://github.com/dtolnay/quote" + }, + { + "ecosystem": "cargo", + "name": "quote", + "version": "1.0.47", + "license": "MIT OR Apache-2.0", + "category": "approved", + "repository": "https://github.com/dtolnay/quote" + }, + { + "ecosystem": "cargo", + "name": "rand", + "version": "0.8.6", + "license": "MIT OR Apache-2.0", + "category": "approved", + "repository": "https://github.com/rust-random/rand" + }, + { + "ecosystem": "cargo", + "name": "rand", + "version": "0.8.8", + "license": "MIT OR Apache-2.0", + "category": "approved", + "repository": "https://github.com/rust-random/rand" + }, + { + "ecosystem": "cargo", + "name": "rand_chacha", + "version": "0.3.1", + "license": "MIT OR Apache-2.0", + "category": "approved", + "repository": "https://github.com/rust-random/rand" + }, + { + "ecosystem": "cargo", + "name": "rand_core", + "version": "0.6.4", + "license": "MIT OR Apache-2.0", + "category": "approved", + "repository": "https://github.com/rust-random/rand" + }, + { + "ecosystem": "cargo", + "name": "ref-cast", + "version": "1.0.25", + "license": "MIT OR Apache-2.0", + "category": "approved", + "repository": "https://github.com/dtolnay/ref-cast" + }, + { + "ecosystem": "cargo", + "name": "ref-cast", + "version": "1.0.27", + "license": "MIT OR Apache-2.0", + "category": "approved", + "repository": "https://github.com/dtolnay/ref-cast" + }, + { + "ecosystem": "cargo", + "name": "ref-cast-impl", + "version": "1.0.25", + "license": "MIT OR Apache-2.0", + "category": "approved", + "repository": "https://github.com/dtolnay/ref-cast" + }, + { + "ecosystem": "cargo", + "name": "ref-cast-impl", + "version": "1.0.27", + "license": "MIT OR Apache-2.0", + "category": "approved", + "repository": "https://github.com/dtolnay/ref-cast" + }, + { + "ecosystem": "cargo", + "name": "rfc6979", + "version": "0.4.0", + "license": "Apache-2.0 OR MIT", + "category": "approved", + "repository": "https://github.com/RustCrypto/signatures/tree/master/rfc6979" + }, + { + "ecosystem": "cargo", + "name": "rustc_version", + "version": "0.4.1", + "license": "MIT OR Apache-2.0", + "category": "approved", + "repository": "https://github.com/djc/rustc-version-rs" + }, + { + "ecosystem": "cargo", + "name": "rustversion", + "version": "1.0.22", + "license": "MIT OR Apache-2.0", + "category": "approved", + "repository": "https://github.com/dtolnay/rustversion" + }, + { + "ecosystem": "cargo", + "name": "rustversion", + "version": "1.0.23", + "license": "MIT OR Apache-2.0", + "category": "approved", + "repository": "https://github.com/dtolnay/rustversion" + }, + { + "ecosystem": "cargo", + "name": "schemars", + "version": "0.8.22", "license": "MIT", - "status": "approved" + "category": "approved", + "repository": "https://github.com/GREsau/schemars" }, { - "lock": "package-lock.json", - "path": "node_modules/@creit-tech/stellar-wallets-kit/node_modules/@noble/hashes", - "version": "1.8.0", + "ecosystem": "cargo", + "name": "schemars", + "version": "0.9.0", "license": "MIT", - "status": "approved" + "category": "approved", + "repository": "https://github.com/GREsau/schemars" }, { - "lock": "package-lock.json", - "path": "node_modules/@creit-tech/stellar-wallets-kit/node_modules/@preact/signals", - "version": "2.9.0", + "ecosystem": "cargo", + "name": "schemars", + "version": "1.2.1", "license": "MIT", - "status": "approved" + "category": "approved", + "repository": "https://github.com/GREsau/schemars" }, { - "lock": "package-lock.json", - "path": "node_modules/@creit-tech/stellar-wallets-kit/node_modules/@reown/appkit", - "version": "1.8.19", - "license": "SEE LICENSE IN LICENSE.md", - "status": "review" + "ecosystem": "cargo", + "name": "schemars", + "version": "1.2.2", + "license": "MIT", + "category": "approved", + "repository": "https://github.com/GREsau/schemars" }, { - "lock": "package-lock.json", - "path": "node_modules/@creit-tech/stellar-wallets-kit/node_modules/@reown/appkit-common", - "version": "1.8.19", - "license": "SEE LICENSE IN LICENSE.md", - "status": "review" + "ecosystem": "cargo", + "name": "sec1", + "version": "0.7.3", + "license": "Apache-2.0 OR MIT", + "category": "approved", + "repository": "https://github.com/RustCrypto/formats/tree/master/sec1" }, { - "lock": "package-lock.json", - "path": "node_modules/@creit-tech/stellar-wallets-kit/node_modules/@reown/appkit-controllers", - "version": "1.8.19", - "license": "SEE LICENSE IN LICENSE.md", - "status": "review" + "ecosystem": "cargo", + "name": "semver", + "version": "1.0.28", + "license": "MIT OR Apache-2.0", + "category": "approved", + "repository": "https://github.com/dtolnay/semver" }, { - "lock": "package-lock.json", - "path": "node_modules/@creit-tech/stellar-wallets-kit/node_modules/@reown/appkit-pay", - "version": "1.8.19", - "license": "SEE LICENSE IN LICENSE.md", - "status": "review" + "ecosystem": "cargo", + "name": "serde", + "version": "1.0.228", + "license": "MIT OR Apache-2.0", + "category": "approved", + "repository": "https://github.com/serde-rs/serde" }, { - "lock": "package-lock.json", - "path": "node_modules/@creit-tech/stellar-wallets-kit/node_modules/@reown/appkit-polyfills", - "version": "1.8.19", - "license": "SEE LICENSE IN LICENSE.md", - "status": "review" + "ecosystem": "cargo", + "name": "serde", + "version": "1.0.229", + "license": "MIT OR Apache-2.0", + "category": "approved", + "repository": "https://github.com/serde-rs/serde" }, { - "lock": "package-lock.json", - "path": "node_modules/@creit-tech/stellar-wallets-kit/node_modules/@reown/appkit-scaffold-ui", - "version": "1.8.19", - "license": "SEE LICENSE IN LICENSE.md", - "status": "review" + "ecosystem": "cargo", + "name": "serde_core", + "version": "1.0.228", + "license": "MIT OR Apache-2.0", + "category": "approved", + "repository": "https://github.com/serde-rs/serde" }, { - "lock": "package-lock.json", - "path": "node_modules/@creit-tech/stellar-wallets-kit/node_modules/@reown/appkit-ui", - "version": "1.8.19", - "license": "SEE LICENSE IN LICENSE.md", - "status": "review" + "ecosystem": "cargo", + "name": "serde_core", + "version": "1.0.229", + "license": "MIT OR Apache-2.0", + "category": "approved", + "repository": "https://github.com/serde-rs/serde" }, { - "lock": "package-lock.json", - "path": "node_modules/@creit-tech/stellar-wallets-kit/node_modules/@reown/appkit-utils", - "version": "1.8.19", - "license": "SEE LICENSE IN LICENSE.md", - "status": "review" + "ecosystem": "cargo", + "name": "serde_derive", + "version": "1.0.228", + "license": "MIT OR Apache-2.0", + "category": "approved", + "repository": "https://github.com/serde-rs/serde" }, { - "lock": "package-lock.json", - "path": "node_modules/@creit-tech/stellar-wallets-kit/node_modules/@reown/appkit-wallet", - "version": "1.8.19", - "license": "SEE LICENSE IN LICENSE.md", - "status": "review" + "ecosystem": "cargo", + "name": "serde_derive", + "version": "1.0.229", + "license": "MIT OR Apache-2.0", + "category": "approved", + "repository": "https://github.com/serde-rs/serde" }, { - "lock": "package-lock.json", - "path": "node_modules/@creit-tech/stellar-wallets-kit/node_modules/@stellar/freighter-api", - "version": "6.0.0", - "license": "Apache-2.0", - "status": "approved" + "ecosystem": "cargo", + "name": "serde_json", + "version": "1.0.150", + "license": "MIT OR Apache-2.0", + "category": "approved", + "repository": "https://github.com/serde-rs/json" }, { - "lock": "package-lock.json", - "path": "node_modules/@creit-tech/stellar-wallets-kit/node_modules/@stellar/freighter-api/node_modules/semver", - "version": "7.7.1", - "license": "ISC", - "status": "approved" + "ecosystem": "cargo", + "name": "serde_json", + "version": "1.0.151", + "license": "MIT OR Apache-2.0", + "category": "approved", + "repository": "https://github.com/serde-rs/json" }, { - "lock": "package-lock.json", - "path": "node_modules/@creit-tech/stellar-wallets-kit/node_modules/@twind/core", - "version": "1.1.3", - "license": "MIT", - "status": "approved" + "ecosystem": "cargo", + "name": "serde_with", + "version": "3.21.0", + "license": "MIT OR Apache-2.0", + "category": "approved", + "repository": "https://github.com/jonasbb/serde_with/" + }, + { + "ecosystem": "cargo", + "name": "serde_with", + "version": "3.23.0", + "license": "MIT OR Apache-2.0", + "category": "approved", + "repository": "https://github.com/jonasbb/serde_with/" }, { - "lock": "package-lock.json", - "path": "node_modules/@creit-tech/stellar-wallets-kit/node_modules/@twind/preset-autoprefix", - "version": "1.0.7", - "license": "MIT", - "status": "approved" + "ecosystem": "cargo", + "name": "serde_with_macros", + "version": "3.21.0", + "license": "MIT OR Apache-2.0", + "category": "approved", + "repository": "https://github.com/jonasbb/serde_with/" }, { - "lock": "package-lock.json", - "path": "node_modules/@creit-tech/stellar-wallets-kit/node_modules/@twind/preset-tailwind", - "version": "1.1.4", - "license": "MIT", - "status": "approved" + "ecosystem": "cargo", + "name": "serde_with_macros", + "version": "3.23.0", + "license": "MIT OR Apache-2.0", + "category": "approved", + "repository": "https://github.com/jonasbb/serde_with/" }, { - "lock": "package-lock.json", - "path": "node_modules/@creit-tech/stellar-wallets-kit/node_modules/@walletconnect/core", - "version": "2.23.0", - "license": "SEE LICENSE IN LICENSE.md", - "status": "review" + "ecosystem": "cargo", + "name": "sha2", + "version": "0.10.9", + "license": "MIT OR Apache-2.0", + "category": "approved", + "repository": "https://github.com/RustCrypto/hashes" }, { - "lock": "package-lock.json", - "path": "node_modules/@creit-tech/stellar-wallets-kit/node_modules/@walletconnect/core/node_modules/@walletconnect/logger", - "version": "3.0.0", - "license": "MIT", - "status": "approved" + "ecosystem": "cargo", + "name": "sha3", + "version": "0.10.9", + "license": "MIT OR Apache-2.0", + "category": "approved", + "repository": "https://github.com/RustCrypto/hashes" }, { - "lock": "package-lock.json", - "path": "node_modules/@creit-tech/stellar-wallets-kit/node_modules/@walletconnect/core/node_modules/@walletconnect/types", - "version": "2.23.0", - "license": "SEE LICENSE IN LICENSE.md", - "status": "review" + "ecosystem": "cargo", + "name": "shlex", + "version": "2.0.1", + "license": "MIT OR Apache-2.0", + "category": "approved", + "repository": "https://github.com/comex/rust-shlex" }, { - "lock": "package-lock.json", - "path": "node_modules/@creit-tech/stellar-wallets-kit/node_modules/@walletconnect/sign-client", - "version": "2.23.0", - "license": "SEE LICENSE IN LICENSE.md", - "status": "review" + "ecosystem": "cargo", + "name": "signature", + "version": "2.2.0", + "license": "Apache-2.0 OR MIT", + "category": "approved", + "repository": "https://github.com/RustCrypto/traits/tree/master/signature" }, { - "lock": "package-lock.json", - "path": "node_modules/@creit-tech/stellar-wallets-kit/node_modules/@walletconnect/sign-client/node_modules/@walletconnect/logger", - "version": "3.0.0", + "ecosystem": "cargo", + "name": "slab", + "version": "0.4.12", "license": "MIT", - "status": "approved" + "category": "approved", + "repository": "https://github.com/tokio-rs/slab" }, { - "lock": "package-lock.json", - "path": "node_modules/@creit-tech/stellar-wallets-kit/node_modules/@walletconnect/sign-client/node_modules/@walletconnect/types", - "version": "2.23.0", - "license": "SEE LICENSE IN LICENSE.md", - "status": "review" + "ecosystem": "cargo", + "name": "smallvec", + "version": "1.15.2", + "license": "MIT OR Apache-2.0", + "category": "approved", + "repository": "https://github.com/servo/rust-smallvec" }, { - "lock": "package-lock.json", - "path": "node_modules/@creit-tech/stellar-wallets-kit/node_modules/@walletconnect/types", - "version": "2.23.9", - "license": "SEE LICENSE IN LICENSE.md", - "status": "review" + "ecosystem": "cargo", + "name": "smallvec", + "version": "1.16.1", + "license": "MIT OR Apache-2.0", + "category": "approved", + "repository": "https://github.com/servo/rust-smallvec" }, { - "lock": "package-lock.json", - "path": "node_modules/@creit-tech/stellar-wallets-kit/node_modules/@walletconnect/utils", - "version": "2.23.0", - "license": "SEE LICENSE IN LICENSE.md", - "status": "review" + "ecosystem": "cargo", + "name": "soroban-builtin-sdk-macros", + "version": "25.0.1", + "license": "Apache-2.0", + "category": "approved", + "repository": "https://github.com/stellar/rs-soroban-env" }, { - "lock": "package-lock.json", - "path": "node_modules/@creit-tech/stellar-wallets-kit/node_modules/@walletconnect/utils/node_modules/@walletconnect/logger", - "version": "3.0.0", - "license": "MIT", - "status": "approved" + "ecosystem": "cargo", + "name": "soroban-builtin-sdk-macros", + "version": "26.1.4", + "license": "Apache-2.0", + "category": "approved", + "repository": "https://github.com/stellar/rs-soroban-env" }, { - "lock": "package-lock.json", - "path": "node_modules/@creit-tech/stellar-wallets-kit/node_modules/@walletconnect/utils/node_modules/@walletconnect/types", - "version": "2.23.0", - "license": "SEE LICENSE IN LICENSE.md", - "status": "review" + "ecosystem": "cargo", + "name": "soroban-env-common", + "version": "25.0.1", + "license": "Apache-2.0", + "category": "approved", + "repository": "https://github.com/stellar/rs-soroban-env" }, { - "lock": "package-lock.json", - "path": "node_modules/@creit-tech/stellar-wallets-kit/node_modules/@walletconnect/utils/node_modules/abitype", - "version": "1.2.4", - "license": "MIT", - "status": "approved" + "ecosystem": "cargo", + "name": "soroban-env-common", + "version": "26.1.4", + "license": "Apache-2.0", + "category": "approved", + "repository": "https://github.com/stellar/rs-soroban-env" }, { - "lock": "package-lock.json", - "path": "node_modules/@creit-tech/stellar-wallets-kit/node_modules/@walletconnect/utils/node_modules/ox", - "version": "0.9.3", - "license": "MIT", - "status": "approved" + "ecosystem": "cargo", + "name": "soroban-env-guest", + "version": "25.0.1", + "license": "Apache-2.0", + "category": "approved", + "repository": "https://github.com/stellar/rs-soroban-env" }, { - "lock": "package-lock.json", - "path": "node_modules/@creit-tech/stellar-wallets-kit/node_modules/@walletconnect/utils/node_modules/ox/node_modules/@noble/curves", - "version": "1.9.1", - "license": "MIT", - "status": "approved" + "ecosystem": "cargo", + "name": "soroban-env-guest", + "version": "26.1.4", + "license": "Apache-2.0", + "category": "approved", + "repository": "https://github.com/stellar/rs-soroban-env" }, { - "lock": "package-lock.json", - "path": "node_modules/@creit-tech/stellar-wallets-kit/node_modules/es-toolkit", - "version": "1.39.3", - "license": "MIT", - "status": "approved" + "ecosystem": "cargo", + "name": "soroban-env-host", + "version": "25.0.1", + "license": "Apache-2.0", + "category": "approved", + "repository": "https://github.com/stellar/rs-soroban-env" }, { - "lock": "package-lock.json", - "path": "node_modules/@creit-tech/stellar-wallets-kit/node_modules/preact", - "version": "10.29.3", - "license": "MIT", - "status": "approved" + "ecosystem": "cargo", + "name": "soroban-env-host", + "version": "26.1.4", + "license": "Apache-2.0", + "category": "approved", + "repository": "https://github.com/stellar/rs-soroban-env" }, { - "lock": "package-lock.json", - "path": "node_modules/@creit-tech/stellar-wallets-kit/node_modules/zod", - "version": "3.22.4", - "license": "MIT", - "status": "approved" + "ecosystem": "cargo", + "name": "soroban-env-macros", + "version": "25.0.1", + "license": "Apache-2.0", + "category": "approved", + "repository": "https://github.com/stellar/rs-soroban-env" }, { - "lock": "package-lock.json", - "path": "node_modules/@creit.tech/xbull-wallet-connect", - "version": "0.4.0", - "license": "UNKNOWN", - "status": "review" + "ecosystem": "cargo", + "name": "soroban-env-macros", + "version": "26.1.4", + "license": "Apache-2.0", + "category": "approved", + "repository": "https://github.com/stellar/rs-soroban-env" }, { - "lock": "package-lock.json", - "path": "node_modules/@csstools/color-helpers", - "version": "6.1.0", - "license": "MIT-0", - "status": "approved" + "ecosystem": "cargo", + "name": "soroban-ledger-snapshot", + "version": "25.3.1", + "license": "Apache-2.0", + "category": "approved", + "repository": "https://github.com/stellar/rs-soroban-sdk" }, { - "lock": "package-lock.json", - "path": "node_modules/@csstools/css-calc", - "version": "3.3.0", - "license": "MIT", - "status": "approved" + "ecosystem": "cargo", + "name": "soroban-ledger-snapshot", + "version": "26.1.1", + "license": "Apache-2.0", + "category": "approved", + "repository": "https://github.com/stellar/rs-soroban-sdk" }, { - "lock": "package-lock.json", - "path": "node_modules/@csstools/css-color-parser", - "version": "4.1.10", - "license": "MIT", - "status": "approved" + "ecosystem": "cargo", + "name": "soroban-sdk", + "version": "25.3.1", + "license": "Apache-2.0", + "category": "approved", + "repository": "https://github.com/stellar/rs-soroban-sdk" }, { - "lock": "package-lock.json", - "path": "node_modules/@csstools/css-parser-algorithms", - "version": "4.0.0", - "license": "MIT", - "status": "approved" + "ecosystem": "cargo", + "name": "soroban-sdk", + "version": "26.1.1", + "license": "Apache-2.0", + "category": "approved", + "repository": "https://github.com/stellar/rs-soroban-sdk" }, { - "lock": "package-lock.json", - "path": "node_modules/@csstools/css-syntax-patches-for-csstree", - "version": "1.1.7", - "license": "MIT-0", - "status": "approved" + "ecosystem": "cargo", + "name": "soroban-sdk-macros", + "version": "25.3.1", + "license": "Apache-2.0", + "category": "approved", + "repository": "https://github.com/stellar/rs-soroban-sdk" }, { - "lock": "package-lock.json", - "path": "node_modules/@csstools/css-tokenizer", - "version": "4.0.0", - "license": "MIT", - "status": "approved" + "ecosystem": "cargo", + "name": "soroban-sdk-macros", + "version": "26.1.1", + "license": "Apache-2.0", + "category": "approved", + "repository": "https://github.com/stellar/rs-soroban-sdk" }, { - "lock": "package-lock.json", - "path": "node_modules/@esbuild/aix-ppc64", - "version": "0.28.2", - "license": "MIT", - "status": "approved" + "ecosystem": "cargo", + "name": "soroban-spec", + "version": "25.3.1", + "license": "Apache-2.0", + "category": "approved", + "repository": "https://github.com/stellar/rs-soroban-sdk" }, { - "lock": "package-lock.json", - "path": "node_modules/@esbuild/android-arm", - "version": "0.28.2", - "license": "MIT", - "status": "approved" + "ecosystem": "cargo", + "name": "soroban-spec", + "version": "26.1.1", + "license": "Apache-2.0", + "category": "approved", + "repository": "https://github.com/stellar/rs-soroban-sdk" }, { - "lock": "package-lock.json", - "path": "node_modules/@esbuild/android-arm64", - "version": "0.28.2", - "license": "MIT", - "status": "approved" + "ecosystem": "cargo", + "name": "soroban-spec-rust", + "version": "25.3.1", + "license": "Apache-2.0", + "category": "approved", + "repository": "https://github.com/stellar/rs-soroban-sdk" }, { - "lock": "package-lock.json", - "path": "node_modules/@esbuild/android-x64", - "version": "0.28.2", - "license": "MIT", - "status": "approved" + "ecosystem": "cargo", + "name": "soroban-spec-rust", + "version": "26.1.1", + "license": "Apache-2.0", + "category": "approved", + "repository": "https://github.com/stellar/rs-soroban-sdk" }, { - "lock": "package-lock.json", - "path": "node_modules/@esbuild/darwin-arm64", - "version": "0.28.2", - "license": "MIT", - "status": "approved" + "ecosystem": "cargo", + "name": "soroban-wasmi", + "version": "0.31.1-soroban.20.0.1", + "license": "MIT/Apache-2.0", + "category": "approved", + "repository": "https://github.com/stellar/wasmi" }, { - "lock": "package-lock.json", - "path": "node_modules/@esbuild/darwin-x64", - "version": "0.28.2", + "ecosystem": "cargo", + "name": "spin", + "version": "0.9.8", "license": "MIT", - "status": "approved" + "category": "approved", + "repository": "https://github.com/mvdnes/spin-rs.git" }, { - "lock": "package-lock.json", - "path": "node_modules/@esbuild/freebsd-arm64", - "version": "0.28.2", + "ecosystem": "cargo", + "name": "spin", + "version": "0.9.9", "license": "MIT", - "status": "approved" + "category": "approved", + "repository": "https://github.com/mvdnes/spin-rs.git" }, { - "lock": "package-lock.json", - "path": "node_modules/@esbuild/freebsd-x64", - "version": "0.28.2", - "license": "MIT", - "status": "approved" + "ecosystem": "cargo", + "name": "spki", + "version": "0.7.3", + "license": "Apache-2.0 OR MIT", + "category": "approved", + "repository": "https://github.com/RustCrypto/formats/tree/master/spki" }, { - "lock": "package-lock.json", - "path": "node_modules/@esbuild/linux-arm", - "version": "0.28.2", - "license": "MIT", - "status": "approved" + "ecosystem": "cargo", + "name": "stable_deref_trait", + "version": "1.2.1", + "license": "MIT OR Apache-2.0", + "category": "approved", + "repository": "https://github.com/storyyeller/stable_deref_trait" }, { - "lock": "package-lock.json", - "path": "node_modules/@esbuild/linux-arm64", - "version": "0.28.2", - "license": "MIT", - "status": "approved" + "ecosystem": "cargo", + "name": "static_assertions", + "version": "1.1.0", + "license": "MIT OR Apache-2.0", + "category": "approved", + "repository": "https://github.com/nvzqz/static-assertions-rs" }, { - "lock": "package-lock.json", - "path": "node_modules/@esbuild/linux-ia32", - "version": "0.28.2", - "license": "MIT", - "status": "approved" + "ecosystem": "cargo", + "name": "stellar-strkey", + "version": "0.0.13", + "license": "Apache-2.0", + "category": "approved", + "repository": "https://github.com/stellar/rs-stellar-strkey" }, { - "lock": "package-lock.json", - "path": "node_modules/@esbuild/linux-loong64", - "version": "0.28.2", - "license": "MIT", - "status": "approved" + "ecosystem": "cargo", + "name": "stellar-strkey", + "version": "0.0.16", + "license": "Apache-2.0", + "category": "approved", + "repository": "https://github.com/stellar/rs-stellar-strkey" }, { - "lock": "package-lock.json", - "path": "node_modules/@esbuild/linux-mips64el", - "version": "0.28.2", - "license": "MIT", - "status": "approved" + "ecosystem": "cargo", + "name": "stellar-xdr", + "version": "25.0.0", + "license": "Apache-2.0", + "category": "approved", + "repository": "https://github.com/stellar/rs-stellar-xdr" }, { - "lock": "package-lock.json", - "path": "node_modules/@esbuild/linux-ppc64", - "version": "0.28.2", - "license": "MIT", - "status": "approved" + "ecosystem": "cargo", + "name": "stellar-xdr", + "version": "26.0.1", + "license": "Apache-2.0", + "category": "approved", + "repository": "https://github.com/stellar/rs-stellar-xdr" }, { - "lock": "package-lock.json", - "path": "node_modules/@esbuild/linux-riscv64", - "version": "0.28.2", + "ecosystem": "cargo", + "name": "strsim", + "version": "0.11.1", "license": "MIT", - "status": "approved" + "category": "approved", + "repository": "https://github.com/rapidfuzz/strsim-rs" }, { - "lock": "package-lock.json", - "path": "node_modules/@esbuild/linux-s390x", - "version": "0.28.2", - "license": "MIT", - "status": "approved" + "ecosystem": "cargo", + "name": "subtle", + "version": "2.6.1", + "license": "BSD-3-Clause", + "category": "approved", + "repository": "https://github.com/dalek-cryptography/subtle" }, { - "lock": "package-lock.json", - "path": "node_modules/@esbuild/linux-x64", - "version": "0.28.2", - "license": "MIT", - "status": "approved" + "ecosystem": "cargo", + "name": "syn", + "version": "1.0.109", + "license": "MIT OR Apache-2.0", + "category": "approved", + "repository": "https://github.com/dtolnay/syn" }, { - "lock": "package-lock.json", - "path": "node_modules/@esbuild/netbsd-arm64", - "version": "0.28.2", - "license": "MIT", - "status": "approved" + "ecosystem": "cargo", + "name": "syn", + "version": "2.0.118", + "license": "MIT OR Apache-2.0", + "category": "approved", + "repository": "https://github.com/dtolnay/syn" }, { - "lock": "package-lock.json", - "path": "node_modules/@esbuild/netbsd-x64", - "version": "0.28.2", - "license": "MIT", - "status": "approved" + "ecosystem": "cargo", + "name": "syn", + "version": "2.0.119", + "license": "MIT OR Apache-2.0", + "category": "approved", + "repository": "https://github.com/dtolnay/syn" }, { - "lock": "package-lock.json", - "path": "node_modules/@esbuild/openbsd-arm64", - "version": "0.28.2", - "license": "MIT", - "status": "approved" + "ecosystem": "cargo", + "name": "syn", + "version": "3.0.6", + "license": "MIT OR Apache-2.0", + "category": "approved", + "repository": "https://github.com/dtolnay/syn" }, { - "lock": "package-lock.json", - "path": "node_modules/@esbuild/openbsd-x64", - "version": "0.28.2", - "license": "MIT", - "status": "approved" + "ecosystem": "cargo", + "name": "thiserror", + "version": "1.0.69", + "license": "MIT OR Apache-2.0", + "category": "approved", + "repository": "https://github.com/dtolnay/thiserror" }, { - "lock": "package-lock.json", - "path": "node_modules/@esbuild/openharmony-arm64", - "version": "0.28.2", - "license": "MIT", - "status": "approved" + "ecosystem": "cargo", + "name": "thiserror", + "version": "2.0.21", + "license": "MIT OR Apache-2.0", + "category": "approved", + "repository": "https://github.com/dtolnay/thiserror" }, { - "lock": "package-lock.json", - "path": "node_modules/@esbuild/sunos-x64", - "version": "0.28.2", - "license": "MIT", - "status": "approved" + "ecosystem": "cargo", + "name": "thiserror-impl", + "version": "1.0.69", + "license": "MIT OR Apache-2.0", + "category": "approved", + "repository": "https://github.com/dtolnay/thiserror" }, { - "lock": "package-lock.json", - "path": "node_modules/@esbuild/win32-arm64", - "version": "0.28.2", - "license": "MIT", - "status": "approved" + "ecosystem": "cargo", + "name": "thiserror-impl", + "version": "2.0.21", + "license": "MIT OR Apache-2.0", + "category": "approved", + "repository": "https://github.com/dtolnay/thiserror" }, { - "lock": "package-lock.json", - "path": "node_modules/@esbuild/win32-ia32", - "version": "0.28.2", - "license": "MIT", - "status": "approved" + "ecosystem": "cargo", + "name": "time", + "version": "0.3.49", + "license": "MIT OR Apache-2.0", + "category": "approved", + "repository": "https://github.com/time-rs/time" }, { - "lock": "package-lock.json", - "path": "node_modules/@esbuild/win32-x64", - "version": "0.28.2", - "license": "MIT", - "status": "approved" + "ecosystem": "cargo", + "name": "time", + "version": "0.3.55", + "license": "MIT OR Apache-2.0", + "category": "approved", + "repository": "https://github.com/time-rs/time" }, { - "lock": "package-lock.json", - "path": "node_modules/@eslint-community/eslint-utils", - "version": "4.10.1", - "license": "MIT", - "status": "approved" + "ecosystem": "cargo", + "name": "time-core", + "version": "0.1.9", + "license": "MIT OR Apache-2.0", + "category": "approved", + "repository": "https://github.com/time-rs/time" }, { - "lock": "package-lock.json", - "path": "node_modules/@eslint-community/eslint-utils/node_modules/eslint-visitor-keys", - "version": "3.4.3", - "license": "Apache-2.0", - "status": "approved" + "ecosystem": "cargo", + "name": "time-macros", + "version": "0.2.29", + "license": "MIT OR Apache-2.0", + "category": "approved", + "repository": "https://github.com/time-rs/time" }, { - "lock": "package-lock.json", - "path": "node_modules/@eslint-community/regexpp", - "version": "4.12.2", - "license": "MIT", - "status": "approved" + "ecosystem": "cargo", + "name": "time-macros", + "version": "0.2.32", + "license": "MIT OR Apache-2.0", + "category": "approved", + "repository": "https://github.com/time-rs/time" }, { - "lock": "package-lock.json", - "path": "node_modules/@eslint/config-array", - "version": "0.21.2", - "license": "Apache-2.0", - "status": "approved" + "ecosystem": "cargo", + "name": "tinyvec", + "version": "1.11.0", + "license": "Zlib OR Apache-2.0 OR MIT", + "category": "approved", + "repository": "https://github.com/Lokathor/tinyvec" }, { - "lock": "package-lock.json", - "path": "node_modules/@eslint/config-helpers", - "version": "0.4.2", - "license": "Apache-2.0", - "status": "approved" + "ecosystem": "cargo", + "name": "tinyvec", + "version": "1.13.3", + "license": "Zlib OR Apache-2.0 OR MIT", + "category": "approved", + "repository": "https://github.com/Lokathor/tinyvec" }, { - "lock": "package-lock.json", - "path": "node_modules/@eslint/core", - "version": "0.17.0", - "license": "Apache-2.0", - "status": "approved" + "ecosystem": "cargo", + "name": "tinyvec_macros", + "version": "0.1.1", + "license": "MIT OR Apache-2.0 OR Zlib", + "category": "approved", + "repository": "https://github.com/Soveu/tinyvec_macros" }, { - "lock": "package-lock.json", - "path": "node_modules/@eslint/eslintrc", - "version": "3.3.7", - "license": "MIT", - "status": "approved" + "ecosystem": "cargo", + "name": "typenum", + "version": "1.20.1", + "license": "MIT OR Apache-2.0", + "category": "approved", + "repository": "https://github.com/paholg/typenum" }, { - "lock": "package-lock.json", - "path": "node_modules/@eslint/js", - "version": "9.39.5", - "license": "MIT", - "status": "approved" + "ecosystem": "cargo", + "name": "unicode-ident", + "version": "1.0.24", + "license": "(MIT OR Apache-2.0) AND Unicode-3.0", + "category": "approved", + "repository": "https://github.com/dtolnay/unicode-ident" }, { - "lock": "package-lock.json", - "path": "node_modules/@eslint/object-schema", - "version": "2.1.7", - "license": "Apache-2.0", - "status": "approved" + "ecosystem": "cargo", + "name": "unicode-ident", + "version": "1.0.26", + "license": "(MIT OR Apache-2.0) AND Unicode-3.0", + "category": "approved", + "repository": "https://github.com/dtolnay/unicode-ident" }, { - "lock": "package-lock.json", - "path": "node_modules/@eslint/plugin-kit", - "version": "0.4.1", - "license": "Apache-2.0", - "status": "approved" + "ecosystem": "cargo", + "name": "version_check", + "version": "0.9.5", + "license": "MIT/Apache-2.0", + "category": "approved", + "repository": "https://github.com/SergioBenitez/version_check" }, { - "lock": "package-lock.json", - "path": "node_modules/@exodus/bytes", - "version": "1.15.1", - "license": "MIT", - "status": "approved" + "ecosystem": "cargo", + "name": "visibility", + "version": "0.1.1", + "license": "Zlib OR MIT OR Apache-2.0", + "category": "approved", + "repository": "https://github.com/danielhenrymantilla/visibility.rs" }, { - "lock": "package-lock.json", - "path": "node_modules/@hot-wallet/sdk", - "version": "1.0.11", - "license": "UNKNOWN", - "status": "review" + "ecosystem": "cargo", + "name": "wasi", + "version": "0.11.1+wasi-snapshot-preview1", + "license": "Apache-2.0 WITH LLVM-exception OR Apache-2.0 OR MIT", + "category": "approved", + "repository": "https://github.com/bytecodealliance/wasi" }, { - "lock": "package-lock.json", - "path": "node_modules/@humanfs/core", - "version": "0.19.2", - "license": "Apache-2.0", - "status": "approved" + "ecosystem": "cargo", + "name": "wasm-bindgen", + "version": "0.2.125", + "license": "MIT OR Apache-2.0", + "category": "approved", + "repository": "https://github.com/wasm-bindgen/wasm-bindgen" }, { - "lock": "package-lock.json", - "path": "node_modules/@humanfs/node", - "version": "0.16.8", - "license": "Apache-2.0", - "status": "approved" + "ecosystem": "cargo", + "name": "wasm-bindgen", + "version": "0.2.128", + "license": "MIT OR Apache-2.0", + "category": "approved", + "repository": "https://github.com/wasm-bindgen/wasm-bindgen" }, { - "lock": "package-lock.json", - "path": "node_modules/@humanfs/types", - "version": "0.15.0", - "license": "Apache-2.0", - "status": "approved" + "ecosystem": "cargo", + "name": "wasm-bindgen-macro", + "version": "0.2.125", + "license": "MIT OR Apache-2.0", + "category": "approved", + "repository": "https://github.com/wasm-bindgen/wasm-bindgen/tree/master/crates/macro" }, { - "lock": "package-lock.json", - "path": "node_modules/@humanwhocodes/module-importer", - "version": "1.0.1", - "license": "Apache-2.0", - "status": "approved" + "ecosystem": "cargo", + "name": "wasm-bindgen-macro", + "version": "0.2.128", + "license": "MIT OR Apache-2.0", + "category": "approved", + "repository": "https://github.com/wasm-bindgen/wasm-bindgen/tree/master/crates/macro" }, { - "lock": "package-lock.json", - "path": "node_modules/@humanwhocodes/retry", - "version": "0.4.3", - "license": "Apache-2.0", - "status": "approved" + "ecosystem": "cargo", + "name": "wasm-bindgen-macro-support", + "version": "0.2.125", + "license": "MIT OR Apache-2.0", + "category": "approved", + "repository": "https://github.com/wasm-bindgen/wasm-bindgen/tree/master/crates/macro-support" }, { - "lock": "package-lock.json", - "path": "node_modules/@inquirer/ansi", - "version": "2.0.8", - "license": "MIT", - "status": "approved" + "ecosystem": "cargo", + "name": "wasm-bindgen-macro-support", + "version": "0.2.128", + "license": "MIT OR Apache-2.0", + "category": "approved", + "repository": "https://github.com/wasm-bindgen/wasm-bindgen/tree/main/crates/macro-support" }, { - "lock": "package-lock.json", - "path": "node_modules/@inquirer/confirm", - "version": "6.3.2", - "license": "MIT", - "status": "approved" + "ecosystem": "cargo", + "name": "wasm-bindgen-shared", + "version": "0.2.125", + "license": "MIT OR Apache-2.0", + "category": "approved", + "repository": "https://github.com/wasm-bindgen/wasm-bindgen/tree/master/crates/shared" }, { - "lock": "package-lock.json", - "path": "node_modules/@inquirer/core", - "version": "12.0.3", - "license": "MIT", - "status": "approved" + "ecosystem": "cargo", + "name": "wasm-bindgen-shared", + "version": "0.2.128", + "license": "MIT OR Apache-2.0", + "category": "approved", + "repository": "https://github.com/wasm-bindgen/wasm-bindgen/tree/master/crates/shared" }, { - "lock": "package-lock.json", - "path": "node_modules/@inquirer/figures", - "version": "2.0.9", - "license": "MIT", - "status": "approved" + "ecosystem": "cargo", + "name": "wasmi_arena", + "version": "0.4.1", + "license": "MIT/Apache-2.0", + "category": "approved", + "repository": "https://github.com/paritytech/wasmi" }, { - "lock": "package-lock.json", - "path": "node_modules/@inquirer/type", - "version": "4.1.1", - "license": "MIT", - "status": "approved" + "ecosystem": "cargo", + "name": "wasmi_core", + "version": "0.13.0", + "license": "MIT/Apache-2.0", + "category": "approved", + "repository": "https://github.com/paritytech/wasmi" }, { - "lock": "package-lock.json", - "path": "node_modules/@isaacs/cliui", - "version": "9.0.0", - "license": "BlueOak-1.0.0", - "status": "approved" + "ecosystem": "cargo", + "name": "wasmparser", + "version": "0.116.1", + "license": "Apache-2.0 WITH LLVM-exception", + "category": "approved", + "repository": "https://github.com/bytecodealliance/wasm-tools/tree/main/crates/wasmparser" }, { - "lock": "package-lock.json", - "path": "node_modules/@jridgewell/gen-mapping", - "version": "0.3.13", - "license": "MIT", - "status": "approved" + "ecosystem": "cargo", + "name": "wasmparser-nostd", + "version": "0.100.2", + "license": "Apache-2.0 WITH LLVM-exception", + "category": "approved", + "repository": "https://github.com/bytecodealliance/wasm-tools/tree/main/crates/wasmparser" }, { - "lock": "package-lock.json", - "path": "node_modules/@jridgewell/remapping", - "version": "2.3.5", - "license": "MIT", - "status": "approved" + "ecosystem": "cargo", + "name": "windows-core", + "version": "0.62.2", + "license": "MIT OR Apache-2.0", + "category": "approved", + "repository": "https://github.com/microsoft/windows-rs" }, { - "lock": "package-lock.json", - "path": "node_modules/@jridgewell/resolve-uri", - "version": "3.1.2", - "license": "MIT", - "status": "approved" + "ecosystem": "cargo", + "name": "windows-implement", + "version": "0.60.2", + "license": "MIT OR Apache-2.0", + "category": "approved", + "repository": "https://github.com/microsoft/windows-rs" }, { - "lock": "package-lock.json", - "path": "node_modules/@jridgewell/source-map", - "version": "0.3.11", - "license": "MIT", - "status": "approved" + "ecosystem": "cargo", + "name": "windows-interface", + "version": "0.59.3", + "license": "MIT OR Apache-2.0", + "category": "approved", + "repository": "https://github.com/microsoft/windows-rs" }, { - "lock": "package-lock.json", - "path": "node_modules/@jridgewell/sourcemap-codec", - "version": "1.5.5", - "license": "MIT", - "status": "approved" + "ecosystem": "cargo", + "name": "windows-link", + "version": "0.2.1", + "license": "MIT OR Apache-2.0", + "category": "approved", + "repository": "https://github.com/microsoft/windows-rs" }, { - "lock": "package-lock.json", - "path": "node_modules/@jridgewell/trace-mapping", - "version": "0.3.31", - "license": "MIT", - "status": "approved" + "ecosystem": "cargo", + "name": "windows-result", + "version": "0.4.1", + "license": "MIT OR Apache-2.0", + "category": "approved", + "repository": "https://github.com/microsoft/windows-rs" }, { - "lock": "package-lock.json", - "path": "node_modules/@jsr/std__encoding", - "version": "1.0.10", - "license": "UNKNOWN", - "status": "review" + "ecosystem": "cargo", + "name": "windows-strings", + "version": "0.5.1", + "license": "MIT OR Apache-2.0", + "category": "approved", + "repository": "https://github.com/microsoft/windows-rs" }, { - "lock": "package-lock.json", - "path": "node_modules/@ledgerhq/devices", - "version": "8.6.1", - "license": "Apache-2.0", - "status": "approved" + "ecosystem": "cargo", + "name": "zerocopy", + "version": "0.8.52", + "license": "BSD-2-Clause OR Apache-2.0 OR MIT", + "category": "approved", + "repository": "https://github.com/google/zerocopy" }, { - "lock": "package-lock.json", - "path": "node_modules/@ledgerhq/errors", - "version": "6.36.0", - "license": "Apache-2.0", - "status": "approved" + "ecosystem": "cargo", + "name": "zerocopy", + "version": "0.8.57", + "license": "BSD-2-Clause OR Apache-2.0 OR MIT", + "category": "approved", + "repository": "https://github.com/google/zerocopy" }, { - "lock": "package-lock.json", - "path": "node_modules/@ledgerhq/hw-app-str", - "version": "7.2.8", - "license": "Apache-2.0", - "status": "approved" + "ecosystem": "cargo", + "name": "zerocopy-derive", + "version": "0.8.52", + "license": "BSD-2-Clause OR Apache-2.0 OR MIT", + "category": "approved", + "repository": "https://github.com/google/zerocopy" }, { - "lock": "package-lock.json", - "path": "node_modules/@ledgerhq/hw-transport", - "version": "6.31.12", - "license": "Apache-2.0", - "status": "approved" + "ecosystem": "cargo", + "name": "zerocopy-derive", + "version": "0.8.57", + "license": "BSD-2-Clause OR Apache-2.0 OR MIT", + "category": "approved", + "repository": "https://github.com/google/zerocopy" }, { - "lock": "package-lock.json", - "path": "node_modules/@ledgerhq/hw-transport-webusb", - "version": "6.29.12", - "license": "Apache-2.0", - "status": "approved" + "ecosystem": "cargo", + "name": "zeroize", + "version": "1.9.0", + "license": "Apache-2.0 OR MIT", + "category": "approved", + "repository": "https://github.com/RustCrypto/utils" }, { - "lock": "package-lock.json", - "path": "node_modules/@ledgerhq/logs", - "version": "6.17.0", - "license": "Apache-2.0", - "status": "approved" + "ecosystem": "cargo", + "name": "zeroize_derive", + "version": "1.5.0", + "license": "Apache-2.0 OR MIT", + "category": "approved", + "repository": "https://github.com/RustCrypto/utils" }, { - "lock": "package-lock.json", - "path": "node_modules/@lit-labs/ssr-dom-shim", - "version": "1.6.0", - "license": "BSD-3-Clause", - "status": "approved" + "ecosystem": "cargo", + "name": "zmij", + "version": "1.0.21", + "license": "MIT", + "category": "approved", + "repository": "https://github.com/dtolnay/zmij" }, { - "lock": "package-lock.json", - "path": "node_modules/@lit/react", - "version": "1.0.8", - "license": "BSD-3-Clause", - "status": "approved" + "ecosystem": "cargo", + "name": "zmij", + "version": "1.0.23", + "license": "MIT", + "category": "approved", + "repository": "https://github.com/dtolnay/zmij" }, { - "lock": "package-lock.json", - "path": "node_modules/@lit/reactive-element", - "version": "2.1.2", - "license": "BSD-3-Clause", - "status": "approved" + "ecosystem": "npm", + "name": "@adobe/css-tools", + "version": "4.5.0", + "license": "MIT", + "category": "approved", + "dev": true, + "repository": "https://github.com/adobe/css-tools" }, { - "lock": "package-lock.json", - "path": "node_modules/@lobstrco/signer-extension-api", - "version": "2.0.0", - "license": "GPL-3.0", - "status": "excepted" + "ecosystem": "npm", + "name": "@adraffy/ens-normalize", + "version": "1.11.1", + "license": "MIT", + "category": "approved", + "repository": "https://github.com/adraffy/ens-normalize.js" }, { - "lock": "package-lock.json", - "path": "node_modules/@mapbox/jsonlint-lines-primitives", - "version": "2.0.2", - "license": "UNKNOWN", - "status": "review" + "ecosystem": "npm", + "name": "@albedo-link/intent", + "version": "0.12.0", + "license": "MIT", + "category": "approved", + "repository": "https://github.com/stellar-expert/albedo" }, { - "lock": "package-lock.json", - "path": "node_modules/@mapbox/unitbezier", - "version": "0.0.1", - "license": "BSD-2-Clause", - "status": "approved" + "ecosystem": "npm", + "name": "@apideck/better-ajv-errors", + "version": "0.3.7", + "license": "MIT", + "category": "approved", + "dev": true, + "repository": "https://github.com/apideck-libraries/better-ajv-errors" }, { - "lock": "package-lock.json", - "path": "node_modules/@maplibre/maplibre-gl-style-spec", - "version": "19.3.3", - "license": "ISC", - "status": "approved" + "ecosystem": "npm", + "name": "@asamuzakjp/css-color", + "version": "5.1.11", + "license": "MIT", + "category": "approved", + "dev": true, + "repository": "https://github.com/asamuzaK/cssColor" }, { - "lock": "package-lock.json", - "path": "node_modules/@msgpack/msgpack", - "version": "3.1.3", - "license": "ISC", - "status": "approved" + "ecosystem": "npm", + "name": "@asamuzakjp/dom-selector", + "version": "7.1.1", + "license": "MIT", + "category": "approved", + "dev": true, + "repository": "https://github.com/asamuzaK/domSelector" }, { - "lock": "package-lock.json", - "path": "node_modules/@msgpackr-extract/msgpackr-extract-darwin-arm64", - "version": "3.0.4", + "ecosystem": "npm", + "name": "@asamuzakjp/generational-cache", + "version": "1.0.1", "license": "MIT", - "status": "approved" + "category": "approved", + "dev": true, + "repository": "https://github.com/asamuzaK/generationalCache" }, { - "lock": "package-lock.json", - "path": "node_modules/@msgpackr-extract/msgpackr-extract-darwin-x64", - "version": "3.0.4", + "ecosystem": "npm", + "name": "@asamuzakjp/nwsapi", + "version": "2.3.9", "license": "MIT", - "status": "approved" + "category": "approved", + "dev": true, + "repository": "git://github.com/dperini/nwsapi" }, { - "lock": "package-lock.json", - "path": "node_modules/@msgpackr-extract/msgpackr-extract-linux-arm", - "version": "3.0.4", - "license": "MIT", - "status": "approved" + "ecosystem": "npm", + "name": "@axe-core/playwright", + "version": "4.13.0", + "license": "MPL-2.0", + "category": "review", + "dev": true, + "repository": "https://github.com/dequelabs/axe-core-npm" }, { - "lock": "package-lock.json", - "path": "node_modules/@msgpackr-extract/msgpackr-extract-linux-arm64", - "version": "3.0.4", + "ecosystem": "npm", + "name": "@aztec/bb.js", + "version": "0.87.9", "license": "MIT", - "status": "approved" + "category": "approved" }, { - "lock": "package-lock.json", - "path": "node_modules/@msgpackr-extract/msgpackr-extract-linux-x64", - "version": "3.0.4", + "ecosystem": "npm", + "name": "@babel/code-frame", + "version": "7.29.7", "license": "MIT", - "status": "approved" + "category": "approved", + "dev": true, + "repository": "https://github.com/babel/babel" }, { - "lock": "package-lock.json", - "path": "node_modules/@msgpackr-extract/msgpackr-extract-win32-x64", - "version": "3.0.4", + "ecosystem": "npm", + "name": "@babel/compat-data", + "version": "7.29.7", "license": "MIT", - "status": "approved" + "category": "approved", + "dev": true, + "repository": "https://github.com/babel/babel" }, { - "lock": "package-lock.json", - "path": "node_modules/@mswjs/interceptors", - "version": "0.41.9", + "ecosystem": "npm", + "name": "@babel/core", + "version": "7.29.7", "license": "MIT", - "status": "approved" + "category": "approved", + "dev": true, + "repository": "https://github.com/babel/babel" }, { - "lock": "package-lock.json", - "path": "node_modules/@mswjs/interceptors/node_modules/@open-draft/deferred-promise", - "version": "2.2.0", + "ecosystem": "npm", + "name": "@babel/generator", + "version": "7.29.8", "license": "MIT", - "status": "approved" + "category": "approved", + "dev": true, + "repository": "https://github.com/babel/babel" }, { - "lock": "package-lock.json", - "path": "node_modules/@napi-rs/lzma-linux-x64-gnu", - "version": "1.5.1", + "ecosystem": "npm", + "name": "@babel/helper-annotate-as-pure", + "version": "7.29.7", "license": "MIT", - "status": "approved" + "category": "approved", + "dev": true, + "repository": "https://github.com/babel/babel" }, { - "lock": "package-lock.json", - "path": "node_modules/@napi-rs/wasm-runtime", - "version": "1.1.5", + "ecosystem": "npm", + "name": "@babel/helper-compilation-targets", + "version": "7.29.7", "license": "MIT", - "status": "approved" + "category": "approved", + "dev": true, + "repository": "https://github.com/babel/babel" }, { - "lock": "package-lock.json", - "path": "node_modules/@near-js/crypto", - "version": "1.4.2", - "license": "ISC", - "status": "approved" + "ecosystem": "npm", + "name": "@babel/helper-create-class-features-plugin", + "version": "7.29.7", + "license": "MIT", + "category": "approved", + "dev": true, + "repository": "https://github.com/babel/babel" }, { - "lock": "package-lock.json", - "path": "node_modules/@near-js/crypto/node_modules/@noble/curves", - "version": "1.8.1", + "ecosystem": "npm", + "name": "@babel/helper-create-regexp-features-plugin", + "version": "7.29.7", "license": "MIT", - "status": "approved" + "category": "approved", + "dev": true, + "repository": "https://github.com/babel/babel" }, { - "lock": "package-lock.json", - "path": "node_modules/@near-js/crypto/node_modules/@noble/hashes", - "version": "1.7.1", + "ecosystem": "npm", + "name": "@babel/helper-define-polyfill-provider", + "version": "0.6.8", "license": "MIT", - "status": "approved" + "category": "approved", + "dev": true, + "repository": "https://github.com/babel/babel-polyfills" }, { - "lock": "package-lock.json", - "path": "node_modules/@near-js/crypto/node_modules/borsh", - "version": "1.0.0", - "license": "Apache-2.0", - "status": "approved" + "ecosystem": "npm", + "name": "@babel/helper-globals", + "version": "7.29.7", + "license": "MIT", + "category": "approved", + "dev": true, + "repository": "https://github.com/babel/babel" }, { - "lock": "package-lock.json", - "path": "node_modules/@near-js/types", - "version": "0.3.1", - "license": "ISC", - "status": "approved" + "ecosystem": "npm", + "name": "@babel/helper-member-expression-to-functions", + "version": "7.29.7", + "license": "MIT", + "category": "approved", + "dev": true, + "repository": "https://github.com/babel/babel" }, { - "lock": "package-lock.json", - "path": "node_modules/@near-js/utils", - "version": "1.1.0", - "license": "ISC", - "status": "approved" + "ecosystem": "npm", + "name": "@babel/helper-module-imports", + "version": "7.29.7", + "license": "MIT", + "category": "approved", + "dev": true, + "repository": "https://github.com/babel/babel" }, { - "lock": "package-lock.json", - "path": "node_modules/@near-wallet-selector/core", - "version": "8.10.2", - "license": "UNKNOWN", - "status": "review" + "ecosystem": "npm", + "name": "@babel/helper-module-transforms", + "version": "7.29.7", + "license": "MIT", + "category": "approved", + "dev": true, + "repository": "https://github.com/babel/babel" }, { - "lock": "package-lock.json", - "path": "node_modules/@near-wallet-selector/core/node_modules/borsh", - "version": "1.0.0", - "license": "Apache-2.0", - "status": "approved" + "ecosystem": "npm", + "name": "@babel/helper-optimise-call-expression", + "version": "7.29.7", + "license": "MIT", + "category": "approved", + "dev": true, + "repository": "https://github.com/babel/babel" }, { - "lock": "package-lock.json", - "path": "node_modules/@near-wallet-selector/core/node_modules/js-sha256", - "version": "0.9.0", + "ecosystem": "npm", + "name": "@babel/helper-plugin-utils", + "version": "7.29.7", "license": "MIT", - "status": "approved" + "category": "approved", + "dev": true, + "repository": "https://github.com/babel/babel" }, { - "lock": "package-lock.json", - "path": "node_modules/@near-wallet-selector/core/node_modules/rxjs", - "version": "7.8.1", - "license": "Apache-2.0", - "status": "approved" + "ecosystem": "npm", + "name": "@babel/helper-remap-async-to-generator", + "version": "7.29.7", + "license": "MIT", + "category": "approved", + "dev": true, + "repository": "https://github.com/babel/babel" }, { - "lock": "package-lock.json", - "path": "node_modules/@noble/ciphers", - "version": "1.3.0", + "ecosystem": "npm", + "name": "@babel/helper-replace-supers", + "version": "7.29.7", "license": "MIT", - "status": "approved" + "category": "approved", + "dev": true, + "repository": "https://github.com/babel/babel" }, { - "lock": "package-lock.json", - "path": "node_modules/@noble/curves", - "version": "1.8.0", + "ecosystem": "npm", + "name": "@babel/helper-skip-transparent-expression-wrappers", + "version": "7.29.7", "license": "MIT", - "status": "approved" + "category": "approved", + "dev": true, + "repository": "https://github.com/babel/babel" }, { - "lock": "package-lock.json", - "path": "node_modules/@noble/curves/node_modules/@noble/hashes", - "version": "1.7.0", + "ecosystem": "npm", + "name": "@babel/helper-string-parser", + "version": "7.29.7", "license": "MIT", - "status": "approved" + "category": "approved", + "dev": true, + "repository": "https://github.com/babel/babel" }, { - "lock": "package-lock.json", - "path": "node_modules/@noble/ed25519", - "version": "3.1.0", + "ecosystem": "npm", + "name": "@babel/helper-validator-identifier", + "version": "7.29.7", "license": "MIT", - "status": "approved" + "category": "approved", + "dev": true, + "repository": "https://github.com/babel/babel" }, { - "lock": "package-lock.json", - "path": "node_modules/@noble/hashes", - "version": "2.2.0", + "ecosystem": "npm", + "name": "@babel/helper-validator-option", + "version": "7.29.7", "license": "MIT", - "status": "approved" + "category": "approved", + "dev": true, + "repository": "https://github.com/babel/babel" }, { - "lock": "package-lock.json", - "path": "node_modules/@noir-lang/acvm_js", - "version": "1.0.0-beta.9", + "ecosystem": "npm", + "name": "@babel/helper-wrap-function", + "version": "7.29.7", "license": "MIT", - "status": "approved" + "category": "approved", + "dev": true, + "repository": "https://github.com/babel/babel" }, { - "lock": "package-lock.json", - "path": "node_modules/@noir-lang/noir_js", - "version": "1.0.0-beta.9", - "license": "(MIT OR Apache-2.0)", - "status": "approved" + "ecosystem": "npm", + "name": "@babel/helpers", + "version": "7.29.7", + "license": "MIT", + "category": "approved", + "dev": true, + "repository": "https://github.com/babel/babel" }, { - "lock": "package-lock.json", - "path": "node_modules/@noir-lang/noir_js/node_modules/@noir-lang/types", - "version": "1.0.0-beta.9", - "license": "(MIT OR Apache-2.0)", - "status": "approved" + "ecosystem": "npm", + "name": "@babel/parser", + "version": "7.29.8", + "license": "MIT", + "category": "approved", + "dev": true, + "repository": "https://github.com/babel/babel" }, { - "lock": "package-lock.json", - "path": "node_modules/@noir-lang/noirc_abi", - "version": "1.0.0-beta.9", - "license": "(MIT OR Apache-2.0)", - "status": "approved" + "ecosystem": "npm", + "name": "@babel/plugin-bugfix-firefox-class-in-computed-class-key", + "version": "7.29.7", + "license": "MIT", + "category": "approved", + "dev": true, + "repository": "https://github.com/babel/babel" }, { - "lock": "package-lock.json", - "path": "node_modules/@noir-lang/noirc_abi/node_modules/@noir-lang/types", - "version": "1.0.0-beta.9", - "license": "(MIT OR Apache-2.0)", - "status": "approved" + "ecosystem": "npm", + "name": "@babel/plugin-bugfix-safari-class-field-initializer-scope", + "version": "7.29.7", + "license": "MIT", + "category": "approved", + "dev": true, + "repository": "https://github.com/babel/babel" }, { - "lock": "package-lock.json", - "path": "node_modules/@open-draft/deferred-promise", - "version": "3.0.0", + "ecosystem": "npm", + "name": "@babel/plugin-bugfix-safari-id-destructuring-collision-in-function-expression", + "version": "7.29.7", "license": "MIT", - "status": "approved" + "category": "approved", + "dev": true, + "repository": "https://github.com/babel/babel" }, { - "lock": "package-lock.json", - "path": "node_modules/@open-draft/logger", - "version": "0.3.0", + "ecosystem": "npm", + "name": "@babel/plugin-bugfix-safari-rest-destructuring-rhs-array", + "version": "7.29.7", "license": "MIT", - "status": "approved" + "category": "approved", + "dev": true, + "repository": "https://github.com/babel/babel" }, { - "lock": "package-lock.json", - "path": "node_modules/@open-draft/until", - "version": "2.1.0", + "ecosystem": "npm", + "name": "@babel/plugin-bugfix-v8-spread-parameters-in-optional-chaining", + "version": "7.29.7", "license": "MIT", - "status": "approved" + "category": "approved", + "dev": true, + "repository": "https://github.com/babel/babel" }, { - "lock": "package-lock.json", - "path": "node_modules/@oxc-project/types", - "version": "0.133.0", + "ecosystem": "npm", + "name": "@babel/plugin-bugfix-v8-static-class-fields-redefine-readonly", + "version": "7.29.7", "license": "MIT", - "status": "approved" + "category": "approved", + "dev": true, + "repository": "https://github.com/babel/babel" }, { - "lock": "package-lock.json", - "path": "node_modules/@paralleldrive/cuid2", - "version": "2.3.1", + "ecosystem": "npm", + "name": "@babel/plugin-proposal-private-property-in-object", + "version": "7.21.0-placeholder-for-preset-env.2", "license": "MIT", - "status": "approved" + "category": "approved", + "dev": true, + "repository": "https://github.com/babel/babel-plugin-proposal-private-property-in-object" }, { - "lock": "package-lock.json", - "path": "node_modules/@paralleldrive/cuid2/node_modules/@noble/hashes", - "version": "1.8.0", + "ecosystem": "npm", + "name": "@babel/plugin-syntax-import-assertions", + "version": "7.29.7", "license": "MIT", - "status": "approved" + "category": "approved", + "dev": true, + "repository": "https://github.com/babel/babel" }, { - "lock": "package-lock.json", - "path": "node_modules/@phosphor-icons/webcomponents", - "version": "2.1.5", + "ecosystem": "npm", + "name": "@babel/plugin-syntax-import-attributes", + "version": "7.29.7", "license": "MIT", - "status": "approved" + "category": "approved", + "dev": true, + "repository": "https://github.com/babel/babel" }, { - "lock": "package-lock.json", - "path": "node_modules/@pinojs/redact", - "version": "0.4.0", + "ecosystem": "npm", + "name": "@babel/plugin-syntax-unicode-sets-regex", + "version": "7.18.6", "license": "MIT", - "status": "approved" + "category": "approved", + "dev": true, + "repository": "https://github.com/babel/babel" }, { - "lock": "package-lock.json", - "path": "node_modules/@preact/signals-core", - "version": "1.14.3", + "ecosystem": "npm", + "name": "@babel/plugin-transform-arrow-functions", + "version": "7.29.7", "license": "MIT", - "status": "approved" + "category": "approved", + "dev": true, + "repository": "https://github.com/babel/babel" }, { - "lock": "package-lock.json", - "path": "node_modules/@rolldown/binding-android-arm64", - "version": "1.0.3", + "ecosystem": "npm", + "name": "@babel/plugin-transform-async-generator-functions", + "version": "7.29.7", "license": "MIT", - "status": "approved" + "category": "approved", + "dev": true, + "repository": "https://github.com/babel/babel" }, { - "lock": "package-lock.json", - "path": "node_modules/@rolldown/binding-darwin-arm64", - "version": "1.0.3", + "ecosystem": "npm", + "name": "@babel/plugin-transform-async-to-generator", + "version": "7.29.7", "license": "MIT", - "status": "approved" + "category": "approved", + "dev": true, + "repository": "https://github.com/babel/babel" }, { - "lock": "package-lock.json", - "path": "node_modules/@rolldown/binding-darwin-x64", - "version": "1.0.3", + "ecosystem": "npm", + "name": "@babel/plugin-transform-block-scoped-functions", + "version": "7.29.7", "license": "MIT", - "status": "approved" + "category": "approved", + "dev": true, + "repository": "https://github.com/babel/babel" }, { - "lock": "package-lock.json", - "path": "node_modules/@rolldown/binding-freebsd-x64", - "version": "1.0.3", + "ecosystem": "npm", + "name": "@babel/plugin-transform-block-scoping", + "version": "7.29.7", "license": "MIT", - "status": "approved" + "category": "approved", + "dev": true, + "repository": "https://github.com/babel/babel" }, { - "lock": "package-lock.json", - "path": "node_modules/@rolldown/binding-linux-arm-gnueabihf", - "version": "1.0.3", + "ecosystem": "npm", + "name": "@babel/plugin-transform-class-properties", + "version": "7.29.7", "license": "MIT", - "status": "approved" + "category": "approved", + "dev": true, + "repository": "https://github.com/babel/babel" }, { - "lock": "package-lock.json", - "path": "node_modules/@rolldown/binding-linux-arm64-gnu", - "version": "1.0.3", + "ecosystem": "npm", + "name": "@babel/plugin-transform-class-static-block", + "version": "7.29.7", "license": "MIT", - "status": "approved" + "category": "approved", + "dev": true, + "repository": "https://github.com/babel/babel" }, { - "lock": "package-lock.json", - "path": "node_modules/@rolldown/binding-linux-arm64-musl", - "version": "1.0.3", + "ecosystem": "npm", + "name": "@babel/plugin-transform-classes", + "version": "7.29.7", "license": "MIT", - "status": "approved" + "category": "approved", + "dev": true, + "repository": "https://github.com/babel/babel" }, { - "lock": "package-lock.json", - "path": "node_modules/@rolldown/binding-linux-ppc64-gnu", - "version": "1.0.3", + "ecosystem": "npm", + "name": "@babel/plugin-transform-computed-properties", + "version": "7.29.7", "license": "MIT", - "status": "approved" + "category": "approved", + "dev": true, + "repository": "https://github.com/babel/babel" }, { - "lock": "package-lock.json", - "path": "node_modules/@rolldown/binding-linux-s390x-gnu", - "version": "1.0.3", + "ecosystem": "npm", + "name": "@babel/plugin-transform-destructuring", + "version": "7.29.7", "license": "MIT", - "status": "approved" + "category": "approved", + "dev": true, + "repository": "https://github.com/babel/babel" }, { - "lock": "package-lock.json", - "path": "node_modules/@rolldown/binding-linux-x64-gnu", - "version": "1.0.3", + "ecosystem": "npm", + "name": "@babel/plugin-transform-dotall-regex", + "version": "7.29.7", "license": "MIT", - "status": "approved" + "category": "approved", + "dev": true, + "repository": "https://github.com/babel/babel" }, { - "lock": "package-lock.json", - "path": "node_modules/@rolldown/binding-linux-x64-musl", - "version": "1.0.3", + "ecosystem": "npm", + "name": "@babel/plugin-transform-duplicate-keys", + "version": "7.29.7", "license": "MIT", - "status": "approved" + "category": "approved", + "dev": true, + "repository": "https://github.com/babel/babel" }, { - "lock": "package-lock.json", - "path": "node_modules/@rolldown/binding-openharmony-arm64", - "version": "1.0.3", + "ecosystem": "npm", + "name": "@babel/plugin-transform-duplicate-named-capturing-groups-regex", + "version": "7.29.7", "license": "MIT", - "status": "approved" + "category": "approved", + "dev": true, + "repository": "https://github.com/babel/babel" }, { - "lock": "package-lock.json", - "path": "node_modules/@rolldown/binding-wasm32-wasi", - "version": "1.0.3", + "ecosystem": "npm", + "name": "@babel/plugin-transform-dynamic-import", + "version": "7.29.7", "license": "MIT", - "status": "approved" + "category": "approved", + "dev": true, + "repository": "https://github.com/babel/babel" }, { - "lock": "package-lock.json", - "path": "node_modules/@rolldown/binding-wasm32-wasi/node_modules/@emnapi/core", - "version": "1.10.0", + "ecosystem": "npm", + "name": "@babel/plugin-transform-explicit-resource-management", + "version": "7.29.7", "license": "MIT", - "status": "approved" + "category": "approved", + "dev": true, + "repository": "https://github.com/babel/babel" }, { - "lock": "package-lock.json", - "path": "node_modules/@rolldown/binding-wasm32-wasi/node_modules/@emnapi/runtime", - "version": "1.10.0", + "ecosystem": "npm", + "name": "@babel/plugin-transform-exponentiation-operator", + "version": "7.29.7", "license": "MIT", - "status": "approved" + "category": "approved", + "dev": true, + "repository": "https://github.com/babel/babel" }, { - "lock": "package-lock.json", - "path": "node_modules/@rolldown/binding-wasm32-wasi/node_modules/@emnapi/wasi-threads", - "version": "1.2.1", + "ecosystem": "npm", + "name": "@babel/plugin-transform-export-namespace-from", + "version": "7.29.7", "license": "MIT", - "status": "approved" + "category": "approved", + "dev": true, + "repository": "https://github.com/babel/babel" }, { - "lock": "package-lock.json", - "path": "node_modules/@rolldown/binding-win32-arm64-msvc", - "version": "1.0.3", + "ecosystem": "npm", + "name": "@babel/plugin-transform-for-of", + "version": "7.29.7", "license": "MIT", - "status": "approved" + "category": "approved", + "dev": true, + "repository": "https://github.com/babel/babel" }, { - "lock": "package-lock.json", - "path": "node_modules/@rolldown/binding-win32-x64-msvc", - "version": "1.0.3", + "ecosystem": "npm", + "name": "@babel/plugin-transform-function-name", + "version": "7.29.7", "license": "MIT", - "status": "approved" + "category": "approved", + "dev": true, + "repository": "https://github.com/babel/babel" }, { - "lock": "package-lock.json", - "path": "node_modules/@rolldown/pluginutils", - "version": "1.0.1", + "ecosystem": "npm", + "name": "@babel/plugin-transform-json-strings", + "version": "7.29.7", "license": "MIT", - "status": "approved" + "category": "approved", + "dev": true, + "repository": "https://github.com/babel/babel" }, { - "lock": "package-lock.json", - "path": "node_modules/@rollup/plugin-babel", - "version": "6.1.0", + "ecosystem": "npm", + "name": "@babel/plugin-transform-literals", + "version": "7.29.7", "license": "MIT", - "status": "approved" + "category": "approved", + "dev": true, + "repository": "https://github.com/babel/babel" }, { - "lock": "package-lock.json", - "path": "node_modules/@rollup/plugin-node-resolve", - "version": "16.0.3", + "ecosystem": "npm", + "name": "@babel/plugin-transform-logical-assignment-operators", + "version": "7.29.7", "license": "MIT", - "status": "approved" + "category": "approved", + "dev": true, + "repository": "https://github.com/babel/babel" }, { - "lock": "package-lock.json", - "path": "node_modules/@rollup/plugin-replace", - "version": "6.0.3", + "ecosystem": "npm", + "name": "@babel/plugin-transform-member-expression-literals", + "version": "7.29.7", "license": "MIT", - "status": "approved" + "category": "approved", + "dev": true, + "repository": "https://github.com/babel/babel" }, { - "lock": "package-lock.json", - "path": "node_modules/@rollup/plugin-terser", - "version": "1.0.0", + "ecosystem": "npm", + "name": "@babel/plugin-transform-modules-amd", + "version": "7.29.7", "license": "MIT", - "status": "approved" + "category": "approved", + "dev": true, + "repository": "https://github.com/babel/babel" }, { - "lock": "package-lock.json", - "path": "node_modules/@rollup/pluginutils", - "version": "5.4.0", + "ecosystem": "npm", + "name": "@babel/plugin-transform-modules-commonjs", + "version": "7.29.7", "license": "MIT", - "status": "approved" + "category": "approved", + "dev": true, + "repository": "https://github.com/babel/babel" }, { - "lock": "package-lock.json", - "path": "node_modules/@rollup/pluginutils/node_modules/estree-walker", - "version": "2.0.2", + "ecosystem": "npm", + "name": "@babel/plugin-transform-modules-systemjs", + "version": "7.29.8", "license": "MIT", - "status": "approved" + "category": "approved", + "dev": true, + "repository": "https://github.com/babel/babel" }, { - "lock": "package-lock.json", - "path": "node_modules/@rollup/rollup-android-arm-eabi", - "version": "4.63.5", + "ecosystem": "npm", + "name": "@babel/plugin-transform-modules-umd", + "version": "7.29.7", "license": "MIT", - "status": "approved" + "category": "approved", + "dev": true, + "repository": "https://github.com/babel/babel" }, { - "lock": "package-lock.json", - "path": "node_modules/@rollup/rollup-android-arm64", - "version": "4.63.5", + "ecosystem": "npm", + "name": "@babel/plugin-transform-named-capturing-groups-regex", + "version": "7.29.7", "license": "MIT", - "status": "approved" + "category": "approved", + "dev": true, + "repository": "https://github.com/babel/babel" }, { - "lock": "package-lock.json", - "path": "node_modules/@rollup/rollup-darwin-arm64", - "version": "4.63.5", + "ecosystem": "npm", + "name": "@babel/plugin-transform-new-target", + "version": "7.29.7", "license": "MIT", - "status": "approved" + "category": "approved", + "dev": true, + "repository": "https://github.com/babel/babel" }, { - "lock": "package-lock.json", - "path": "node_modules/@rollup/rollup-darwin-x64", - "version": "4.63.5", + "ecosystem": "npm", + "name": "@babel/plugin-transform-nullish-coalescing-operator", + "version": "7.29.7", "license": "MIT", - "status": "approved" + "category": "approved", + "dev": true, + "repository": "https://github.com/babel/babel" }, { - "lock": "package-lock.json", - "path": "node_modules/@rollup/rollup-freebsd-arm64", - "version": "4.63.5", + "ecosystem": "npm", + "name": "@babel/plugin-transform-numeric-separator", + "version": "7.29.7", "license": "MIT", - "status": "approved" + "category": "approved", + "dev": true, + "repository": "https://github.com/babel/babel" }, { - "lock": "package-lock.json", - "path": "node_modules/@rollup/rollup-freebsd-x64", - "version": "4.63.5", + "ecosystem": "npm", + "name": "@babel/plugin-transform-object-rest-spread", + "version": "7.29.7", "license": "MIT", - "status": "approved" + "category": "approved", + "dev": true, + "repository": "https://github.com/babel/babel" }, { - "lock": "package-lock.json", - "path": "node_modules/@rollup/rollup-linux-arm-gnueabihf", - "version": "4.63.5", + "ecosystem": "npm", + "name": "@babel/plugin-transform-object-super", + "version": "7.29.7", "license": "MIT", - "status": "approved" + "category": "approved", + "dev": true, + "repository": "https://github.com/babel/babel" }, { - "lock": "package-lock.json", - "path": "node_modules/@rollup/rollup-linux-arm-musleabihf", - "version": "4.63.5", + "ecosystem": "npm", + "name": "@babel/plugin-transform-optional-catch-binding", + "version": "7.29.7", "license": "MIT", - "status": "approved" + "category": "approved", + "dev": true, + "repository": "https://github.com/babel/babel" }, { - "lock": "package-lock.json", - "path": "node_modules/@rollup/rollup-linux-arm64-gnu", - "version": "4.63.5", + "ecosystem": "npm", + "name": "@babel/plugin-transform-optional-chaining", + "version": "7.29.7", "license": "MIT", - "status": "approved" + "category": "approved", + "dev": true, + "repository": "https://github.com/babel/babel" }, { - "lock": "package-lock.json", - "path": "node_modules/@rollup/rollup-linux-arm64-musl", - "version": "4.63.5", + "ecosystem": "npm", + "name": "@babel/plugin-transform-parameters", + "version": "7.29.7", "license": "MIT", - "status": "approved" + "category": "approved", + "dev": true, + "repository": "https://github.com/babel/babel" }, { - "lock": "package-lock.json", - "path": "node_modules/@rollup/rollup-linux-loong64-gnu", - "version": "4.63.5", + "ecosystem": "npm", + "name": "@babel/plugin-transform-private-methods", + "version": "7.29.7", "license": "MIT", - "status": "approved" + "category": "approved", + "dev": true, + "repository": "https://github.com/babel/babel" }, { - "lock": "package-lock.json", - "path": "node_modules/@rollup/rollup-linux-loong64-musl", - "version": "4.63.5", + "ecosystem": "npm", + "name": "@babel/plugin-transform-private-property-in-object", + "version": "7.29.7", "license": "MIT", - "status": "approved" + "category": "approved", + "dev": true, + "repository": "https://github.com/babel/babel" }, { - "lock": "package-lock.json", - "path": "node_modules/@rollup/rollup-linux-ppc64-gnu", - "version": "4.63.5", + "ecosystem": "npm", + "name": "@babel/plugin-transform-property-literals", + "version": "7.29.7", "license": "MIT", - "status": "approved" + "category": "approved", + "dev": true, + "repository": "https://github.com/babel/babel" }, { - "lock": "package-lock.json", - "path": "node_modules/@rollup/rollup-linux-ppc64-musl", - "version": "4.63.5", + "ecosystem": "npm", + "name": "@babel/plugin-transform-regenerator", + "version": "7.29.8", "license": "MIT", - "status": "approved" + "category": "approved", + "dev": true, + "repository": "https://github.com/babel/babel" }, { - "lock": "package-lock.json", - "path": "node_modules/@rollup/rollup-linux-riscv64-gnu", - "version": "4.63.5", + "ecosystem": "npm", + "name": "@babel/plugin-transform-regexp-modifiers", + "version": "7.29.7", "license": "MIT", - "status": "approved" + "category": "approved", + "dev": true, + "repository": "https://github.com/babel/babel" }, { - "lock": "package-lock.json", - "path": "node_modules/@rollup/rollup-linux-riscv64-musl", - "version": "4.63.5", + "ecosystem": "npm", + "name": "@babel/plugin-transform-reserved-words", + "version": "7.29.7", "license": "MIT", - "status": "approved" + "category": "approved", + "dev": true, + "repository": "https://github.com/babel/babel" }, { - "lock": "package-lock.json", - "path": "node_modules/@rollup/rollup-linux-s390x-gnu", - "version": "4.63.5", + "ecosystem": "npm", + "name": "@babel/plugin-transform-shorthand-properties", + "version": "7.29.7", "license": "MIT", - "status": "approved" + "category": "approved", + "dev": true, + "repository": "https://github.com/babel/babel" }, { - "lock": "package-lock.json", - "path": "node_modules/@rollup/rollup-linux-x64-gnu", - "version": "4.63.5", + "ecosystem": "npm", + "name": "@babel/plugin-transform-spread", + "version": "7.29.8", "license": "MIT", - "status": "approved" + "category": "approved", + "dev": true, + "repository": "https://github.com/babel/babel" }, { - "lock": "package-lock.json", - "path": "node_modules/@rollup/rollup-linux-x64-musl", - "version": "4.63.5", + "ecosystem": "npm", + "name": "@babel/plugin-transform-sticky-regex", + "version": "7.29.7", "license": "MIT", - "status": "approved" + "category": "approved", + "dev": true, + "repository": "https://github.com/babel/babel" }, { - "lock": "package-lock.json", - "path": "node_modules/@rollup/rollup-openbsd-x64", - "version": "4.63.5", + "ecosystem": "npm", + "name": "@babel/plugin-transform-template-literals", + "version": "7.29.7", "license": "MIT", - "status": "approved" + "category": "approved", + "dev": true, + "repository": "https://github.com/babel/babel" }, { - "lock": "package-lock.json", - "path": "node_modules/@rollup/rollup-openharmony-arm64", - "version": "4.63.5", + "ecosystem": "npm", + "name": "@babel/plugin-transform-typeof-symbol", + "version": "7.29.7", "license": "MIT", - "status": "approved" + "category": "approved", + "dev": true, + "repository": "https://github.com/babel/babel" }, { - "lock": "package-lock.json", - "path": "node_modules/@rollup/rollup-win32-arm64-msvc", - "version": "4.63.5", + "ecosystem": "npm", + "name": "@babel/plugin-transform-unicode-escapes", + "version": "7.29.7", "license": "MIT", - "status": "approved" + "category": "approved", + "dev": true, + "repository": "https://github.com/babel/babel" }, { - "lock": "package-lock.json", - "path": "node_modules/@rollup/rollup-win32-ia32-msvc", - "version": "4.63.5", + "ecosystem": "npm", + "name": "@babel/plugin-transform-unicode-property-regex", + "version": "7.29.7", "license": "MIT", - "status": "approved" + "category": "approved", + "dev": true, + "repository": "https://github.com/babel/babel" }, { - "lock": "package-lock.json", - "path": "node_modules/@rollup/rollup-win32-x64-gnu", - "version": "4.63.5", + "ecosystem": "npm", + "name": "@babel/plugin-transform-unicode-regex", + "version": "7.29.7", "license": "MIT", - "status": "approved" + "category": "approved", + "dev": true, + "repository": "https://github.com/babel/babel" }, { - "lock": "package-lock.json", - "path": "node_modules/@rollup/rollup-win32-x64-msvc", - "version": "4.63.5", + "ecosystem": "npm", + "name": "@babel/plugin-transform-unicode-sets-regex", + "version": "7.29.7", "license": "MIT", - "status": "approved" + "category": "approved", + "dev": true, + "repository": "https://github.com/babel/babel" }, { - "lock": "package-lock.json", - "path": "node_modules/@safe-global/safe-apps-provider", - "version": "0.18.6", + "ecosystem": "npm", + "name": "@babel/preset-env", + "version": "7.29.7", "license": "MIT", - "status": "approved" + "category": "approved", + "dev": true, + "repository": "https://github.com/babel/babel" }, { - "lock": "package-lock.json", - "path": "node_modules/@safe-global/safe-apps-sdk", - "version": "9.1.0", + "ecosystem": "npm", + "name": "@babel/preset-modules", + "version": "0.1.6-no-external-plugins", "license": "MIT", - "status": "approved" + "category": "approved", + "dev": true, + "repository": "https://github.com/babel/preset-modules" }, { - "lock": "package-lock.json", - "path": "node_modules/@safe-global/safe-gateway-typescript-sdk", - "version": "3.23.1", + "ecosystem": "npm", + "name": "@babel/runtime", + "version": "7.29.7", "license": "MIT", - "status": "approved" + "category": "approved", + "repository": "https://github.com/babel/babel" }, { - "lock": "package-lock.json", - "path": "node_modules/@scure/base", - "version": "1.2.6", + "ecosystem": "npm", + "name": "@babel/template", + "version": "7.29.7", "license": "MIT", - "status": "approved" + "category": "approved", + "dev": true, + "repository": "https://github.com/babel/babel" }, { - "lock": "package-lock.json", - "path": "node_modules/@scure/bip32", - "version": "1.7.0", + "ecosystem": "npm", + "name": "@babel/traverse", + "version": "7.29.8", "license": "MIT", - "status": "approved" + "category": "approved", + "dev": true, + "repository": "https://github.com/babel/babel" }, { - "lock": "package-lock.json", - "path": "node_modules/@scure/bip32/node_modules/@noble/curves", - "version": "1.9.7", + "ecosystem": "npm", + "name": "@babel/types", + "version": "7.29.8", "license": "MIT", - "status": "approved" + "category": "approved", + "dev": true, + "repository": "https://github.com/babel/babel" }, { - "lock": "package-lock.json", - "path": "node_modules/@scure/bip32/node_modules/@noble/hashes", - "version": "1.8.0", + "ecosystem": "npm", + "name": "@base-org/account", + "version": "2.4.0", + "license": "Apache-2.0", + "category": "approved", + "repository": "https://github.com/base/account-sdk" + }, + { + "ecosystem": "npm", + "name": "@bcoe/v8-coverage", + "version": "1.0.2", "license": "MIT", - "status": "approved" + "category": "approved", + "dev": true, + "repository": "git://github.com/bcoe/v8-coverage" }, { - "lock": "package-lock.json", - "path": "node_modules/@scure/bip39", - "version": "1.6.0", + "ecosystem": "npm", + "name": "@bramus/specificity", + "version": "2.4.2", "license": "MIT", - "status": "approved" + "category": "approved", + "dev": true, + "repository": "https://github.com/bramus/specificity" }, { - "lock": "package-lock.json", - "path": "node_modules/@scure/bip39/node_modules/@noble/hashes", - "version": "1.8.0", + "ecosystem": "npm", + "name": "@bufbuild/protobuf", + "version": "2.12.1", + "license": "(Apache-2.0 AND BSD-3-Clause)", + "category": "approved", + "repository": "https://github.com/bufbuild/protobuf-es" + }, + { + "ecosystem": "npm", + "name": "@coinbase/cdp-sdk", + "version": "1.51.2", "license": "MIT", - "status": "approved" + "category": "approved", + "repository": "https://github.com/coinbase/cdp-sdk" }, { - "lock": "package-lock.json", - "path": "node_modules/@solana-program/system", - "version": "0.10.0", - "license": "Apache-2.0", - "status": "approved" + "ecosystem": "npm", + "name": "@creit-tech/stellar-wallets-kit", + "version": "2.4.0", + "license": "UNKNOWN", + "category": "review" }, { - "lock": "package-lock.json", - "path": "node_modules/@solana-program/token", - "version": "0.9.0", - "license": "Apache-2.0", - "status": "approved" + "ecosystem": "npm", + "name": "@creit.tech/xbull-wallet-connect", + "version": "0.4.0", + "license": "UNKNOWN", + "category": "review", + "repository": "https://github.com/Creit-Tech/xbull-wallet-connect" }, { - "lock": "package-lock.json", - "path": "node_modules/@solana/accounts", - "version": "5.5.1", - "license": "MIT", - "status": "approved" + "ecosystem": "npm", + "name": "@csstools/color-helpers", + "version": "6.1.0", + "license": "MIT-0", + "category": "approved", + "dev": true, + "repository": "https://github.com/csstools/postcss-plugins" }, { - "lock": "package-lock.json", - "path": "node_modules/@solana/addresses", - "version": "5.5.1", + "ecosystem": "npm", + "name": "@csstools/css-calc", + "version": "3.3.0", "license": "MIT", - "status": "approved" + "category": "approved", + "dev": true, + "repository": "https://github.com/csstools/postcss-plugins" }, { - "lock": "package-lock.json", - "path": "node_modules/@solana/assertions", - "version": "5.5.1", + "ecosystem": "npm", + "name": "@csstools/css-color-parser", + "version": "4.1.10", "license": "MIT", - "status": "approved" + "category": "approved", + "dev": true, + "repository": "https://github.com/csstools/postcss-plugins" }, { - "lock": "package-lock.json", - "path": "node_modules/@solana/buffer-layout", - "version": "4.0.1", + "ecosystem": "npm", + "name": "@csstools/css-parser-algorithms", + "version": "4.0.0", "license": "MIT", - "status": "approved" + "category": "approved", + "dev": true, + "repository": "https://github.com/csstools/postcss-plugins" }, { - "lock": "package-lock.json", - "path": "node_modules/@solana/codecs", - "version": "5.5.1", - "license": "MIT", - "status": "approved" + "ecosystem": "npm", + "name": "@csstools/css-syntax-patches-for-csstree", + "version": "1.1.7", + "license": "MIT-0", + "category": "approved", + "dev": true, + "repository": "https://github.com/csstools/postcss-plugins" }, { - "lock": "package-lock.json", - "path": "node_modules/@solana/codecs-core", - "version": "5.5.1", + "ecosystem": "npm", + "name": "@csstools/css-tokenizer", + "version": "4.0.0", "license": "MIT", - "status": "approved" + "category": "approved", + "dev": true, + "repository": "https://github.com/csstools/postcss-plugins" }, { - "lock": "package-lock.json", - "path": "node_modules/@solana/codecs-data-structures", - "version": "5.5.1", + "ecosystem": "npm", + "name": "@emnapi/core", + "version": "1.10.0", "license": "MIT", - "status": "approved" + "category": "approved", + "dev": true }, { - "lock": "package-lock.json", - "path": "node_modules/@solana/codecs-numbers", - "version": "5.5.1", + "ecosystem": "npm", + "name": "@emnapi/runtime", + "version": "1.10.0", "license": "MIT", - "status": "approved" + "category": "approved", + "dev": true }, { - "lock": "package-lock.json", - "path": "node_modules/@solana/codecs-strings", - "version": "5.5.1", + "ecosystem": "npm", + "name": "@emnapi/wasi-threads", + "version": "1.2.1", "license": "MIT", - "status": "approved" + "category": "approved", + "dev": true }, { - "lock": "package-lock.json", - "path": "node_modules/@solana/errors", - "version": "5.5.1", + "ecosystem": "npm", + "name": "@eslint-community/eslint-utils", + "version": "4.10.1", "license": "MIT", - "status": "approved" + "category": "approved", + "dev": true, + "repository": "https://github.com/eslint-community/eslint-utils" }, { - "lock": "package-lock.json", - "path": "node_modules/@solana/errors/node_modules/commander", - "version": "14.0.2", + "ecosystem": "npm", + "name": "@eslint-community/regexpp", + "version": "4.12.2", "license": "MIT", - "status": "approved" + "category": "approved", + "dev": true, + "repository": "https://github.com/eslint-community/regexpp" }, { - "lock": "package-lock.json", - "path": "node_modules/@solana/fast-stable-stringify", - "version": "5.5.1", - "license": "MIT", - "status": "approved" + "ecosystem": "npm", + "name": "@eslint/config-array", + "version": "0.21.2", + "license": "Apache-2.0", + "category": "approved", + "dev": true, + "repository": "https://github.com/eslint/rewrite" }, { - "lock": "package-lock.json", - "path": "node_modules/@solana/functional", - "version": "5.5.1", - "license": "MIT", - "status": "approved" + "ecosystem": "npm", + "name": "@eslint/config-helpers", + "version": "0.4.2", + "license": "Apache-2.0", + "category": "approved", + "dev": true, + "repository": "https://github.com/eslint/rewrite" }, { - "lock": "package-lock.json", - "path": "node_modules/@solana/instruction-plans", - "version": "5.5.1", - "license": "MIT", - "status": "approved" + "ecosystem": "npm", + "name": "@eslint/core", + "version": "0.17.0", + "license": "Apache-2.0", + "category": "approved", + "dev": true, + "repository": "https://github.com/eslint/rewrite" }, { - "lock": "package-lock.json", - "path": "node_modules/@solana/instructions", - "version": "5.5.1", + "ecosystem": "npm", + "name": "@eslint/eslintrc", + "version": "3.3.6", "license": "MIT", - "status": "approved" + "category": "approved", + "dev": true, + "repository": "eslint/eslintrc" }, { - "lock": "package-lock.json", - "path": "node_modules/@solana/keys", - "version": "5.5.1", + "ecosystem": "npm", + "name": "@eslint/js", + "version": "9.39.5", "license": "MIT", - "status": "approved" + "category": "approved", + "dev": true, + "repository": "https://github.com/eslint/eslint" }, { - "lock": "package-lock.json", - "path": "node_modules/@solana/kit", - "version": "5.5.1", - "license": "MIT", - "status": "approved" + "ecosystem": "npm", + "name": "@eslint/object-schema", + "version": "2.1.7", + "license": "Apache-2.0", + "category": "approved", + "dev": true, + "repository": "https://github.com/eslint/rewrite" }, { - "lock": "package-lock.json", - "path": "node_modules/@solana/nominal-types", - "version": "5.5.1", - "license": "MIT", - "status": "approved" + "ecosystem": "npm", + "name": "@eslint/plugin-kit", + "version": "0.4.1", + "license": "Apache-2.0", + "category": "approved", + "dev": true, + "repository": "https://github.com/eslint/rewrite" }, { - "lock": "package-lock.json", - "path": "node_modules/@solana/offchain-messages", - "version": "5.5.1", + "ecosystem": "npm", + "name": "@exodus/bytes", + "version": "1.15.1", "license": "MIT", - "status": "approved" + "category": "approved", + "dev": true, + "repository": "https://github.com/ExodusOSS/bytes" }, { - "lock": "package-lock.json", - "path": "node_modules/@solana/options", - "version": "5.5.1", - "license": "MIT", - "status": "approved" + "ecosystem": "npm", + "name": "@hot-wallet/sdk", + "version": "1.0.11", + "license": "UNKNOWN", + "category": "review" }, { - "lock": "package-lock.json", - "path": "node_modules/@solana/plugin-core", - "version": "5.5.1", - "license": "MIT", - "status": "approved" + "ecosystem": "npm", + "name": "@humanfs/core", + "version": "0.19.2", + "license": "Apache-2.0", + "category": "approved", + "dev": true, + "repository": "https://github.com/humanwhocodes/humanfs" }, { - "lock": "package-lock.json", - "path": "node_modules/@solana/programs", - "version": "5.5.1", - "license": "MIT", - "status": "approved" + "ecosystem": "npm", + "name": "@humanfs/node", + "version": "0.16.8", + "license": "Apache-2.0", + "category": "approved", + "dev": true, + "repository": "https://github.com/humanwhocodes/humanfs" }, { - "lock": "package-lock.json", - "path": "node_modules/@solana/promises", - "version": "5.5.1", - "license": "MIT", - "status": "approved" + "ecosystem": "npm", + "name": "@humanfs/types", + "version": "0.15.0", + "license": "Apache-2.0", + "category": "approved", + "dev": true, + "repository": "https://github.com/humanwhocodes/humanfs" }, { - "lock": "package-lock.json", - "path": "node_modules/@solana/rpc", - "version": "5.5.1", - "license": "MIT", - "status": "approved" + "ecosystem": "npm", + "name": "@humanwhocodes/module-importer", + "version": "1.0.1", + "license": "Apache-2.0", + "category": "approved", + "dev": true, + "repository": "https://github.com/humanwhocodes/module-importer" }, { - "lock": "package-lock.json", - "path": "node_modules/@solana/rpc-api", - "version": "5.5.1", + "ecosystem": "npm", + "name": "@humanwhocodes/retry", + "version": "0.4.3", + "license": "Apache-2.0", + "category": "approved", + "dev": true, + "repository": "https://github.com/humanwhocodes/retry" + }, + { + "ecosystem": "npm", + "name": "@inquirer/ansi", + "version": "2.0.7", "license": "MIT", - "status": "approved" + "category": "approved", + "dev": true, + "repository": "https://github.com/SBoudrias/Inquirer.js" }, { - "lock": "package-lock.json", - "path": "node_modules/@solana/rpc-parsed-types", - "version": "5.5.1", + "ecosystem": "npm", + "name": "@inquirer/confirm", + "version": "6.2.0", "license": "MIT", - "status": "approved" + "category": "approved", + "dev": true, + "repository": "https://github.com/SBoudrias/Inquirer.js" }, { - "lock": "package-lock.json", - "path": "node_modules/@solana/rpc-spec", - "version": "5.5.1", + "ecosystem": "npm", + "name": "@inquirer/core", + "version": "12.0.0", "license": "MIT", - "status": "approved" + "category": "approved", + "dev": true, + "repository": "https://github.com/SBoudrias/Inquirer.js" }, { - "lock": "package-lock.json", - "path": "node_modules/@solana/rpc-spec-types", - "version": "5.5.1", + "ecosystem": "npm", + "name": "@inquirer/figures", + "version": "2.0.8", "license": "MIT", - "status": "approved" + "category": "approved", + "dev": true, + "repository": "https://github.com/SBoudrias/Inquirer.js" }, { - "lock": "package-lock.json", - "path": "node_modules/@solana/rpc-subscriptions", - "version": "5.5.1", + "ecosystem": "npm", + "name": "@inquirer/type", + "version": "4.0.7", "license": "MIT", - "status": "approved" + "category": "approved", + "dev": true, + "repository": "https://github.com/SBoudrias/Inquirer.js" }, { - "lock": "package-lock.json", - "path": "node_modules/@solana/rpc-subscriptions-api", - "version": "5.5.1", + "ecosystem": "npm", + "name": "@isaacs/cliui", + "version": "9.0.0", + "license": "BlueOak-1.0.0", + "category": "approved", + "dev": true, + "repository": "ssh://git@github.com:isaacs/cliui" + }, + { + "ecosystem": "npm", + "name": "@jest/diff-sequences", + "version": "30.4.0", "license": "MIT", - "status": "approved" + "category": "approved", + "dev": true, + "repository": "https://github.com/jestjs/jest" }, { - "lock": "package-lock.json", - "path": "node_modules/@solana/rpc-subscriptions-channel-websocket", - "version": "5.5.1", + "ecosystem": "npm", + "name": "@jest/get-type", + "version": "30.1.0", "license": "MIT", - "status": "approved" + "category": "approved", + "dev": true, + "repository": "https://github.com/jestjs/jest" }, { - "lock": "package-lock.json", - "path": "node_modules/@solana/rpc-subscriptions-spec", - "version": "5.5.1", + "ecosystem": "npm", + "name": "@jest/schemas", + "version": "30.4.1", "license": "MIT", - "status": "approved" + "category": "approved", + "dev": true, + "repository": "https://github.com/jestjs/jest" }, { - "lock": "package-lock.json", - "path": "node_modules/@solana/rpc-transformers", - "version": "5.5.1", + "ecosystem": "npm", + "name": "@jridgewell/gen-mapping", + "version": "0.3.13", "license": "MIT", - "status": "approved" + "category": "approved", + "dev": true, + "repository": "https://github.com/jridgewell/sourcemaps" }, { - "lock": "package-lock.json", - "path": "node_modules/@solana/rpc-transport-http", - "version": "5.5.1", + "ecosystem": "npm", + "name": "@jridgewell/remapping", + "version": "2.3.5", "license": "MIT", - "status": "approved" + "category": "approved", + "dev": true, + "repository": "https://github.com/jridgewell/sourcemaps" }, { - "lock": "package-lock.json", - "path": "node_modules/@solana/rpc-types", - "version": "5.5.1", + "ecosystem": "npm", + "name": "@jridgewell/resolve-uri", + "version": "3.1.2", "license": "MIT", - "status": "approved" + "category": "approved", + "dev": true, + "repository": "https://github.com/jridgewell/resolve-uri" }, { - "lock": "package-lock.json", - "path": "node_modules/@solana/signers", - "version": "5.5.1", + "ecosystem": "npm", + "name": "@jridgewell/source-map", + "version": "0.3.11", "license": "MIT", - "status": "approved" + "category": "approved", + "dev": true, + "repository": "https://github.com/jridgewell/sourcemaps" }, { - "lock": "package-lock.json", - "path": "node_modules/@solana/subscribable", - "version": "5.5.1", + "ecosystem": "npm", + "name": "@jridgewell/sourcemap-codec", + "version": "1.5.5", "license": "MIT", - "status": "approved" + "category": "approved", + "dev": true, + "repository": "https://github.com/jridgewell/sourcemaps" }, { - "lock": "package-lock.json", - "path": "node_modules/@solana/sysvars", - "version": "5.5.1", + "ecosystem": "npm", + "name": "@jridgewell/trace-mapping", + "version": "0.3.31", "license": "MIT", - "status": "approved" + "category": "approved", + "dev": true, + "repository": "https://github.com/jridgewell/sourcemaps" }, { - "lock": "package-lock.json", - "path": "node_modules/@solana/transaction-confirmation", - "version": "5.5.1", - "license": "MIT", - "status": "approved" + "ecosystem": "npm", + "name": "@jsr/std__encoding", + "version": "1.0.10", + "license": "UNKNOWN", + "category": "review" }, { - "lock": "package-lock.json", - "path": "node_modules/@solana/transaction-messages", - "version": "5.5.1", - "license": "MIT", - "status": "approved" + "ecosystem": "npm", + "name": "@ledgerhq/devices", + "version": "8.6.1", + "license": "Apache-2.0", + "category": "approved", + "repository": "https://github.com/LedgerHQ/ledger-live" }, { - "lock": "package-lock.json", - "path": "node_modules/@solana/transactions", - "version": "5.5.1", - "license": "MIT", - "status": "approved" + "ecosystem": "npm", + "name": "@ledgerhq/errors", + "version": "6.36.0", + "license": "Apache-2.0", + "category": "approved", + "repository": "https://github.com/LedgerHQ/ledger-live" }, { - "lock": "package-lock.json", - "path": "node_modules/@solana/wallet-adapter-base", - "version": "0.9.27", + "ecosystem": "npm", + "name": "@ledgerhq/hw-app-str", + "version": "7.2.8", "license": "Apache-2.0", - "status": "approved" + "category": "approved", + "repository": "https://github.com/LedgerHQ/ledger-live" }, { - "lock": "package-lock.json", - "path": "node_modules/@solana/wallet-standard-features", - "version": "1.4.0", + "ecosystem": "npm", + "name": "@ledgerhq/hw-transport", + "version": "6.31.12", "license": "Apache-2.0", - "status": "approved" + "category": "approved", + "repository": "https://github.com/LedgerHQ/ledger-live" }, { - "lock": "package-lock.json", - "path": "node_modules/@solana/web3.js", - "version": "1.98.4", - "license": "MIT", - "status": "approved" + "ecosystem": "npm", + "name": "@ledgerhq/hw-transport-webusb", + "version": "6.29.12", + "license": "Apache-2.0", + "category": "approved", + "repository": "https://github.com/LedgerHQ/ledger-live" }, { - "lock": "package-lock.json", - "path": "node_modules/@solana/web3.js/node_modules/@noble/hashes", - "version": "1.8.0", - "license": "MIT", - "status": "approved" + "ecosystem": "npm", + "name": "@ledgerhq/logs", + "version": "6.17.0", + "license": "Apache-2.0", + "category": "approved", + "repository": "https://github.com/LedgerHQ/ledger-live" }, { - "lock": "package-lock.json", - "path": "node_modules/@solana/web3.js/node_modules/@solana/codecs-core", - "version": "2.3.0", - "license": "MIT", - "status": "approved" + "ecosystem": "npm", + "name": "@lit-labs/ssr-dom-shim", + "version": "1.6.0", + "license": "BSD-3-Clause", + "category": "approved", + "repository": "https://github.com/lit/lit" }, { - "lock": "package-lock.json", - "path": "node_modules/@solana/web3.js/node_modules/@solana/codecs-numbers", - "version": "2.3.0", - "license": "MIT", - "status": "approved" + "ecosystem": "npm", + "name": "@lit/react", + "version": "1.0.8", + "license": "BSD-3-Clause", + "category": "approved", + "repository": "https://github.com/lit/lit" }, { - "lock": "package-lock.json", - "path": "node_modules/@solana/web3.js/node_modules/@solana/errors", - "version": "2.3.0", - "license": "MIT", - "status": "approved" + "ecosystem": "npm", + "name": "@lit/reactive-element", + "version": "2.1.2", + "license": "BSD-3-Clause", + "category": "approved", + "repository": "https://github.com/lit/lit" }, { - "lock": "package-lock.json", - "path": "node_modules/@solana/web3.js/node_modules/base-x", - "version": "3.0.11", - "license": "MIT", - "status": "approved" + "ecosystem": "npm", + "name": "@lobstrco/signer-extension-api", + "version": "2.0.0", + "license": "GPL-3.0", + "category": "excepted", + "repository": "ssh://git@github.com/Lobstrco/lobstr-browser-extension", + "exception": "GPL-3.0 via @creit-tech/stellar-wallets-kit; browser-extension messaging shim, tracked for replacement (#625)" }, { - "lock": "package-lock.json", - "path": "node_modules/@solana/web3.js/node_modules/borsh", - "version": "0.7.0", - "license": "Apache-2.0", - "status": "approved" + "ecosystem": "npm", + "name": "@mapbox/jsonlint-lines-primitives", + "version": "2.0.2", + "license": "UNKNOWN", + "category": "review", + "repository": "git://github.com/mapbox/jsonlint" }, { - "lock": "package-lock.json", - "path": "node_modules/@solana/web3.js/node_modules/bs58", - "version": "4.0.1", - "license": "MIT", - "status": "approved" + "ecosystem": "npm", + "name": "@mapbox/unitbezier", + "version": "0.0.1", + "license": "BSD-2-Clause", + "category": "approved", + "repository": "git@github.com:mapbox/unitbezier" }, { - "lock": "package-lock.json", - "path": "node_modules/@standard-schema/spec", - "version": "1.1.0", - "license": "MIT", - "status": "approved" + "ecosystem": "npm", + "name": "@maplibre/maplibre-gl-style-spec", + "version": "19.3.3", + "license": "ISC", + "category": "approved", + "repository": "git@github.com:maplibre/maplibre-gl-style-spec" }, { - "lock": "package-lock.json", - "path": "node_modules/@stellar/js-xdr", - "version": "4.0.0", - "license": "Apache-2.0", - "status": "approved" + "ecosystem": "npm", + "name": "@msgpack/msgpack", + "version": "3.1.2", + "license": "ISC", + "category": "approved", + "repository": "https://github.com/msgpack/msgpack-javascript" }, { - "lock": "package-lock.json", - "path": "node_modules/@stellar/stellar-sdk", - "version": "16.0.0", - "license": "Apache-2.0", - "status": "approved" + "ecosystem": "npm", + "name": "@msgpack/msgpack", + "version": "3.1.3", + "license": "ISC", + "category": "approved", + "repository": "https://github.com/msgpack/msgpack-javascript" }, { - "lock": "package-lock.json", - "path": "node_modules/@supabase/auth-js", - "version": "2.108.2", + "ecosystem": "npm", + "name": "@msgpackr-extract/msgpackr-extract-darwin-arm64", + "version": "3.0.4", "license": "MIT", - "status": "approved" + "category": "approved" }, { - "lock": "package-lock.json", - "path": "node_modules/@supabase/functions-js", - "version": "2.108.2", + "ecosystem": "npm", + "name": "@msgpackr-extract/msgpackr-extract-darwin-x64", + "version": "3.0.4", "license": "MIT", - "status": "approved" + "category": "approved" }, { - "lock": "package-lock.json", - "path": "node_modules/@supabase/phoenix", - "version": "0.4.4", + "ecosystem": "npm", + "name": "@msgpackr-extract/msgpackr-extract-linux-arm", + "version": "3.0.4", "license": "MIT", - "status": "approved" + "category": "approved" }, { - "lock": "package-lock.json", - "path": "node_modules/@supabase/postgrest-js", - "version": "2.108.2", + "ecosystem": "npm", + "name": "@msgpackr-extract/msgpackr-extract-linux-arm64", + "version": "3.0.4", "license": "MIT", - "status": "approved" + "category": "approved" }, { - "lock": "package-lock.json", - "path": "node_modules/@supabase/realtime-js", - "version": "2.108.2", + "ecosystem": "npm", + "name": "@msgpackr-extract/msgpackr-extract-linux-x64", + "version": "3.0.4", "license": "MIT", - "status": "approved" + "category": "approved", + "repository": "http://github.com/kriszyp/msgpackr-extract" }, { - "lock": "package-lock.json", - "path": "node_modules/@supabase/storage-js", - "version": "2.108.2", + "ecosystem": "npm", + "name": "@msgpackr-extract/msgpackr-extract-win32-x64", + "version": "3.0.4", "license": "MIT", - "status": "approved" + "category": "approved" }, { - "lock": "package-lock.json", - "path": "node_modules/@supabase/supabase-js", - "version": "2.108.2", + "ecosystem": "npm", + "name": "@mswjs/interceptors", + "version": "0.41.9", "license": "MIT", - "status": "approved" + "category": "approved", + "dev": true, + "repository": "https://github.com/mswjs/interceptors" }, { - "lock": "package-lock.json", - "path": "node_modules/@swc/helpers", - "version": "0.5.23", - "license": "Apache-2.0", - "status": "approved" + "ecosystem": "npm", + "name": "@napi-rs/lzma-linux-x64-gnu", + "version": "1.5.1", + "license": "MIT", + "category": "approved", + "dev": true, + "repository": "https://github.com/Brooooooklyn/lzma" }, { - "lock": "package-lock.json", - "path": "node_modules/@testing-library/jest-dom", - "version": "7.0.0", + "ecosystem": "npm", + "name": "@napi-rs/wasm-runtime", + "version": "1.1.5", "license": "MIT", - "status": "approved" + "category": "approved", + "dev": true }, { - "lock": "package-lock.json", - "path": "node_modules/@testing-library/jest-dom/node_modules/dom-accessibility-api", - "version": "0.6.3", - "license": "MIT", - "status": "approved" + "ecosystem": "npm", + "name": "@near-js/crypto", + "version": "1.4.2", + "license": "ISC", + "category": "approved" }, { - "lock": "package-lock.json", - "path": "node_modules/@testing-library/react", - "version": "16.3.2", - "license": "MIT", - "status": "approved" + "ecosystem": "npm", + "name": "@near-js/types", + "version": "0.3.1", + "license": "ISC", + "category": "approved" }, { - "lock": "package-lock.json", - "path": "node_modules/@trezor/connect-plugin-stellar", - "version": "10.0.0-alpha.1", - "license": "SEE LICENSE IN LICENSE.md", - "status": "review" + "ecosystem": "npm", + "name": "@near-js/utils", + "version": "1.1.0", + "license": "ISC", + "category": "approved" }, { - "lock": "package-lock.json", - "path": "node_modules/@trezor/connect-plugin-stellar/node_modules/@trezor/utils", - "version": "10.0.0-alpha.1", - "license": "MIT", - "status": "approved" + "ecosystem": "npm", + "name": "@near-wallet-selector/core", + "version": "8.10.2", + "license": "UNKNOWN", + "category": "review", + "repository": "https://github.com/near/wallet-selector" }, { - "lock": "package-lock.json", - "path": "node_modules/@trezor/connect-plugin-stellar/node_modules/bignumber.js", - "version": "9.3.1", + "ecosystem": "npm", + "name": "@noble/ciphers", + "version": "1.3.0", "license": "MIT", - "status": "approved" + "category": "approved", + "repository": "https://github.com/paulmillr/noble-ciphers" }, { - "lock": "package-lock.json", - "path": "node_modules/@trezor/connect-web", - "version": "10.0.0-alpha.1", + "ecosystem": "npm", + "name": "@noble/curves", + "version": "1.8.0", "license": "MIT", - "status": "approved" + "category": "approved", + "repository": "https://github.com/paulmillr/noble-curves" }, { - "lock": "package-lock.json", - "path": "node_modules/@trezor/connect-web/node_modules/@sinclair/typebox", - "version": "0.34.49", + "ecosystem": "npm", + "name": "@noble/curves", + "version": "1.8.1", "license": "MIT", - "status": "approved" + "category": "approved", + "repository": "https://github.com/paulmillr/noble-curves" }, { - "lock": "package-lock.json", - "path": "node_modules/@trezor/connect-web/node_modules/@trezor/connect-common", - "version": "10.0.0-alpha.1", + "ecosystem": "npm", + "name": "@noble/curves", + "version": "1.9.1", "license": "MIT", - "status": "approved" + "category": "approved", + "repository": "https://github.com/paulmillr/noble-curves" }, { - "lock": "package-lock.json", - "path": "node_modules/@trezor/connect-web/node_modules/@trezor/device-utils", - "version": "10.0.0-alpha.1", + "ecosystem": "npm", + "name": "@noble/curves", + "version": "1.9.7", "license": "MIT", - "status": "approved" + "category": "approved", + "repository": "https://github.com/paulmillr/noble-curves" }, { - "lock": "package-lock.json", - "path": "node_modules/@trezor/connect-web/node_modules/@trezor/protobuf", - "version": "10.0.0-alpha.1", + "ecosystem": "npm", + "name": "@noble/ed25519", + "version": "3.1.0", "license": "MIT", - "status": "approved" + "category": "approved", + "repository": "https://github.com/paulmillr/noble-ed25519" }, { - "lock": "package-lock.json", - "path": "node_modules/@trezor/connect-web/node_modules/@trezor/protocol", - "version": "10.0.0-alpha.1", + "ecosystem": "npm", + "name": "@noble/hashes", + "version": "1.4.0", "license": "MIT", - "status": "approved" + "category": "approved", + "repository": "https://github.com/paulmillr/noble-hashes" }, { - "lock": "package-lock.json", - "path": "node_modules/@trezor/connect-web/node_modules/@trezor/schema-utils", - "version": "10.0.0-alpha.1", + "ecosystem": "npm", + "name": "@noble/hashes", + "version": "1.7.0", "license": "MIT", - "status": "approved" + "category": "approved", + "repository": "https://github.com/paulmillr/noble-hashes" }, { - "lock": "package-lock.json", - "path": "node_modules/@trezor/connect-web/node_modules/@trezor/type-utils", - "version": "10.0.0-alpha.1", + "ecosystem": "npm", + "name": "@noble/hashes", + "version": "1.7.1", "license": "MIT", - "status": "approved" + "category": "approved", + "repository": "https://github.com/paulmillr/noble-hashes" }, { - "lock": "package-lock.json", - "path": "node_modules/@trezor/connect-web/node_modules/@trezor/utils", - "version": "10.0.0-alpha.1", + "ecosystem": "npm", + "name": "@noble/hashes", + "version": "1.8.0", "license": "MIT", - "status": "approved" + "category": "approved", + "repository": "https://github.com/paulmillr/noble-hashes" }, { - "lock": "package-lock.json", - "path": "node_modules/@trezor/connect-web/node_modules/@trezor/websocket-client", - "version": "10.0.0-alpha.1", + "ecosystem": "npm", + "name": "@noble/hashes", + "version": "2.2.0", "license": "MIT", - "status": "approved" + "category": "approved", + "repository": "https://github.com/paulmillr/noble-hashes" }, { - "lock": "package-lock.json", - "path": "node_modules/@trezor/connect-web/node_modules/bignumber.js", - "version": "9.3.1", + "ecosystem": "npm", + "name": "@noir-lang/acvm_js", + "version": "1.0.0-beta.9", "license": "MIT", - "status": "approved" + "category": "approved", + "repository": "https://github.com/noir-lang/noir" }, { - "lock": "package-lock.json", - "path": "node_modules/@trickfilm400/rollup-plugin-off-main-thread", - "version": "3.0.0-pre1", - "license": "Apache-2.0", - "status": "approved" + "ecosystem": "npm", + "name": "@noir-lang/noir_js", + "version": "1.0.0-beta.9", + "license": "(MIT OR Apache-2.0)", + "category": "approved", + "repository": "https://github.com/noir-lang/noir" }, { - "lock": "package-lock.json", - "path": "node_modules/@tybys/wasm-util", - "version": "0.10.2", - "license": "MIT", - "status": "approved" + "ecosystem": "npm", + "name": "@noir-lang/noirc_abi", + "version": "1.0.0-beta.9", + "license": "(MIT OR Apache-2.0)", + "category": "approved", + "repository": "https://github.com/noir-lang/noir" }, { - "lock": "package-lock.json", - "path": "node_modules/@types/body-parser", - "version": "1.19.6", - "license": "MIT", - "status": "approved" + "ecosystem": "npm", + "name": "@noir-lang/types", + "version": "1.0.0-beta.9", + "license": "(MIT OR Apache-2.0)", + "category": "approved", + "repository": "https://github.com/noir-lang/noir" }, { - "lock": "package-lock.json", - "path": "node_modules/@types/chai", - "version": "5.2.3", + "ecosystem": "npm", + "name": "@open-draft/deferred-promise", + "version": "2.2.0", "license": "MIT", - "status": "approved" + "category": "approved", + "dev": true, + "repository": "https://github.com/open-draft/deferred-promise" }, { - "lock": "package-lock.json", - "path": "node_modules/@types/connect", - "version": "3.4.38", + "ecosystem": "npm", + "name": "@open-draft/deferred-promise", + "version": "3.0.0", "license": "MIT", - "status": "approved" + "category": "approved", + "dev": true, + "repository": "https://github.com/open-draft/deferred-promise" }, { - "lock": "package-lock.json", - "path": "node_modules/@types/cors", - "version": "2.8.19", + "ecosystem": "npm", + "name": "@open-draft/logger", + "version": "0.3.0", "license": "MIT", - "status": "approved" + "category": "approved", + "dev": true, + "repository": "https://github.com/open-draft/logger" }, { - "lock": "package-lock.json", - "path": "node_modules/@types/deep-eql", - "version": "4.0.2", + "ecosystem": "npm", + "name": "@open-draft/until", + "version": "2.1.0", "license": "MIT", - "status": "approved" + "category": "approved", + "dev": true, + "repository": "open-draft/until" }, { - "lock": "package-lock.json", - "path": "node_modules/@types/estree", - "version": "1.0.9", + "ecosystem": "npm", + "name": "@oxc-project/types", + "version": "0.133.0", "license": "MIT", - "status": "approved" + "category": "approved", + "dev": true, + "repository": "https://github.com/oxc-project/oxc" }, { - "lock": "package-lock.json", - "path": "node_modules/@types/express", - "version": "4.17.25", + "ecosystem": "npm", + "name": "@paralleldrive/cuid2", + "version": "2.3.1", "license": "MIT", - "status": "approved" + "category": "approved", + "dev": true, + "repository": "https://github.com/ericelliott/cuid2" }, { - "lock": "package-lock.json", - "path": "node_modules/@types/express-serve-static-core", - "version": "4.19.9", + "ecosystem": "npm", + "name": "@phosphor-icons/webcomponents", + "version": "2.1.5", "license": "MIT", - "status": "approved" + "category": "approved", + "repository": "https://github.com/phosphor-icons/webcomponents" }, { - "lock": "package-lock.json", - "path": "node_modules/@types/http-errors", - "version": "2.0.5", + "ecosystem": "npm", + "name": "@pinojs/redact", + "version": "0.4.0", "license": "MIT", - "status": "approved" + "category": "approved", + "repository": "https://github.com/pinojs/redact" }, { - "lock": "package-lock.json", - "path": "node_modules/@types/json-schema", - "version": "7.0.15", - "license": "MIT", - "status": "approved" + "ecosystem": "npm", + "name": "@playwright/test", + "version": "1.62.1", + "license": "Apache-2.0", + "category": "approved", + "dev": true, + "repository": "https://github.com/microsoft/playwright" }, { - "lock": "package-lock.json", - "path": "node_modules/@types/mime", - "version": "1.3.5", + "ecosystem": "npm", + "name": "@preact/signals", + "version": "2.9.0", "license": "MIT", - "status": "approved" + "category": "approved", + "repository": "https://github.com/preactjs/signals" }, { - "lock": "package-lock.json", - "path": "node_modules/@types/node", - "version": "22.20.4", + "ecosystem": "npm", + "name": "@preact/signals-core", + "version": "1.14.3", "license": "MIT", - "status": "approved" + "category": "approved", + "repository": "https://github.com/preactjs/signals" }, { - "lock": "package-lock.json", - "path": "node_modules/@types/node/node_modules/undici-types", - "version": "6.21.0", - "license": "MIT", - "status": "approved" + "ecosystem": "npm", + "name": "@reown/appkit", + "version": "1.8.19", + "license": "SEE LICENSE IN LICENSE.md", + "category": "review", + "repository": "https://github.com/reown-com/appkit" }, { - "lock": "package-lock.json", - "path": "node_modules/@types/pg", - "version": "8.23.1", - "license": "MIT", - "status": "approved" + "ecosystem": "npm", + "name": "@reown/appkit-common", + "version": "1.8.19", + "license": "SEE LICENSE IN LICENSE.md", + "category": "review", + "repository": "https://github.com/reown-com/appkit" }, { - "lock": "package-lock.json", - "path": "node_modules/@types/qs", - "version": "6.15.1", - "license": "MIT", - "status": "approved" + "ecosystem": "npm", + "name": "@reown/appkit-controllers", + "version": "1.8.19", + "license": "SEE LICENSE IN LICENSE.md", + "category": "review", + "repository": "https://github.com/reown-com/appkit" }, { - "lock": "package-lock.json", - "path": "node_modules/@types/range-parser", - "version": "1.2.7", - "license": "MIT", - "status": "approved" + "ecosystem": "npm", + "name": "@reown/appkit-pay", + "version": "1.8.19", + "license": "SEE LICENSE IN LICENSE.md", + "category": "review", + "repository": "https://github.com/reown-com/appkit" }, { - "lock": "package-lock.json", - "path": "node_modules/@types/react", - "version": "19.3.0", - "license": "MIT", - "status": "approved" + "ecosystem": "npm", + "name": "@reown/appkit-polyfills", + "version": "1.8.19", + "license": "SEE LICENSE IN LICENSE.md", + "category": "review", + "repository": "https://github.com/reown-com/appkit" }, { - "lock": "package-lock.json", - "path": "node_modules/@types/react-dom", - "version": "19.3.0", - "license": "MIT", - "status": "approved" + "ecosystem": "npm", + "name": "@reown/appkit-scaffold-ui", + "version": "1.8.19", + "license": "SEE LICENSE IN LICENSE.md", + "category": "review", + "repository": "https://github.com/reown-com/appkit" }, { - "lock": "package-lock.json", - "path": "node_modules/@types/resolve", - "version": "1.20.2", - "license": "MIT", - "status": "approved" + "ecosystem": "npm", + "name": "@reown/appkit-ui", + "version": "1.8.19", + "license": "SEE LICENSE IN LICENSE.md", + "category": "review", + "repository": "https://github.com/reown-com/appkit" }, { - "lock": "package-lock.json", - "path": "node_modules/@types/send", - "version": "1.2.1", + "ecosystem": "npm", + "name": "@reown/appkit-utils", + "version": "1.8.19", + "license": "SEE LICENSE IN LICENSE.md", + "category": "review", + "repository": "https://github.com/reown-com/appkit" + }, + { + "ecosystem": "npm", + "name": "@reown/appkit-wallet", + "version": "1.8.19", + "license": "SEE LICENSE IN LICENSE.md", + "category": "review", + "repository": "https://github.com/reown-com/appkit" + }, + { + "ecosystem": "npm", + "name": "@rolldown/binding-android-arm64", + "version": "1.0.3", "license": "MIT", - "status": "approved" + "category": "approved", + "dev": true }, { - "lock": "package-lock.json", - "path": "node_modules/@types/serve-static", - "version": "1.15.10", + "ecosystem": "npm", + "name": "@rolldown/binding-darwin-arm64", + "version": "1.0.3", "license": "MIT", - "status": "approved" + "category": "approved", + "dev": true }, { - "lock": "package-lock.json", - "path": "node_modules/@types/serve-static/node_modules/@types/send", - "version": "0.17.6", + "ecosystem": "npm", + "name": "@rolldown/binding-darwin-x64", + "version": "1.0.3", "license": "MIT", - "status": "approved" + "category": "approved", + "dev": true }, { - "lock": "package-lock.json", - "path": "node_modules/@types/set-cookie-parser", - "version": "2.4.10", + "ecosystem": "npm", + "name": "@rolldown/binding-freebsd-x64", + "version": "1.0.3", "license": "MIT", - "status": "approved" + "category": "approved", + "dev": true }, { - "lock": "package-lock.json", - "path": "node_modules/@types/statuses", - "version": "2.0.6", + "ecosystem": "npm", + "name": "@rolldown/binding-linux-arm-gnueabihf", + "version": "1.0.3", "license": "MIT", - "status": "approved" + "category": "approved", + "dev": true }, { - "lock": "package-lock.json", - "path": "node_modules/@types/trusted-types", - "version": "2.0.7", + "ecosystem": "npm", + "name": "@rolldown/binding-linux-arm64-gnu", + "version": "1.0.3", "license": "MIT", - "status": "approved" + "category": "approved", + "dev": true }, { - "lock": "package-lock.json", - "path": "node_modules/@types/uuid", - "version": "10.0.0", + "ecosystem": "npm", + "name": "@rolldown/binding-linux-arm64-musl", + "version": "1.0.3", "license": "MIT", - "status": "approved" + "category": "approved", + "dev": true }, { - "lock": "package-lock.json", - "path": "node_modules/@types/ws", - "version": "7.4.7", + "ecosystem": "npm", + "name": "@rolldown/binding-linux-ppc64-gnu", + "version": "1.0.3", "license": "MIT", - "status": "approved" + "category": "approved", + "dev": true }, { - "lock": "package-lock.json", - "path": "node_modules/@vis.gl/react-mapbox", - "version": "8.1.1", + "ecosystem": "npm", + "name": "@rolldown/binding-linux-s390x-gnu", + "version": "1.0.3", "license": "MIT", - "status": "approved" + "category": "approved", + "dev": true }, { - "lock": "package-lock.json", - "path": "node_modules/@vis.gl/react-maplibre", - "version": "8.1.1", + "ecosystem": "npm", + "name": "@rolldown/binding-linux-x64-gnu", + "version": "1.0.3", "license": "MIT", - "status": "approved" + "category": "approved", + "dev": true, + "repository": "https://github.com/rolldown/rolldown" }, { - "lock": "package-lock.json", - "path": "node_modules/@vitejs/plugin-react", - "version": "6.0.2", + "ecosystem": "npm", + "name": "@rolldown/binding-linux-x64-musl", + "version": "1.0.3", "license": "MIT", - "status": "approved" + "category": "approved", + "dev": true, + "repository": "https://github.com/rolldown/rolldown" }, { - "lock": "package-lock.json", - "path": "node_modules/@vitest/expect", - "version": "4.1.10", + "ecosystem": "npm", + "name": "@rolldown/binding-openharmony-arm64", + "version": "1.0.3", "license": "MIT", - "status": "approved" + "category": "approved", + "dev": true }, { - "lock": "package-lock.json", - "path": "node_modules/@vitest/mocker", - "version": "4.1.10", + "ecosystem": "npm", + "name": "@rolldown/binding-wasm32-wasi", + "version": "1.0.3", "license": "MIT", - "status": "approved" + "category": "approved", + "dev": true }, { - "lock": "package-lock.json", - "path": "node_modules/@vitest/pretty-format", - "version": "4.1.10", + "ecosystem": "npm", + "name": "@rolldown/binding-win32-arm64-msvc", + "version": "1.0.3", "license": "MIT", - "status": "approved" + "category": "approved", + "dev": true }, { - "lock": "package-lock.json", - "path": "node_modules/@vitest/runner", - "version": "4.1.10", + "ecosystem": "npm", + "name": "@rolldown/binding-win32-x64-msvc", + "version": "1.0.3", "license": "MIT", - "status": "approved" + "category": "approved", + "dev": true }, { - "lock": "package-lock.json", - "path": "node_modules/@vitest/snapshot", - "version": "4.1.10", + "ecosystem": "npm", + "name": "@rolldown/pluginutils", + "version": "1.0.1", "license": "MIT", - "status": "approved" + "category": "approved", + "dev": true, + "repository": "https://github.com/rolldown/plugins" }, { - "lock": "package-lock.json", - "path": "node_modules/@vitest/spy", - "version": "4.1.10", + "ecosystem": "npm", + "name": "@rollup/plugin-babel", + "version": "6.1.0", "license": "MIT", - "status": "approved" + "category": "approved", + "dev": true, + "repository": "rollup/plugins" }, { - "lock": "package-lock.json", - "path": "node_modules/@vitest/utils", - "version": "4.1.10", + "ecosystem": "npm", + "name": "@rollup/plugin-node-resolve", + "version": "16.0.3", "license": "MIT", - "status": "approved" + "category": "approved", + "dev": true, + "repository": "rollup/plugins" }, { - "lock": "package-lock.json", - "path": "node_modules/@wallet-standard/base", - "version": "1.1.1", - "license": "Apache-2.0", - "status": "approved" + "ecosystem": "npm", + "name": "@rollup/plugin-replace", + "version": "6.0.3", + "license": "MIT", + "category": "approved", + "dev": true, + "repository": "rollup/plugins" }, { - "lock": "package-lock.json", - "path": "node_modules/@wallet-standard/features", - "version": "1.1.1", - "license": "Apache-2.0", - "status": "approved" + "ecosystem": "npm", + "name": "@rollup/plugin-terser", + "version": "1.0.0", + "license": "MIT", + "category": "approved", + "dev": true, + "repository": "rollup/plugins" }, { - "lock": "package-lock.json", - "path": "node_modules/@wallet-standard/wallet", - "version": "1.1.0", - "license": "Apache-2.0", - "status": "approved" + "ecosystem": "npm", + "name": "@rollup/pluginutils", + "version": "5.4.0", + "license": "MIT", + "category": "approved", + "dev": true, + "repository": "rollup/plugins" }, { - "lock": "package-lock.json", - "path": "node_modules/@walletconnect/environment", - "version": "1.0.1", + "ecosystem": "npm", + "name": "@rollup/rollup-android-arm-eabi", + "version": "4.63.0", "license": "MIT", - "status": "approved" + "category": "approved", + "dev": true }, { - "lock": "package-lock.json", - "path": "node_modules/@walletconnect/environment/node_modules/tslib", - "version": "1.14.1", - "license": "0BSD", - "status": "approved" + "ecosystem": "npm", + "name": "@rollup/rollup-android-arm64", + "version": "4.63.0", + "license": "MIT", + "category": "approved", + "dev": true }, { - "lock": "package-lock.json", - "path": "node_modules/@walletconnect/events", - "version": "1.0.1", + "ecosystem": "npm", + "name": "@rollup/rollup-darwin-arm64", + "version": "4.63.0", "license": "MIT", - "status": "approved" + "category": "approved", + "dev": true }, { - "lock": "package-lock.json", - "path": "node_modules/@walletconnect/events/node_modules/tslib", - "version": "1.14.1", - "license": "0BSD", - "status": "approved" + "ecosystem": "npm", + "name": "@rollup/rollup-darwin-x64", + "version": "4.63.0", + "license": "MIT", + "category": "approved", + "dev": true }, { - "lock": "package-lock.json", - "path": "node_modules/@walletconnect/heartbeat", - "version": "1.2.2", + "ecosystem": "npm", + "name": "@rollup/rollup-freebsd-arm64", + "version": "4.63.0", "license": "MIT", - "status": "approved" + "category": "approved", + "dev": true }, { - "lock": "package-lock.json", - "path": "node_modules/@walletconnect/jsonrpc-http-connection", - "version": "1.0.8", + "ecosystem": "npm", + "name": "@rollup/rollup-freebsd-x64", + "version": "4.63.0", "license": "MIT", - "status": "approved" + "category": "approved", + "dev": true }, { - "lock": "package-lock.json", - "path": "node_modules/@walletconnect/jsonrpc-provider", - "version": "1.0.14", + "ecosystem": "npm", + "name": "@rollup/rollup-linux-arm-gnueabihf", + "version": "4.63.0", "license": "MIT", - "status": "approved" + "category": "approved", + "dev": true }, { - "lock": "package-lock.json", - "path": "node_modules/@walletconnect/jsonrpc-types", - "version": "1.0.4", + "ecosystem": "npm", + "name": "@rollup/rollup-linux-arm-musleabihf", + "version": "4.63.0", "license": "MIT", - "status": "approved" + "category": "approved", + "dev": true }, { - "lock": "package-lock.json", - "path": "node_modules/@walletconnect/jsonrpc-utils", - "version": "1.0.8", + "ecosystem": "npm", + "name": "@rollup/rollup-linux-arm64-gnu", + "version": "4.63.0", "license": "MIT", - "status": "approved" + "category": "approved", + "dev": true }, { - "lock": "package-lock.json", - "path": "node_modules/@walletconnect/jsonrpc-utils/node_modules/tslib", - "version": "1.14.1", - "license": "0BSD", - "status": "approved" + "ecosystem": "npm", + "name": "@rollup/rollup-linux-arm64-musl", + "version": "4.63.0", + "license": "MIT", + "category": "approved", + "dev": true }, { - "lock": "package-lock.json", - "path": "node_modules/@walletconnect/jsonrpc-ws-connection", - "version": "1.0.16", + "ecosystem": "npm", + "name": "@rollup/rollup-linux-loong64-gnu", + "version": "4.63.0", "license": "MIT", - "status": "approved" + "category": "approved", + "dev": true }, { - "lock": "package-lock.json", - "path": "node_modules/@walletconnect/jsonrpc-ws-connection/node_modules/ws", - "version": "7.5.11", + "ecosystem": "npm", + "name": "@rollup/rollup-linux-loong64-musl", + "version": "4.63.0", "license": "MIT", - "status": "approved" + "category": "approved", + "dev": true }, { - "lock": "package-lock.json", - "path": "node_modules/@walletconnect/keyvaluestorage", - "version": "1.1.1", + "ecosystem": "npm", + "name": "@rollup/rollup-linux-ppc64-gnu", + "version": "4.63.0", "license": "MIT", - "status": "approved" + "category": "approved", + "dev": true }, { - "lock": "package-lock.json", - "path": "node_modules/@walletconnect/logger", - "version": "3.0.2", + "ecosystem": "npm", + "name": "@rollup/rollup-linux-ppc64-musl", + "version": "4.63.0", "license": "MIT", - "status": "approved" + "category": "approved", + "dev": true }, { - "lock": "package-lock.json", - "path": "node_modules/@walletconnect/relay-api", - "version": "1.0.11", + "ecosystem": "npm", + "name": "@rollup/rollup-linux-riscv64-gnu", + "version": "4.63.0", "license": "MIT", - "status": "approved" + "category": "approved", + "dev": true }, { - "lock": "package-lock.json", - "path": "node_modules/@walletconnect/relay-auth", - "version": "1.1.0", + "ecosystem": "npm", + "name": "@rollup/rollup-linux-riscv64-musl", + "version": "4.63.0", "license": "MIT", - "status": "approved" + "category": "approved", + "dev": true }, { - "lock": "package-lock.json", - "path": "node_modules/@walletconnect/relay-auth/node_modules/@noble/hashes", - "version": "1.7.0", + "ecosystem": "npm", + "name": "@rollup/rollup-linux-s390x-gnu", + "version": "4.63.0", "license": "MIT", - "status": "approved" + "category": "approved", + "dev": true }, { - "lock": "package-lock.json", - "path": "node_modules/@walletconnect/safe-json", - "version": "1.0.2", + "ecosystem": "npm", + "name": "@rollup/rollup-linux-x64-gnu", + "version": "4.63.0", "license": "MIT", - "status": "approved" + "category": "approved", + "dev": true, + "repository": "https://github.com/rollup/rollup" }, { - "lock": "package-lock.json", - "path": "node_modules/@walletconnect/safe-json/node_modules/tslib", - "version": "1.14.1", - "license": "0BSD", - "status": "approved" + "ecosystem": "npm", + "name": "@rollup/rollup-linux-x64-musl", + "version": "4.63.0", + "license": "MIT", + "category": "approved", + "dev": true, + "repository": "https://github.com/rollup/rollup" }, { - "lock": "package-lock.json", - "path": "node_modules/@walletconnect/sign-client", - "version": "2.23.7", - "license": "SEE LICENSE IN LICENSE.md", - "status": "review" + "ecosystem": "npm", + "name": "@rollup/rollup-openbsd-x64", + "version": "4.63.0", + "license": "MIT", + "category": "approved", + "dev": true }, { - "lock": "package-lock.json", - "path": "node_modules/@walletconnect/sign-client/node_modules/@noble/curves", - "version": "1.9.7", + "ecosystem": "npm", + "name": "@rollup/rollup-openharmony-arm64", + "version": "4.63.0", "license": "MIT", - "status": "approved" + "category": "approved", + "dev": true }, { - "lock": "package-lock.json", - "path": "node_modules/@walletconnect/sign-client/node_modules/@noble/hashes", - "version": "1.8.0", + "ecosystem": "npm", + "name": "@rollup/rollup-win32-arm64-msvc", + "version": "4.63.0", "license": "MIT", - "status": "approved" + "category": "approved", + "dev": true }, { - "lock": "package-lock.json", - "path": "node_modules/@walletconnect/sign-client/node_modules/@walletconnect/core", - "version": "2.23.7", - "license": "SEE LICENSE IN LICENSE.md", - "status": "review" + "ecosystem": "npm", + "name": "@rollup/rollup-win32-ia32-msvc", + "version": "4.63.0", + "license": "MIT", + "category": "approved", + "dev": true }, { - "lock": "package-lock.json", - "path": "node_modules/@walletconnect/sign-client/node_modules/@walletconnect/utils", - "version": "2.23.7", - "license": "SEE LICENSE IN LICENSE.md", - "status": "review" + "ecosystem": "npm", + "name": "@rollup/rollup-win32-x64-gnu", + "version": "4.63.0", + "license": "MIT", + "category": "approved", + "dev": true }, { - "lock": "package-lock.json", - "path": "node_modules/@walletconnect/sign-client/node_modules/abitype", - "version": "1.2.4", + "ecosystem": "npm", + "name": "@rollup/rollup-win32-x64-msvc", + "version": "4.63.0", "license": "MIT", - "status": "approved" + "category": "approved", + "dev": true }, { - "lock": "package-lock.json", - "path": "node_modules/@walletconnect/sign-client/node_modules/ox", - "version": "0.9.3", + "ecosystem": "npm", + "name": "@safe-global/safe-apps-provider", + "version": "0.18.6", "license": "MIT", - "status": "approved" + "category": "approved", + "repository": "https://github.com/safe-global/safe-apps-sdk" }, { - "lock": "package-lock.json", - "path": "node_modules/@walletconnect/sign-client/node_modules/ox/node_modules/@noble/curves", - "version": "1.9.1", + "ecosystem": "npm", + "name": "@safe-global/safe-apps-sdk", + "version": "9.1.0", "license": "MIT", - "status": "approved" + "category": "approved", + "repository": "https://github.com/safe-global/safe-apps-sdk" }, { - "lock": "package-lock.json", - "path": "node_modules/@walletconnect/time", - "version": "1.0.2", + "ecosystem": "npm", + "name": "@safe-global/safe-gateway-typescript-sdk", + "version": "3.23.1", "license": "MIT", - "status": "approved" + "category": "approved", + "repository": "git@github.com:safe-global/safe-gateway-typescript-sdk" }, { - "lock": "package-lock.json", - "path": "node_modules/@walletconnect/time/node_modules/tslib", - "version": "1.14.1", - "license": "0BSD", - "status": "approved" + "ecosystem": "npm", + "name": "@scure/base", + "version": "1.2.6", + "license": "MIT", + "category": "approved", + "repository": "https://github.com/paulmillr/scure-base" }, { - "lock": "package-lock.json", - "path": "node_modules/@walletconnect/types", - "version": "2.23.7", - "license": "SEE LICENSE IN LICENSE.md", - "status": "review" + "ecosystem": "npm", + "name": "@scure/bip32", + "version": "1.7.0", + "license": "MIT", + "category": "approved", + "repository": "https://github.com/paulmillr/scure-bip32" }, { - "lock": "package-lock.json", - "path": "node_modules/@walletconnect/universal-provider", - "version": "2.23.7", - "license": "SEE LICENSE IN LICENSE.md", - "status": "review" + "ecosystem": "npm", + "name": "@scure/bip39", + "version": "1.6.0", + "license": "MIT", + "category": "approved", + "repository": "https://github.com/paulmillr/scure-bip39" }, { - "lock": "package-lock.json", - "path": "node_modules/@walletconnect/universal-provider/node_modules/@noble/curves", - "version": "1.9.7", + "ecosystem": "npm", + "name": "@sinclair/typebox", + "version": "0.34.49", "license": "MIT", - "status": "approved" + "category": "approved", + "repository": "https://github.com/sinclairzx81/sinclair-typebox" }, { - "lock": "package-lock.json", - "path": "node_modules/@walletconnect/universal-provider/node_modules/@noble/hashes", - "version": "1.8.0", + "ecosystem": "npm", + "name": "@sinclair/typebox", + "version": "0.34.52", "license": "MIT", - "status": "approved" + "category": "approved", + "dev": true, + "repository": "https://github.com/sinclairzx81/sinclair-typebox" }, { - "lock": "package-lock.json", - "path": "node_modules/@walletconnect/universal-provider/node_modules/@walletconnect/utils", - "version": "2.23.7", - "license": "SEE LICENSE IN LICENSE.md", - "status": "review" + "ecosystem": "npm", + "name": "@solana-program/system", + "version": "0.10.0", + "license": "Apache-2.0", + "category": "approved", + "repository": "https://github.com/solana-program/system" }, { - "lock": "package-lock.json", - "path": "node_modules/@walletconnect/universal-provider/node_modules/abitype", - "version": "1.2.4", - "license": "MIT", - "status": "approved" + "ecosystem": "npm", + "name": "@solana-program/token", + "version": "0.9.0", + "license": "Apache-2.0", + "category": "approved", + "repository": "https://github.com/solana-program/token" }, { - "lock": "package-lock.json", - "path": "node_modules/@walletconnect/universal-provider/node_modules/ox", - "version": "0.9.3", + "ecosystem": "npm", + "name": "@solana/accounts", + "version": "5.5.1", "license": "MIT", - "status": "approved" + "category": "approved", + "repository": "https://github.com/anza-xyz/kit" }, { - "lock": "package-lock.json", - "path": "node_modules/@walletconnect/universal-provider/node_modules/ox/node_modules/@noble/curves", - "version": "1.9.1", + "ecosystem": "npm", + "name": "@solana/addresses", + "version": "5.5.1", "license": "MIT", - "status": "approved" + "category": "approved", + "repository": "https://github.com/anza-xyz/kit" }, { - "lock": "package-lock.json", - "path": "node_modules/@walletconnect/window-getters", - "version": "1.0.1", + "ecosystem": "npm", + "name": "@solana/assertions", + "version": "5.5.1", "license": "MIT", - "status": "approved" - }, - { - "lock": "package-lock.json", - "path": "node_modules/@walletconnect/window-getters/node_modules/tslib", - "version": "1.14.1", - "license": "0BSD", - "status": "approved" + "category": "approved", + "repository": "https://github.com/anza-xyz/kit" }, { - "lock": "package-lock.json", - "path": "node_modules/@walletconnect/window-metadata", - "version": "1.0.1", + "ecosystem": "npm", + "name": "@solana/buffer-layout", + "version": "4.0.1", "license": "MIT", - "status": "approved" + "category": "approved", + "repository": "https://github.com/solana-labs/buffer-layout" }, { - "lock": "package-lock.json", - "path": "node_modules/@walletconnect/window-metadata/node_modules/tslib", - "version": "1.14.1", - "license": "0BSD", - "status": "approved" + "ecosystem": "npm", + "name": "@solana/codecs", + "version": "5.5.1", + "license": "MIT", + "category": "approved", + "repository": "https://github.com/anza-xyz/kit" }, { - "lock": "package-lock.json", - "path": "node_modules/abitype", - "version": "1.0.6", + "ecosystem": "npm", + "name": "@solana/codecs-core", + "version": "2.3.0", "license": "MIT", - "status": "approved" + "category": "approved", + "repository": "https://github.com/anza-xyz/kit" }, { - "lock": "package-lock.json", - "path": "node_modules/accepts", - "version": "1.3.8", + "ecosystem": "npm", + "name": "@solana/codecs-core", + "version": "5.5.1", "license": "MIT", - "status": "approved" + "category": "approved", + "repository": "https://github.com/anza-xyz/kit" }, { - "lock": "package-lock.json", - "path": "node_modules/acorn", - "version": "8.18.0", + "ecosystem": "npm", + "name": "@solana/codecs-data-structures", + "version": "5.5.1", "license": "MIT", - "status": "approved" + "category": "approved", + "repository": "https://github.com/anza-xyz/kit" }, { - "lock": "package-lock.json", - "path": "node_modules/acorn-jsx", - "version": "5.3.2", + "ecosystem": "npm", + "name": "@solana/codecs-numbers", + "version": "2.3.0", "license": "MIT", - "status": "approved" + "category": "approved", + "repository": "https://github.com/anza-xyz/kit" }, { - "lock": "package-lock.json", - "path": "node_modules/agent-base", - "version": "6.0.2", + "ecosystem": "npm", + "name": "@solana/codecs-numbers", + "version": "5.5.1", "license": "MIT", - "status": "approved" + "category": "approved", + "repository": "https://github.com/anza-xyz/kit" }, { - "lock": "package-lock.json", - "path": "node_modules/agentkeepalive", - "version": "4.6.0", + "ecosystem": "npm", + "name": "@solana/codecs-strings", + "version": "5.5.1", "license": "MIT", - "status": "approved" + "category": "approved", + "repository": "https://github.com/anza-xyz/kit" }, { - "lock": "package-lock.json", - "path": "node_modules/ajv", - "version": "6.15.0", + "ecosystem": "npm", + "name": "@solana/errors", + "version": "2.3.0", "license": "MIT", - "status": "approved" + "category": "approved", + "repository": "https://github.com/anza-xyz/kit" }, { - "lock": "package-lock.json", - "path": "node_modules/ansi-escapes", - "version": "7.3.0", + "ecosystem": "npm", + "name": "@solana/errors", + "version": "5.5.1", "license": "MIT", - "status": "approved" + "category": "approved", + "repository": "https://github.com/anza-xyz/kit" }, { - "lock": "package-lock.json", - "path": "node_modules/ansi-regex", - "version": "5.0.1", + "ecosystem": "npm", + "name": "@solana/fast-stable-stringify", + "version": "5.5.1", "license": "MIT", - "status": "approved" + "category": "approved", + "repository": "https://github.com/anza-xyz/kit" }, { - "lock": "package-lock.json", - "path": "node_modules/ansi-styles", - "version": "4.3.0", + "ecosystem": "npm", + "name": "@solana/functional", + "version": "5.5.1", "license": "MIT", - "status": "approved" + "category": "approved", + "repository": "https://github.com/anza-xyz/kit" }, { - "lock": "package-lock.json", - "path": "node_modules/anymatch", - "version": "3.1.3", - "license": "ISC", - "status": "approved" + "ecosystem": "npm", + "name": "@solana/instruction-plans", + "version": "5.5.1", + "license": "MIT", + "category": "approved", + "repository": "https://github.com/anza-xyz/kit" }, { - "lock": "package-lock.json", - "path": "node_modules/anymatch/node_modules/picomatch", - "version": "2.3.2", + "ecosystem": "npm", + "name": "@solana/instructions", + "version": "5.5.1", "license": "MIT", - "status": "approved" + "category": "approved", + "repository": "https://github.com/anza-xyz/kit" }, { - "lock": "package-lock.json", - "path": "node_modules/argparse", - "version": "2.0.1", - "license": "Python-2.0", - "status": "review" + "ecosystem": "npm", + "name": "@solana/keys", + "version": "5.5.1", + "license": "MIT", + "category": "approved", + "repository": "https://github.com/anza-xyz/kit" }, { - "lock": "package-lock.json", - "path": "node_modules/aria-query", - "version": "5.3.0", - "license": "Apache-2.0", - "status": "approved" + "ecosystem": "npm", + "name": "@solana/kit", + "version": "5.5.1", + "license": "MIT", + "category": "approved", + "repository": "https://github.com/anza-xyz/kit" }, { - "lock": "package-lock.json", - "path": "node_modules/arr-union", - "version": "3.1.0", + "ecosystem": "npm", + "name": "@solana/nominal-types", + "version": "5.5.1", "license": "MIT", - "status": "approved" + "category": "approved", + "repository": "https://github.com/anza-xyz/kit" }, { - "lock": "package-lock.json", - "path": "node_modules/array-buffer-byte-length", - "version": "1.0.2", + "ecosystem": "npm", + "name": "@solana/offchain-messages", + "version": "5.5.1", "license": "MIT", - "status": "approved" + "category": "approved", + "repository": "https://github.com/anza-xyz/kit" }, { - "lock": "package-lock.json", - "path": "node_modules/array-flatten", - "version": "1.1.1", + "ecosystem": "npm", + "name": "@solana/options", + "version": "5.5.1", "license": "MIT", - "status": "approved" + "category": "approved", + "repository": "https://github.com/anza-xyz/kit" }, { - "lock": "package-lock.json", - "path": "node_modules/arraybuffer.prototype.slice", - "version": "1.0.4", + "ecosystem": "npm", + "name": "@solana/plugin-core", + "version": "5.5.1", "license": "MIT", - "status": "approved" + "category": "approved", + "repository": "https://github.com/anza-xyz/kit" }, { - "lock": "package-lock.json", - "path": "node_modules/asap", - "version": "2.0.6", + "ecosystem": "npm", + "name": "@solana/programs", + "version": "5.5.1", "license": "MIT", - "status": "approved" + "category": "approved", + "repository": "https://github.com/anza-xyz/kit" }, { - "lock": "package-lock.json", - "path": "node_modules/assertion-error", - "version": "2.0.1", + "ecosystem": "npm", + "name": "@solana/promises", + "version": "5.5.1", "license": "MIT", - "status": "approved" + "category": "approved", + "repository": "https://github.com/anza-xyz/kit" }, { - "lock": "package-lock.json", - "path": "node_modules/assign-symbols", - "version": "1.0.0", + "ecosystem": "npm", + "name": "@solana/rpc", + "version": "5.5.1", "license": "MIT", - "status": "approved" + "category": "approved", + "repository": "https://github.com/anza-xyz/kit" }, { - "lock": "package-lock.json", - "path": "node_modules/async", - "version": "3.2.6", + "ecosystem": "npm", + "name": "@solana/rpc-api", + "version": "5.5.1", "license": "MIT", - "status": "approved" + "category": "approved", + "repository": "https://github.com/anza-xyz/kit" }, { - "lock": "package-lock.json", - "path": "node_modules/async-function", - "version": "1.0.0", + "ecosystem": "npm", + "name": "@solana/rpc-parsed-types", + "version": "5.5.1", "license": "MIT", - "status": "approved" + "category": "approved", + "repository": "https://github.com/anza-xyz/kit" }, { - "lock": "package-lock.json", - "path": "node_modules/asynckit", - "version": "0.4.0", + "ecosystem": "npm", + "name": "@solana/rpc-spec", + "version": "5.5.1", "license": "MIT", - "status": "approved" + "category": "approved", + "repository": "https://github.com/anza-xyz/kit" }, { - "lock": "package-lock.json", - "path": "node_modules/at-least-node", - "version": "1.0.0", - "license": "ISC", - "status": "approved" + "ecosystem": "npm", + "name": "@solana/rpc-spec-types", + "version": "5.5.1", + "license": "MIT", + "category": "approved", + "repository": "https://github.com/anza-xyz/kit" }, { - "lock": "package-lock.json", - "path": "node_modules/atomic-sleep", - "version": "1.0.0", + "ecosystem": "npm", + "name": "@solana/rpc-subscriptions", + "version": "5.5.1", "license": "MIT", - "status": "approved" + "category": "approved", + "repository": "https://github.com/anza-xyz/kit" }, { - "lock": "package-lock.json", - "path": "node_modules/available-typed-arrays", - "version": "1.0.7", + "ecosystem": "npm", + "name": "@solana/rpc-subscriptions-api", + "version": "5.5.1", "license": "MIT", - "status": "approved" + "category": "approved", + "repository": "https://github.com/anza-xyz/kit" }, { - "lock": "package-lock.json", - "path": "node_modules/axios", - "version": "1.16.1", + "ecosystem": "npm", + "name": "@solana/rpc-subscriptions-channel-websocket", + "version": "5.5.1", "license": "MIT", - "status": "approved" + "category": "approved", + "repository": "https://github.com/anza-xyz/kit" }, { - "lock": "package-lock.json", - "path": "node_modules/axios-retry", - "version": "4.5.0", - "license": "Apache-2.0", - "status": "approved" + "ecosystem": "npm", + "name": "@solana/rpc-subscriptions-spec", + "version": "5.5.1", + "license": "MIT", + "category": "approved", + "repository": "https://github.com/anza-xyz/kit" }, { - "lock": "package-lock.json", - "path": "node_modules/axios-retry/node_modules/is-retry-allowed", - "version": "2.2.0", + "ecosystem": "npm", + "name": "@solana/rpc-transformers", + "version": "5.5.1", "license": "MIT", - "status": "approved" + "category": "approved", + "repository": "https://github.com/anza-xyz/kit" }, { - "lock": "package-lock.json", - "path": "node_modules/babel-plugin-polyfill-corejs2", - "version": "0.4.17", + "ecosystem": "npm", + "name": "@solana/rpc-transport-http", + "version": "5.5.1", "license": "MIT", - "status": "approved" + "category": "approved", + "repository": "https://github.com/anza-xyz/kit" }, { - "lock": "package-lock.json", - "path": "node_modules/babel-plugin-polyfill-corejs2/node_modules/semver", - "version": "6.3.1", - "license": "ISC", - "status": "approved" + "ecosystem": "npm", + "name": "@solana/rpc-types", + "version": "5.5.1", + "license": "MIT", + "category": "approved", + "repository": "https://github.com/anza-xyz/kit" }, { - "lock": "package-lock.json", - "path": "node_modules/babel-plugin-polyfill-corejs3", - "version": "0.14.2", + "ecosystem": "npm", + "name": "@solana/signers", + "version": "5.5.1", "license": "MIT", - "status": "approved" + "category": "approved", + "repository": "https://github.com/anza-xyz/kit" }, { - "lock": "package-lock.json", - "path": "node_modules/babel-plugin-polyfill-regenerator", - "version": "0.6.8", + "ecosystem": "npm", + "name": "@solana/subscribable", + "version": "5.5.1", "license": "MIT", - "status": "approved" + "category": "approved", + "repository": "https://github.com/anza-xyz/kit" }, { - "lock": "package-lock.json", - "path": "node_modules/balanced-match", - "version": "1.0.2", + "ecosystem": "npm", + "name": "@solana/sysvars", + "version": "5.5.1", "license": "MIT", - "status": "approved" + "category": "approved", + "repository": "https://github.com/anza-xyz/kit" }, { - "lock": "package-lock.json", - "path": "node_modules/base-x", - "version": "5.0.1", + "ecosystem": "npm", + "name": "@solana/transaction-confirmation", + "version": "5.5.1", "license": "MIT", - "status": "approved" + "category": "approved", + "repository": "https://github.com/anza-xyz/kit" }, { - "lock": "package-lock.json", - "path": "node_modules/base32.js", - "version": "0.1.0", + "ecosystem": "npm", + "name": "@solana/transaction-messages", + "version": "5.5.1", "license": "MIT", - "status": "approved" + "category": "approved", + "repository": "https://github.com/anza-xyz/kit" }, { - "lock": "package-lock.json", - "path": "node_modules/base64-js", - "version": "1.5.1", + "ecosystem": "npm", + "name": "@solana/transactions", + "version": "5.5.1", "license": "MIT", - "status": "approved" + "category": "approved", + "repository": "https://github.com/anza-xyz/kit" }, { - "lock": "package-lock.json", - "path": "node_modules/baseline-browser-mapping", - "version": "2.11.26", + "ecosystem": "npm", + "name": "@solana/wallet-adapter-base", + "version": "0.9.27", "license": "Apache-2.0", - "status": "approved" + "category": "approved", + "repository": "https://github.com/anza-xyz/wallet-adapter" }, { - "lock": "package-lock.json", - "path": "node_modules/bidi-js", - "version": "1.0.3", - "license": "MIT", - "status": "approved" + "ecosystem": "npm", + "name": "@solana/wallet-standard-features", + "version": "1.4.0", + "license": "Apache-2.0", + "category": "approved", + "repository": "https://github.com/anza-xyz/wallet-standard" }, { - "lock": "package-lock.json", - "path": "node_modules/big.js", - "version": "6.2.2", + "ecosystem": "npm", + "name": "@solana/web3.js", + "version": "1.98.4", "license": "MIT", - "status": "approved" + "category": "approved", + "repository": "https://github.com/solana-foundation/solana-web3.js" }, { - "lock": "package-lock.json", - "path": "node_modules/bignumber.js", - "version": "11.1.3", - "license": "MIT", - "status": "approved" + "ecosystem": "npm", + "name": "@sqlite.org/sqlite-wasm", + "version": "3.53.4-build1", + "license": "Apache-2.0", + "category": "approved", + "dev": true, + "repository": "https://github.com/sqlite/sqlite-wasm" }, { - "lock": "package-lock.json", - "path": "node_modules/bip32-path", - "version": "0.4.2", + "ecosystem": "npm", + "name": "@standard-schema/spec", + "version": "1.1.0", "license": "MIT", - "status": "approved" + "category": "approved", + "dev": true, + "repository": "https://github.com/standard-schema/standard-schema" }, { - "lock": "package-lock.json", - "path": "node_modules/blakejs", - "version": "1.2.1", - "license": "MIT", - "status": "approved" + "ecosystem": "npm", + "name": "@stellar/freighter-api", + "version": "6.0.0", + "license": "Apache-2.0", + "category": "approved", + "repository": "git@github.com:stellar/freighter" }, { - "lock": "package-lock.json", - "path": "node_modules/bn.js", - "version": "5.2.4", - "license": "MIT", - "status": "approved" + "ecosystem": "npm", + "name": "@stellar/js-xdr", + "version": "4.0.0", + "license": "Apache-2.0", + "category": "approved", + "repository": "https://github.com/stellar/js-xdr" }, { - "lock": "package-lock.json", - "path": "node_modules/body-parser", - "version": "1.20.5", - "license": "MIT", - "status": "approved" + "ecosystem": "npm", + "name": "@stellar/stellar-sdk", + "version": "16.0.0", + "license": "Apache-2.0", + "category": "approved", + "repository": "https://github.com/stellar/js-stellar-sdk" }, { - "lock": "package-lock.json", - "path": "node_modules/body-parser/node_modules/debug", - "version": "2.6.9", + "ecosystem": "npm", + "name": "@supabase/auth-js", + "version": "2.108.2", "license": "MIT", - "status": "approved" + "category": "approved", + "repository": "https://github.com/supabase/supabase-js" }, { - "lock": "package-lock.json", - "path": "node_modules/body-parser/node_modules/http-errors", - "version": "2.0.1", + "ecosystem": "npm", + "name": "@supabase/functions-js", + "version": "2.108.2", "license": "MIT", - "status": "approved" + "category": "approved", + "repository": "https://github.com/supabase/supabase-js" }, { - "lock": "package-lock.json", - "path": "node_modules/body-parser/node_modules/ms", - "version": "2.0.0", + "ecosystem": "npm", + "name": "@supabase/phoenix", + "version": "0.4.4", "license": "MIT", - "status": "approved" + "category": "approved", + "repository": "git://github.com/supabase/phoenix" }, { - "lock": "package-lock.json", - "path": "node_modules/body-parser/node_modules/setprototypeof", - "version": "1.2.0", - "license": "ISC", - "status": "approved" - }, - { - "lock": "package-lock.json", - "path": "node_modules/body-parser/node_modules/toidentifier", - "version": "1.0.1", + "ecosystem": "npm", + "name": "@supabase/postgrest-js", + "version": "2.108.2", "license": "MIT", - "status": "approved" + "category": "approved", + "repository": "https://github.com/supabase/supabase-js" }, { - "lock": "package-lock.json", - "path": "node_modules/borsh", - "version": "2.0.0", - "license": "Apache-2.0", - "status": "approved" + "ecosystem": "npm", + "name": "@supabase/realtime-js", + "version": "2.108.2", + "license": "MIT", + "category": "approved", + "repository": "https://github.com/supabase/supabase-js" }, { - "lock": "package-lock.json", - "path": "node_modules/brace-expansion", - "version": "1.1.21", + "ecosystem": "npm", + "name": "@supabase/storage-js", + "version": "2.108.2", "license": "MIT", - "status": "approved" + "category": "approved", + "repository": "https://github.com/supabase/supabase-js" }, { - "lock": "package-lock.json", - "path": "node_modules/braces", - "version": "3.0.3", + "ecosystem": "npm", + "name": "@supabase/supabase-js", + "version": "2.108.2", "license": "MIT", - "status": "approved" + "category": "approved", + "repository": "https://github.com/supabase/supabase-js" }, { - "lock": "package-lock.json", - "path": "node_modules/brorand", - "version": "1.1.0", - "license": "MIT", - "status": "approved" + "ecosystem": "npm", + "name": "@swc/helpers", + "version": "0.5.23", + "license": "Apache-2.0", + "category": "approved", + "repository": "https://github.com/swc-project/swc" }, { - "lock": "package-lock.json", - "path": "node_modules/browserslist", - "version": "4.29.1", + "ecosystem": "npm", + "name": "@testing-library/dom", + "version": "10.4.1", "license": "MIT", - "status": "approved" + "category": "approved", + "dev": true, + "repository": "https://github.com/testing-library/dom-testing-library" }, { - "lock": "package-lock.json", - "path": "node_modules/bs58", - "version": "6.0.0", + "ecosystem": "npm", + "name": "@testing-library/jest-dom", + "version": "7.0.0", "license": "MIT", - "status": "approved" + "category": "approved", + "dev": true, + "repository": "https://github.com/testing-library/jest-dom" }, { - "lock": "package-lock.json", - "path": "node_modules/buffer", - "version": "6.0.3", + "ecosystem": "npm", + "name": "@testing-library/react", + "version": "16.3.2", "license": "MIT", - "status": "approved" + "category": "approved", + "dev": true, + "repository": "https://github.com/testing-library/react-testing-library" }, { - "lock": "package-lock.json", - "path": "node_modules/buffer-from", - "version": "1.1.2", + "ecosystem": "npm", + "name": "@trezor/connect-common", + "version": "10.0.0-alpha.1", "license": "MIT", - "status": "approved" + "category": "approved", + "repository": "git://github.com/trezor/trezor-suite" }, { - "lock": "package-lock.json", - "path": "node_modules/bufferutil", - "version": "4.1.0", - "license": "MIT", - "status": "approved" + "ecosystem": "npm", + "name": "@trezor/connect-plugin-stellar", + "version": "10.0.0-alpha.1", + "license": "SEE LICENSE IN LICENSE.md", + "category": "review", + "repository": "git://github.com/trezor/trezor-suite" }, { - "lock": "package-lock.json", - "path": "node_modules/bundle-name", - "version": "4.1.0", + "ecosystem": "npm", + "name": "@trezor/connect-web", + "version": "10.0.0-alpha.1", "license": "MIT", - "status": "approved" + "category": "approved", + "repository": "git://github.com/trezor/trezor-suite" }, { - "lock": "package-lock.json", - "path": "node_modules/bytes", - "version": "3.1.2", + "ecosystem": "npm", + "name": "@trezor/device-utils", + "version": "10.0.0-alpha.1", "license": "MIT", - "status": "approved" + "category": "approved" }, { - "lock": "package-lock.json", - "path": "node_modules/bytewise", - "version": "1.1.0", + "ecosystem": "npm", + "name": "@trezor/protobuf", + "version": "10.0.0-alpha.1", "license": "MIT", - "status": "approved" + "category": "approved", + "repository": "git://github.com/trezor/trezor-suite" }, { - "lock": "package-lock.json", - "path": "node_modules/bytewise-core", - "version": "1.2.3", + "ecosystem": "npm", + "name": "@trezor/protocol", + "version": "10.0.0-alpha.1", "license": "MIT", - "status": "approved" + "category": "approved", + "repository": "git://github.com/trezor/trezor-suite" }, { - "lock": "package-lock.json", - "path": "node_modules/call-bind", - "version": "1.0.9", + "ecosystem": "npm", + "name": "@trezor/schema-utils", + "version": "10.0.0-alpha.1", "license": "MIT", - "status": "approved" + "category": "approved" }, { - "lock": "package-lock.json", - "path": "node_modules/call-bind-apply-helpers", - "version": "1.0.2", + "ecosystem": "npm", + "name": "@trezor/type-utils", + "version": "10.0.0-alpha.1", "license": "MIT", - "status": "approved" + "category": "approved", + "repository": "git://github.com/trezor/trezor-suite" }, { - "lock": "package-lock.json", - "path": "node_modules/call-bound", - "version": "1.0.4", + "ecosystem": "npm", + "name": "@trezor/utils", + "version": "10.0.0-alpha.1", "license": "MIT", - "status": "approved" + "category": "approved", + "repository": "git://github.com/trezor/trezor-suite" }, { - "lock": "package-lock.json", - "path": "node_modules/callsites", - "version": "3.1.0", + "ecosystem": "npm", + "name": "@trezor/websocket-client", + "version": "10.0.0-alpha.1", "license": "MIT", - "status": "approved" + "category": "approved", + "repository": "git://github.com/trezor/trezor-suite" }, { - "lock": "package-lock.json", - "path": "node_modules/camelcase", - "version": "5.3.1", - "license": "MIT", - "status": "approved" + "ecosystem": "npm", + "name": "@trickfilm400/rollup-plugin-off-main-thread", + "version": "3.0.0-pre1", + "license": "Apache-2.0", + "category": "approved", + "dev": true, + "repository": "https://github.com/Trickfilm400/rollup-plugin-off-main-thread" }, { - "lock": "package-lock.json", - "path": "node_modules/caniuse-lite", - "version": "1.0.30001812", - "license": "CC-BY-4.0", - "status": "review" + "ecosystem": "npm", + "name": "@twind/core", + "version": "1.1.3", + "license": "MIT", + "category": "approved", + "repository": "https://github.com/tw-in-js/twind" }, { - "lock": "package-lock.json", - "path": "node_modules/chai", - "version": "6.2.2", + "ecosystem": "npm", + "name": "@twind/preset-autoprefix", + "version": "1.0.7", "license": "MIT", - "status": "approved" + "category": "approved", + "repository": "https://github.com/tw-in-js/twind" }, { - "lock": "package-lock.json", - "path": "node_modules/chalk", - "version": "5.6.2", + "ecosystem": "npm", + "name": "@twind/preset-tailwind", + "version": "1.1.4", "license": "MIT", - "status": "approved" + "category": "approved", + "repository": "https://github.com/tw-in-js/twind" }, { - "lock": "package-lock.json", - "path": "node_modules/charenc", - "version": "0.0.2", - "license": "BSD-3-Clause", - "status": "approved" + "ecosystem": "npm", + "name": "@tybys/wasm-util", + "version": "0.10.2", + "license": "MIT", + "category": "approved", + "dev": true }, { - "lock": "package-lock.json", - "path": "node_modules/chokidar", - "version": "5.0.0", + "ecosystem": "npm", + "name": "@types/aria-query", + "version": "5.0.4", "license": "MIT", - "status": "approved" + "category": "approved", + "dev": true, + "repository": "https://github.com/DefinitelyTyped/DefinitelyTyped" }, { - "lock": "package-lock.json", - "path": "node_modules/cli-cursor", - "version": "5.0.0", + "ecosystem": "npm", + "name": "@types/body-parser", + "version": "1.19.6", "license": "MIT", - "status": "approved" + "category": "approved", + "dev": true, + "repository": "https://github.com/DefinitelyTyped/DefinitelyTyped" }, { - "lock": "package-lock.json", - "path": "node_modules/cli-truncate", - "version": "4.0.0", + "ecosystem": "npm", + "name": "@types/chai", + "version": "5.2.3", "license": "MIT", - "status": "approved" + "category": "approved", + "dev": true, + "repository": "https://github.com/DefinitelyTyped/DefinitelyTyped" }, { - "lock": "package-lock.json", - "path": "node_modules/cli-truncate/node_modules/ansi-regex", - "version": "6.3.0", + "ecosystem": "npm", + "name": "@types/connect", + "version": "3.4.38", "license": "MIT", - "status": "approved" + "category": "approved", + "repository": "https://github.com/DefinitelyTyped/DefinitelyTyped" }, { - "lock": "package-lock.json", - "path": "node_modules/cli-truncate/node_modules/emoji-regex", - "version": "10.6.0", + "ecosystem": "npm", + "name": "@types/cors", + "version": "2.8.19", "license": "MIT", - "status": "approved" + "category": "approved", + "dev": true, + "repository": "https://github.com/DefinitelyTyped/DefinitelyTyped" }, { - "lock": "package-lock.json", - "path": "node_modules/cli-truncate/node_modules/string-width", - "version": "7.2.0", + "ecosystem": "npm", + "name": "@types/deep-eql", + "version": "4.0.2", "license": "MIT", - "status": "approved" + "category": "approved", + "dev": true, + "repository": "https://github.com/DefinitelyTyped/DefinitelyTyped" }, { - "lock": "package-lock.json", - "path": "node_modules/cli-truncate/node_modules/strip-ansi", - "version": "7.2.0", + "ecosystem": "npm", + "name": "@types/estree", + "version": "1.0.9", "license": "MIT", - "status": "approved" + "category": "approved", + "dev": true, + "repository": "https://github.com/DefinitelyTyped/DefinitelyTyped" }, { - "lock": "package-lock.json", - "path": "node_modules/cli-width", - "version": "4.1.0", - "license": "ISC", - "status": "approved" + "ecosystem": "npm", + "name": "@types/express", + "version": "5.0.6", + "license": "MIT", + "category": "approved", + "dev": true, + "repository": "https://github.com/DefinitelyTyped/DefinitelyTyped" }, { - "lock": "package-lock.json", - "path": "node_modules/cliui", - "version": "6.0.0", - "license": "ISC", - "status": "approved" + "ecosystem": "npm", + "name": "@types/express-serve-static-core", + "version": "5.1.3", + "license": "MIT", + "category": "approved", + "dev": true, + "repository": "https://github.com/DefinitelyTyped/DefinitelyTyped" }, { - "lock": "package-lock.json", - "path": "node_modules/clsx", - "version": "1.2.1", + "ecosystem": "npm", + "name": "@types/geojson", + "version": "7946.0.16", "license": "MIT", - "status": "approved" + "category": "approved", + "repository": "https://github.com/DefinitelyTyped/DefinitelyTyped" }, { - "lock": "package-lock.json", - "path": "node_modules/color-convert", - "version": "2.0.1", + "ecosystem": "npm", + "name": "@types/http-errors", + "version": "2.0.5", "license": "MIT", - "status": "approved" + "category": "approved", + "dev": true, + "repository": "https://github.com/DefinitelyTyped/DefinitelyTyped" }, { - "lock": "package-lock.json", - "path": "node_modules/color-name", - "version": "1.1.4", + "ecosystem": "npm", + "name": "@types/json-schema", + "version": "7.0.15", "license": "MIT", - "status": "approved" + "category": "approved", + "dev": true, + "repository": "https://github.com/DefinitelyTyped/DefinitelyTyped" }, { - "lock": "package-lock.json", - "path": "node_modules/colorette", - "version": "2.0.20", + "ecosystem": "npm", + "name": "@types/morgan", + "version": "1.9.10", "license": "MIT", - "status": "approved" + "category": "approved", + "dev": true, + "repository": "https://github.com/DefinitelyTyped/DefinitelyTyped" }, { - "lock": "package-lock.json", - "path": "node_modules/combined-stream", - "version": "1.0.8", + "ecosystem": "npm", + "name": "@types/node", + "version": "12.20.55", "license": "MIT", - "status": "approved" + "category": "approved", + "repository": "https://github.com/DefinitelyTyped/DefinitelyTyped" }, { - "lock": "package-lock.json", - "path": "node_modules/comlink", - "version": "4.4.2", - "license": "Apache-2.0", - "status": "approved" + "ecosystem": "npm", + "name": "@types/node", + "version": "22.20.1", + "license": "MIT", + "category": "approved", + "repository": "https://github.com/DefinitelyTyped/DefinitelyTyped" }, { - "lock": "package-lock.json", - "path": "node_modules/commander", - "version": "14.0.3", + "ecosystem": "npm", + "name": "@types/qs", + "version": "6.15.1", "license": "MIT", - "status": "approved" + "category": "approved", + "dev": true, + "repository": "https://github.com/DefinitelyTyped/DefinitelyTyped" }, { - "lock": "package-lock.json", - "path": "node_modules/common-tags", - "version": "1.8.2", + "ecosystem": "npm", + "name": "@types/range-parser", + "version": "1.2.7", "license": "MIT", - "status": "approved" + "category": "approved", + "dev": true, + "repository": "https://github.com/DefinitelyTyped/DefinitelyTyped" }, { - "lock": "package-lock.json", - "path": "node_modules/component-emitter", - "version": "1.3.1", + "ecosystem": "npm", + "name": "@types/react", + "version": "19.2.18", "license": "MIT", - "status": "approved" + "category": "approved", + "dev": true, + "repository": "https://github.com/DefinitelyTyped/DefinitelyTyped" }, { - "lock": "package-lock.json", - "path": "node_modules/concat-map", - "version": "0.0.1", + "ecosystem": "npm", + "name": "@types/react-dom", + "version": "19.2.5", "license": "MIT", - "status": "approved" + "category": "approved", + "dev": true, + "repository": "https://github.com/DefinitelyTyped/DefinitelyTyped" }, { - "lock": "package-lock.json", - "path": "node_modules/content-disposition", - "version": "0.5.4", + "ecosystem": "npm", + "name": "@types/resolve", + "version": "1.20.2", "license": "MIT", - "status": "approved" + "category": "approved", + "dev": true, + "repository": "https://github.com/DefinitelyTyped/DefinitelyTyped" }, { - "lock": "package-lock.json", - "path": "node_modules/content-type", - "version": "1.0.5", + "ecosystem": "npm", + "name": "@types/send", + "version": "1.2.1", "license": "MIT", - "status": "approved" + "category": "approved", + "dev": true, + "repository": "https://github.com/DefinitelyTyped/DefinitelyTyped" }, { - "lock": "package-lock.json", - "path": "node_modules/convert-source-map", - "version": "2.0.0", + "ecosystem": "npm", + "name": "@types/serve-static", + "version": "2.2.0", "license": "MIT", - "status": "approved" + "category": "approved", + "dev": true, + "repository": "https://github.com/DefinitelyTyped/DefinitelyTyped" }, { - "lock": "package-lock.json", - "path": "node_modules/cookie", - "version": "1.1.1", + "ecosystem": "npm", + "name": "@types/set-cookie-parser", + "version": "2.4.10", "license": "MIT", - "status": "approved" + "category": "approved", + "dev": true, + "repository": "https://github.com/DefinitelyTyped/DefinitelyTyped" }, { - "lock": "package-lock.json", - "path": "node_modules/cookie-es", - "version": "1.2.3", + "ecosystem": "npm", + "name": "@types/statuses", + "version": "2.0.6", "license": "MIT", - "status": "approved" + "category": "approved", + "dev": true, + "repository": "https://github.com/DefinitelyTyped/DefinitelyTyped" }, { - "lock": "package-lock.json", - "path": "node_modules/cookie-signature", - "version": "1.0.7", + "ecosystem": "npm", + "name": "@types/supercluster", + "version": "7.1.3", "license": "MIT", - "status": "approved" + "category": "approved", + "repository": "https://github.com/DefinitelyTyped/DefinitelyTyped" }, { - "lock": "package-lock.json", - "path": "node_modules/cookiejar", - "version": "2.1.4", + "ecosystem": "npm", + "name": "@types/trusted-types", + "version": "2.0.7", "license": "MIT", - "status": "approved" + "category": "approved", + "repository": "https://github.com/DefinitelyTyped/DefinitelyTyped" }, { - "lock": "package-lock.json", - "path": "node_modules/core-js-compat", - "version": "3.50.0", + "ecosystem": "npm", + "name": "@types/uuid", + "version": "10.0.0", "license": "MIT", - "status": "approved" + "category": "approved", + "repository": "https://github.com/DefinitelyTyped/DefinitelyTyped" }, { - "lock": "package-lock.json", - "path": "node_modules/cors", - "version": "2.8.6", + "ecosystem": "npm", + "name": "@types/ws", + "version": "7.4.7", "license": "MIT", - "status": "approved" + "category": "approved", + "repository": "https://github.com/DefinitelyTyped/DefinitelyTyped" }, { - "lock": "package-lock.json", - "path": "node_modules/cross-fetch", - "version": "3.2.0", + "ecosystem": "npm", + "name": "@types/ws", + "version": "8.18.1", "license": "MIT", - "status": "approved" + "category": "approved", + "repository": "https://github.com/DefinitelyTyped/DefinitelyTyped" }, { - "lock": "package-lock.json", - "path": "node_modules/cross-spawn", - "version": "7.0.6", - "license": "MIT", - "status": "approved" + "ecosystem": "npm", + "name": "@typescript/typescript-aix-ppc64", + "version": "7.0.2", + "license": "Apache-2.0", + "category": "approved", + "dev": true }, { - "lock": "package-lock.json", - "path": "node_modules/crossws", - "version": "0.3.5", - "license": "MIT", - "status": "approved" + "ecosystem": "npm", + "name": "@typescript/typescript-darwin-arm64", + "version": "7.0.2", + "license": "Apache-2.0", + "category": "approved", + "dev": true }, { - "lock": "package-lock.json", - "path": "node_modules/crypt", - "version": "0.0.2", - "license": "BSD-3-Clause", - "status": "approved" + "ecosystem": "npm", + "name": "@typescript/typescript-darwin-x64", + "version": "7.0.2", + "license": "Apache-2.0", + "category": "approved", + "dev": true }, { - "lock": "package-lock.json", - "path": "node_modules/crypto-random-string", - "version": "2.0.0", - "license": "MIT", - "status": "approved" + "ecosystem": "npm", + "name": "@typescript/typescript-freebsd-arm64", + "version": "7.0.2", + "license": "Apache-2.0", + "category": "approved", + "dev": true }, { - "lock": "package-lock.json", - "path": "node_modules/css-tree", - "version": "3.2.1", - "license": "MIT", - "status": "approved" + "ecosystem": "npm", + "name": "@typescript/typescript-freebsd-x64", + "version": "7.0.2", + "license": "Apache-2.0", + "category": "approved", + "dev": true }, { - "lock": "package-lock.json", - "path": "node_modules/css.escape", - "version": "1.5.1", - "license": "MIT", - "status": "approved" + "ecosystem": "npm", + "name": "@typescript/typescript-linux-arm", + "version": "7.0.2", + "license": "Apache-2.0", + "category": "approved", + "dev": true }, { - "lock": "package-lock.json", - "path": "node_modules/csstype", - "version": "3.2.3", - "license": "MIT", - "status": "approved" + "ecosystem": "npm", + "name": "@typescript/typescript-linux-arm64", + "version": "7.0.2", + "license": "Apache-2.0", + "category": "approved", + "dev": true }, { - "lock": "package-lock.json", - "path": "node_modules/data-urls", - "version": "7.0.0", - "license": "MIT", - "status": "approved" + "ecosystem": "npm", + "name": "@typescript/typescript-linux-loong64", + "version": "7.0.2", + "license": "Apache-2.0", + "category": "approved", + "dev": true }, { - "lock": "package-lock.json", - "path": "node_modules/data-urls/node_modules/tr46", - "version": "6.0.0", - "license": "MIT", - "status": "approved" + "ecosystem": "npm", + "name": "@typescript/typescript-linux-mips64el", + "version": "7.0.2", + "license": "Apache-2.0", + "category": "approved", + "dev": true }, { - "lock": "package-lock.json", - "path": "node_modules/data-urls/node_modules/webidl-conversions", - "version": "8.0.1", - "license": "BSD-2-Clause", - "status": "approved" + "ecosystem": "npm", + "name": "@typescript/typescript-linux-ppc64", + "version": "7.0.2", + "license": "Apache-2.0", + "category": "approved", + "dev": true }, { - "lock": "package-lock.json", - "path": "node_modules/data-urls/node_modules/whatwg-url", - "version": "16.0.1", - "license": "MIT", - "status": "approved" + "ecosystem": "npm", + "name": "@typescript/typescript-linux-riscv64", + "version": "7.0.2", + "license": "Apache-2.0", + "category": "approved", + "dev": true }, { - "lock": "package-lock.json", - "path": "node_modules/data-view-buffer", - "version": "1.0.2", - "license": "MIT", - "status": "approved" + "ecosystem": "npm", + "name": "@typescript/typescript-linux-s390x", + "version": "7.0.2", + "license": "Apache-2.0", + "category": "approved", + "dev": true }, { - "lock": "package-lock.json", - "path": "node_modules/data-view-byte-length", - "version": "1.0.2", - "license": "MIT", - "status": "approved" + "ecosystem": "npm", + "name": "@typescript/typescript-linux-x64", + "version": "7.0.2", + "license": "Apache-2.0", + "category": "approved", + "dev": true, + "repository": "https://github.com/microsoft/TypeScript" }, { - "lock": "package-lock.json", - "path": "node_modules/data-view-byte-offset", - "version": "1.0.1", - "license": "MIT", - "status": "approved" + "ecosystem": "npm", + "name": "@typescript/typescript-netbsd-arm64", + "version": "7.0.2", + "license": "Apache-2.0", + "category": "approved", + "dev": true }, { - "lock": "package-lock.json", - "path": "node_modules/dayjs", - "version": "1.11.13", - "license": "MIT", - "status": "approved" + "ecosystem": "npm", + "name": "@typescript/typescript-netbsd-x64", + "version": "7.0.2", + "license": "Apache-2.0", + "category": "approved", + "dev": true }, { - "lock": "package-lock.json", - "path": "node_modules/debug", - "version": "4.4.3", - "license": "MIT", - "status": "approved" + "ecosystem": "npm", + "name": "@typescript/typescript-openbsd-arm64", + "version": "7.0.2", + "license": "Apache-2.0", + "category": "approved", + "dev": true }, { - "lock": "package-lock.json", - "path": "node_modules/decamelize", - "version": "1.2.0", - "license": "MIT", - "status": "approved" + "ecosystem": "npm", + "name": "@typescript/typescript-openbsd-x64", + "version": "7.0.2", + "license": "Apache-2.0", + "category": "approved", + "dev": true }, { - "lock": "package-lock.json", - "path": "node_modules/decimal.js", - "version": "10.6.0", - "license": "MIT", - "status": "approved" + "ecosystem": "npm", + "name": "@typescript/typescript-sunos-x64", + "version": "7.0.2", + "license": "Apache-2.0", + "category": "approved", + "dev": true }, { - "lock": "package-lock.json", - "path": "node_modules/deep-is", - "version": "0.1.4", - "license": "MIT", - "status": "approved" + "ecosystem": "npm", + "name": "@typescript/typescript-win32-arm64", + "version": "7.0.2", + "license": "Apache-2.0", + "category": "approved", + "dev": true }, { - "lock": "package-lock.json", - "path": "node_modules/deepmerge", - "version": "4.3.1", - "license": "MIT", - "status": "approved" + "ecosystem": "npm", + "name": "@typescript/typescript-win32-x64", + "version": "7.0.2", + "license": "Apache-2.0", + "category": "approved", + "dev": true }, { - "lock": "package-lock.json", - "path": "node_modules/default-browser", - "version": "5.5.1", + "ecosystem": "npm", + "name": "@vis.gl/react-mapbox", + "version": "8.1.1", "license": "MIT", - "status": "approved" + "category": "approved", + "repository": "https://github.com/visgl/react-map-gl" }, { - "lock": "package-lock.json", - "path": "node_modules/default-browser-id", - "version": "5.0.1", + "ecosystem": "npm", + "name": "@vis.gl/react-maplibre", + "version": "8.1.1", "license": "MIT", - "status": "approved" + "category": "approved", + "repository": "https://github.com/visgl/react-map-gl" }, { - "lock": "package-lock.json", - "path": "node_modules/define-data-property", - "version": "1.1.4", + "ecosystem": "npm", + "name": "@vitejs/plugin-react", + "version": "6.0.2", "license": "MIT", - "status": "approved" + "category": "approved", + "dev": true, + "repository": "https://github.com/vitejs/vite-plugin-react" }, { - "lock": "package-lock.json", - "path": "node_modules/define-lazy-prop", - "version": "3.0.0", + "ecosystem": "npm", + "name": "@vitest/coverage-v8", + "version": "4.1.11", "license": "MIT", - "status": "approved" + "category": "approved", + "dev": true, + "repository": "https://github.com/vitest-dev/vitest" }, { - "lock": "package-lock.json", - "path": "node_modules/define-properties", - "version": "1.2.1", + "ecosystem": "npm", + "name": "@vitest/expect", + "version": "4.1.11", "license": "MIT", - "status": "approved" + "category": "approved", + "dev": true, + "repository": "https://github.com/vitest-dev/vitest" }, { - "lock": "package-lock.json", - "path": "node_modules/defu", - "version": "6.1.7", + "ecosystem": "npm", + "name": "@vitest/mocker", + "version": "4.1.11", "license": "MIT", - "status": "approved" + "category": "approved", + "dev": true, + "repository": "https://github.com/vitest-dev/vitest" }, { - "lock": "package-lock.json", - "path": "node_modules/delay", - "version": "5.0.0", + "ecosystem": "npm", + "name": "@vitest/pretty-format", + "version": "4.1.11", "license": "MIT", - "status": "approved" + "category": "approved", + "dev": true, + "repository": "https://github.com/vitest-dev/vitest" }, { - "lock": "package-lock.json", - "path": "node_modules/delayed-stream", - "version": "1.0.0", + "ecosystem": "npm", + "name": "@vitest/runner", + "version": "4.1.11", "license": "MIT", - "status": "approved" + "category": "approved", + "dev": true, + "repository": "https://github.com/vitest-dev/vitest" }, { - "lock": "package-lock.json", - "path": "node_modules/depd", - "version": "2.0.0", + "ecosystem": "npm", + "name": "@vitest/snapshot", + "version": "4.1.11", "license": "MIT", - "status": "approved" + "category": "approved", + "dev": true, + "repository": "https://github.com/vitest-dev/vitest" }, { - "lock": "package-lock.json", - "path": "node_modules/dequal", - "version": "2.0.3", + "ecosystem": "npm", + "name": "@vitest/spy", + "version": "4.1.11", "license": "MIT", - "status": "approved" + "category": "approved", + "dev": true, + "repository": "https://github.com/vitest-dev/vitest" }, { - "lock": "package-lock.json", - "path": "node_modules/destr", - "version": "2.0.5", + "ecosystem": "npm", + "name": "@vitest/utils", + "version": "4.1.11", "license": "MIT", - "status": "approved" + "category": "approved", + "dev": true, + "repository": "https://github.com/vitest-dev/vitest" }, { - "lock": "package-lock.json", - "path": "node_modules/destroy", - "version": "1.2.0", - "license": "MIT", - "status": "approved" + "ecosystem": "npm", + "name": "@wallet-standard/base", + "version": "1.1.1", + "license": "Apache-2.0", + "category": "approved", + "repository": "https://github.com/wallet-standard/wallet-standard" }, { - "lock": "package-lock.json", - "path": "node_modules/detect-browser", - "version": "5.3.0", - "license": "MIT", - "status": "approved" + "ecosystem": "npm", + "name": "@wallet-standard/features", + "version": "1.1.1", + "license": "Apache-2.0", + "category": "approved", + "repository": "https://github.com/wallet-standard/wallet-standard" }, { - "lock": "package-lock.json", - "path": "node_modules/detect-libc", - "version": "2.1.2", + "ecosystem": "npm", + "name": "@wallet-standard/wallet", + "version": "1.1.0", "license": "Apache-2.0", - "status": "approved" + "category": "approved", + "repository": "https://github.com/wallet-standard/wallet-standard" }, { - "lock": "package-lock.json", - "path": "node_modules/dezalgo", - "version": "1.0.4", - "license": "ISC", - "status": "approved" + "ecosystem": "npm", + "name": "@walletconnect/core", + "version": "2.23.0", + "license": "SEE LICENSE IN LICENSE.md", + "category": "review", + "repository": "https://github.com/WalletConnect/walletconnect-monorepo" }, { - "lock": "package-lock.json", - "path": "node_modules/dijkstrajs", - "version": "1.0.3", - "license": "MIT", - "status": "approved" + "ecosystem": "npm", + "name": "@walletconnect/core", + "version": "2.23.7", + "license": "SEE LICENSE IN LICENSE.md", + "category": "review", + "repository": "https://github.com/WalletConnect/walletconnect-monorepo" }, { - "lock": "package-lock.json", - "path": "node_modules/dunder-proto", + "ecosystem": "npm", + "name": "@walletconnect/environment", "version": "1.0.1", "license": "MIT", - "status": "approved" + "category": "approved", + "repository": "https://github.com/walletconnect/walletconnect-utils" }, { - "lock": "package-lock.json", - "path": "node_modules/ee-first", - "version": "1.1.1", + "ecosystem": "npm", + "name": "@walletconnect/events", + "version": "1.0.1", "license": "MIT", - "status": "approved" + "category": "approved", + "repository": "https://github.com/WalletConnect/walletconnect-utils" }, { - "lock": "package-lock.json", - "path": "node_modules/ejs", - "version": "3.1.10", - "license": "Apache-2.0", - "status": "approved" + "ecosystem": "npm", + "name": "@walletconnect/heartbeat", + "version": "1.2.2", + "license": "MIT", + "category": "approved", + "repository": "https://github.com/walletconnect/walletconnect-utils" }, { - "lock": "package-lock.json", - "path": "node_modules/electron-to-chromium", - "version": "1.5.438", - "license": "ISC", - "status": "approved" + "ecosystem": "npm", + "name": "@walletconnect/jsonrpc-http-connection", + "version": "1.0.8", + "license": "MIT", + "category": "approved", + "repository": "https://github.com/WalletConnect/walletconnect-utils" }, { - "lock": "package-lock.json", - "path": "node_modules/elliptic", - "version": "6.6.1", + "ecosystem": "npm", + "name": "@walletconnect/jsonrpc-provider", + "version": "1.0.14", "license": "MIT", - "status": "approved" + "category": "approved", + "repository": "https://github.com/WalletConnect/walletconnect-utils" }, { - "lock": "package-lock.json", - "path": "node_modules/elliptic/node_modules/bn.js", - "version": "4.12.4", + "ecosystem": "npm", + "name": "@walletconnect/jsonrpc-types", + "version": "1.0.4", "license": "MIT", - "status": "approved" + "category": "approved", + "repository": "https://github.com/WalletConnect/walletconnect-utils" }, { - "lock": "package-lock.json", - "path": "node_modules/emoji-regex", - "version": "8.0.0", + "ecosystem": "npm", + "name": "@walletconnect/jsonrpc-utils", + "version": "1.0.8", "license": "MIT", - "status": "approved" + "category": "approved", + "repository": "https://github.com/WalletConnect/walletconnect-utils" }, { - "lock": "package-lock.json", - "path": "node_modules/encode-utf8", - "version": "1.0.3", + "ecosystem": "npm", + "name": "@walletconnect/jsonrpc-ws-connection", + "version": "1.0.16", "license": "MIT", - "status": "approved" + "category": "approved", + "repository": "https://github.com/WalletConnect/walletconnect-utils" }, { - "lock": "package-lock.json", - "path": "node_modules/encodeurl", - "version": "2.0.0", + "ecosystem": "npm", + "name": "@walletconnect/keyvaluestorage", + "version": "1.1.1", "license": "MIT", - "status": "approved" + "category": "approved", + "repository": "https://github.com/walletconnect/walletconnect-utils" }, { - "lock": "package-lock.json", - "path": "node_modules/entities", - "version": "8.0.0", - "license": "BSD-2-Clause", - "status": "approved" + "ecosystem": "npm", + "name": "@walletconnect/logger", + "version": "3.0.0", + "license": "MIT", + "category": "approved", + "repository": "https://github.com/WalletConnect/walletconnect-utils" }, { - "lock": "package-lock.json", - "path": "node_modules/environment", - "version": "1.1.0", + "ecosystem": "npm", + "name": "@walletconnect/logger", + "version": "3.0.2", "license": "MIT", - "status": "approved" + "category": "approved", + "repository": "https://github.com/WalletConnect/walletconnect-utils" }, { - "lock": "package-lock.json", - "path": "node_modules/es-abstract", - "version": "1.24.2", + "ecosystem": "npm", + "name": "@walletconnect/relay-api", + "version": "1.0.11", "license": "MIT", - "status": "approved" + "category": "approved", + "repository": "https://github.com/walletconnect/walletconnect-utils" }, { - "lock": "package-lock.json", - "path": "node_modules/es-abstract-get", - "version": "1.0.0", + "ecosystem": "npm", + "name": "@walletconnect/relay-auth", + "version": "1.1.0", "license": "MIT", - "status": "approved" + "category": "approved", + "repository": "https://github.com/walletconnect/walletconnect-utils" }, { - "lock": "package-lock.json", - "path": "node_modules/es-define-property", - "version": "1.0.1", + "ecosystem": "npm", + "name": "@walletconnect/safe-json", + "version": "1.0.2", "license": "MIT", - "status": "approved" + "category": "approved", + "repository": "https://github.com/walletconnect/walletconnect-utils" }, { - "lock": "package-lock.json", - "path": "node_modules/es-errors", - "version": "1.3.0", - "license": "MIT", - "status": "approved" + "ecosystem": "npm", + "name": "@walletconnect/sign-client", + "version": "2.23.0", + "license": "SEE LICENSE IN LICENSE.md", + "category": "review", + "repository": "https://github.com/WalletConnect/walletconnect-monorepo" }, { - "lock": "package-lock.json", - "path": "node_modules/es-module-lexer", - "version": "2.3.1", - "license": "MIT", - "status": "approved" + "ecosystem": "npm", + "name": "@walletconnect/sign-client", + "version": "2.23.7", + "license": "SEE LICENSE IN LICENSE.md", + "category": "review", + "repository": "https://github.com/WalletConnect/walletconnect-monorepo" }, { - "lock": "package-lock.json", - "path": "node_modules/es-object-atoms", - "version": "1.1.2", + "ecosystem": "npm", + "name": "@walletconnect/time", + "version": "1.0.2", "license": "MIT", - "status": "approved" + "category": "approved", + "repository": "https://github.com/walletconnect/walletconnect-utils" }, { - "lock": "package-lock.json", - "path": "node_modules/es-set-tostringtag", - "version": "2.1.0", - "license": "MIT", - "status": "approved" + "ecosystem": "npm", + "name": "@walletconnect/types", + "version": "2.23.0", + "license": "SEE LICENSE IN LICENSE.md", + "category": "review", + "repository": "https://github.com/WalletConnect/walletconnect-monorepo" }, { - "lock": "package-lock.json", - "path": "node_modules/es-to-primitive", - "version": "1.3.4", - "license": "MIT", - "status": "approved" + "ecosystem": "npm", + "name": "@walletconnect/types", + "version": "2.23.7", + "license": "SEE LICENSE IN LICENSE.md", + "category": "review", + "repository": "https://github.com/WalletConnect/walletconnect-monorepo" }, { - "lock": "package-lock.json", - "path": "node_modules/es-toolkit", - "version": "1.44.0", - "license": "MIT", - "status": "approved" + "ecosystem": "npm", + "name": "@walletconnect/types", + "version": "2.23.9", + "license": "SEE LICENSE IN LICENSE.md", + "category": "review", + "repository": "https://github.com/WalletConnect/walletconnect-monorepo" }, { - "lock": "package-lock.json", - "path": "node_modules/es6-promise", - "version": "4.2.8", - "license": "MIT", - "status": "approved" + "ecosystem": "npm", + "name": "@walletconnect/universal-provider", + "version": "2.23.7", + "license": "SEE LICENSE IN LICENSE.md", + "category": "review", + "repository": "https://github.com/WalletConnect/walletconnect-monorepo" }, { - "lock": "package-lock.json", - "path": "node_modules/es6-promisify", - "version": "5.0.0", + "ecosystem": "npm", + "name": "@walletconnect/utils", + "version": "2.23.0", + "license": "SEE LICENSE IN LICENSE.md", + "category": "review", + "repository": "https://github.com/WalletConnect/walletconnect-monorepo" + }, + { + "ecosystem": "npm", + "name": "@walletconnect/utils", + "version": "2.23.7", + "license": "SEE LICENSE IN LICENSE.md", + "category": "review", + "repository": "https://github.com/WalletConnect/walletconnect-monorepo" + }, + { + "ecosystem": "npm", + "name": "@walletconnect/window-getters", + "version": "1.0.1", "license": "MIT", - "status": "approved" + "category": "approved", + "repository": "https://github.com/walletconnect/walletconnect-utils" }, { - "lock": "package-lock.json", - "path": "node_modules/esbuild", - "version": "0.28.2", + "ecosystem": "npm", + "name": "@walletconnect/window-metadata", + "version": "1.0.1", "license": "MIT", - "status": "approved" + "category": "approved", + "repository": "https://github.com/walletconnect/walletconnect-utils" }, { - "lock": "package-lock.json", - "path": "node_modules/escalade", - "version": "3.2.0", + "ecosystem": "npm", + "name": "abitype", + "version": "1.0.6", "license": "MIT", - "status": "approved" + "category": "approved", + "repository": "wevm/abitype" }, { - "lock": "package-lock.json", - "path": "node_modules/escape-html", - "version": "1.0.3", + "ecosystem": "npm", + "name": "abitype", + "version": "1.2.3", "license": "MIT", - "status": "approved" + "category": "approved", + "repository": "wevm/abitype" }, { - "lock": "package-lock.json", - "path": "node_modules/escape-string-regexp", - "version": "4.0.0", + "ecosystem": "npm", + "name": "abitype", + "version": "1.2.4", "license": "MIT", - "status": "approved" + "category": "approved", + "repository": "wevm/abitype" }, { - "lock": "package-lock.json", - "path": "node_modules/eslint", - "version": "9.39.5", + "ecosystem": "npm", + "name": "accepts", + "version": "1.3.8", "license": "MIT", - "status": "approved" + "category": "approved", + "repository": "jshttp/accepts" }, { - "lock": "package-lock.json", - "path": "node_modules/eslint-scope", - "version": "8.4.0", - "license": "BSD-2-Clause", - "status": "approved" + "ecosystem": "npm", + "name": "acorn", + "version": "8.18.0", + "license": "MIT", + "category": "approved", + "dev": true, + "repository": "https://github.com/acornjs/acorn" }, { - "lock": "package-lock.json", - "path": "node_modules/eslint-visitor-keys", - "version": "4.2.1", - "license": "Apache-2.0", - "status": "approved" + "ecosystem": "npm", + "name": "acorn-jsx", + "version": "5.3.2", + "license": "MIT", + "category": "approved", + "dev": true, + "repository": "https://github.com/acornjs/acorn-jsx" }, { - "lock": "package-lock.json", - "path": "node_modules/eslint/node_modules/chalk", - "version": "4.1.2", + "ecosystem": "npm", + "name": "agent-base", + "version": "6.0.2", "license": "MIT", - "status": "approved" + "category": "approved", + "repository": "git://github.com/TooTallNate/node-agent-base" }, { - "lock": "package-lock.json", - "path": "node_modules/eslint/node_modules/find-up", - "version": "5.0.0", + "ecosystem": "npm", + "name": "agentkeepalive", + "version": "4.6.0", "license": "MIT", - "status": "approved" + "category": "approved", + "repository": "git://github.com/node-modules/agentkeepalive" }, { - "lock": "package-lock.json", - "path": "node_modules/eslint/node_modules/locate-path", - "version": "6.0.0", + "ecosystem": "npm", + "name": "ajv", + "version": "6.15.0", "license": "MIT", - "status": "approved" + "category": "approved", + "dev": true, + "repository": "https://github.com/ajv-validator/ajv" }, { - "lock": "package-lock.json", - "path": "node_modules/eslint/node_modules/p-limit", - "version": "3.1.0", + "ecosystem": "npm", + "name": "ajv", + "version": "8.20.0", "license": "MIT", - "status": "approved" + "category": "approved", + "dev": true, + "repository": "ajv-validator/ajv" }, { - "lock": "package-lock.json", - "path": "node_modules/eslint/node_modules/p-locate", - "version": "5.0.0", + "ecosystem": "npm", + "name": "ansi-escapes", + "version": "7.3.0", "license": "MIT", - "status": "approved" + "category": "approved", + "dev": true, + "repository": "sindresorhus/ansi-escapes" }, { - "lock": "package-lock.json", - "path": "node_modules/espree", - "version": "10.4.0", - "license": "BSD-2-Clause", - "status": "approved" + "ecosystem": "npm", + "name": "ansi-regex", + "version": "5.0.1", + "license": "MIT", + "category": "approved", + "repository": "chalk/ansi-regex" }, { - "lock": "package-lock.json", - "path": "node_modules/esquery", - "version": "1.7.0", - "license": "BSD-3-Clause", - "status": "approved" + "ecosystem": "npm", + "name": "ansi-regex", + "version": "6.3.0", + "license": "MIT", + "category": "approved", + "dev": true, + "repository": "chalk/ansi-regex" }, { - "lock": "package-lock.json", - "path": "node_modules/esrecurse", + "ecosystem": "npm", + "name": "ansi-styles", "version": "4.3.0", - "license": "BSD-2-Clause", - "status": "approved" + "license": "MIT", + "category": "approved", + "repository": "chalk/ansi-styles" }, { - "lock": "package-lock.json", - "path": "node_modules/estraverse", - "version": "5.3.0", - "license": "BSD-2-Clause", - "status": "approved" + "ecosystem": "npm", + "name": "ansi-styles", + "version": "5.2.0", + "license": "MIT", + "category": "approved", + "dev": true, + "repository": "chalk/ansi-styles" }, { - "lock": "package-lock.json", - "path": "node_modules/estree-walker", - "version": "3.0.3", + "ecosystem": "npm", + "name": "ansi-styles", + "version": "6.2.3", "license": "MIT", - "status": "approved" + "category": "approved", + "dev": true, + "repository": "chalk/ansi-styles" }, { - "lock": "package-lock.json", - "path": "node_modules/esutils", - "version": "2.0.3", - "license": "BSD-2-Clause", - "status": "approved" + "ecosystem": "npm", + "name": "anymatch", + "version": "3.1.3", + "license": "ISC", + "category": "approved", + "repository": "https://github.com/micromatch/anymatch" }, { - "lock": "package-lock.json", - "path": "node_modules/eta", - "version": "4.6.0", - "license": "MIT", - "status": "approved" + "ecosystem": "npm", + "name": "argparse", + "version": "2.0.1", + "license": "Python-2.0", + "category": "approved", + "dev": true, + "repository": "nodeca/argparse" + }, + { + "ecosystem": "npm", + "name": "aria-query", + "version": "5.3.0", + "license": "Apache-2.0", + "category": "approved", + "dev": true, + "repository": "https://github.com/A11yance/aria-query" }, { - "lock": "package-lock.json", - "path": "node_modules/etag", - "version": "1.8.1", + "ecosystem": "npm", + "name": "arr-union", + "version": "3.1.0", "license": "MIT", - "status": "approved" + "category": "approved", + "repository": "jonschlinkert/arr-union" }, { - "lock": "package-lock.json", - "path": "node_modules/eventemitter3", - "version": "5.0.1", + "ecosystem": "npm", + "name": "array-buffer-byte-length", + "version": "1.0.2", "license": "MIT", - "status": "approved" + "category": "approved", + "dev": true, + "repository": "https://github.com/inspect-js/array-buffer-byte-length" }, { - "lock": "package-lock.json", - "path": "node_modules/events", - "version": "3.3.0", + "ecosystem": "npm", + "name": "array-flatten", + "version": "1.1.1", "license": "MIT", - "status": "approved" + "category": "approved", + "repository": "git://github.com/blakeembrey/array-flatten" }, { - "lock": "package-lock.json", - "path": "node_modules/eventsource", - "version": "4.1.0", + "ecosystem": "npm", + "name": "arraybuffer.prototype.slice", + "version": "1.0.4", "license": "MIT", - "status": "approved" + "category": "approved", + "dev": true, + "repository": "https://github.com/es-shims/ArrayBuffer.prototype.slice" }, { - "lock": "package-lock.json", - "path": "node_modules/eventsource-parser", - "version": "3.1.0", + "ecosystem": "npm", + "name": "asap", + "version": "2.0.6", "license": "MIT", - "status": "approved" + "category": "approved", + "dev": true, + "repository": "https://github.com/kriskowal/asap" }, { - "lock": "package-lock.json", - "path": "node_modules/execa", - "version": "8.0.1", + "ecosystem": "npm", + "name": "assertion-error", + "version": "2.0.1", "license": "MIT", - "status": "approved" - }, - { - "lock": "package-lock.json", - "path": "node_modules/expect-type", - "version": "1.4.0", - "license": "Apache-2.0", - "status": "approved" + "category": "approved", + "dev": true, + "repository": "git@github.com:chaijs/assertion-error" }, { - "lock": "package-lock.json", - "path": "node_modules/express", - "version": "4.22.2", + "ecosystem": "npm", + "name": "assign-symbols", + "version": "1.0.0", "license": "MIT", - "status": "approved" + "category": "approved", + "repository": "jonschlinkert/assign-symbols" }, { - "lock": "package-lock.json", - "path": "node_modules/express/node_modules/cookie", - "version": "0.7.2", + "ecosystem": "npm", + "name": "ast-v8-to-istanbul", + "version": "1.0.5", "license": "MIT", - "status": "approved" + "category": "approved", + "dev": true, + "repository": "https://github.com/AriPerkkio/ast-v8-to-istanbul" }, { - "lock": "package-lock.json", - "path": "node_modules/express/node_modules/debug", - "version": "2.6.9", + "ecosystem": "npm", + "name": "async", + "version": "3.2.6", "license": "MIT", - "status": "approved" + "category": "approved", + "dev": true, + "repository": "https://github.com/caolan/async" }, { - "lock": "package-lock.json", - "path": "node_modules/express/node_modules/http-errors", - "version": "2.0.1", + "ecosystem": "npm", + "name": "async-function", + "version": "1.0.0", "license": "MIT", - "status": "approved" + "category": "approved", + "dev": true, + "repository": "https://github.com/ljharb/async-function" }, { - "lock": "package-lock.json", - "path": "node_modules/express/node_modules/ms", - "version": "2.0.0", + "ecosystem": "npm", + "name": "asynckit", + "version": "0.4.0", "license": "MIT", - "status": "approved" + "category": "approved", + "repository": "https://github.com/alexindigo/asynckit" }, { - "lock": "package-lock.json", - "path": "node_modules/express/node_modules/setprototypeof", - "version": "1.2.0", + "ecosystem": "npm", + "name": "at-least-node", + "version": "1.0.0", "license": "ISC", - "status": "approved" + "category": "approved", + "dev": true, + "repository": "https://github.com/RyanZim/at-least-node" }, { - "lock": "package-lock.json", - "path": "node_modules/express/node_modules/toidentifier", - "version": "1.0.1", + "ecosystem": "npm", + "name": "atomic-sleep", + "version": "1.0.0", "license": "MIT", - "status": "approved" + "category": "approved", + "repository": "https://github.com/davidmarkclements/atomic-sleep" }, { - "lock": "package-lock.json", - "path": "node_modules/extend-shallow", - "version": "2.0.1", + "ecosystem": "npm", + "name": "available-typed-arrays", + "version": "1.0.7", "license": "MIT", - "status": "approved" + "category": "approved", + "dev": true, + "repository": "https://github.com/inspect-js/available-typed-arrays" }, { - "lock": "package-lock.json", - "path": "node_modules/eyes", - "version": "0.1.8", - "license": "UNKNOWN", - "status": "review" + "ecosystem": "npm", + "name": "axe-core", + "version": "4.12.1", + "license": "MPL-2.0", + "category": "review", + "dev": true, + "repository": "https://github.com/dequelabs/axe-core" }, { - "lock": "package-lock.json", - "path": "node_modules/fast-deep-equal", - "version": "3.1.3", - "license": "MIT", - "status": "approved" + "ecosystem": "npm", + "name": "axe-core", + "version": "4.13.0", + "license": "MPL-2.0", + "category": "review", + "dev": true, + "repository": "https://github.com/dequelabs/axe-core" }, { - "lock": "package-lock.json", - "path": "node_modules/fast-json-stable-stringify", - "version": "2.1.0", + "ecosystem": "npm", + "name": "axios", + "version": "1.20.0", "license": "MIT", - "status": "approved" + "category": "approved", + "repository": "https://github.com/axios/axios" }, { - "lock": "package-lock.json", - "path": "node_modules/fast-levenshtein", - "version": "2.0.6", - "license": "MIT", - "status": "approved" + "ecosystem": "npm", + "name": "axios-retry", + "version": "4.5.0", + "license": "Apache-2.0", + "category": "approved", + "repository": "https://github.com/softonic/axios-retry" }, { - "lock": "package-lock.json", - "path": "node_modules/fast-safe-stringify", - "version": "2.1.1", + "ecosystem": "npm", + "name": "babel-plugin-polyfill-corejs2", + "version": "0.4.17", "license": "MIT", - "status": "approved" + "category": "approved", + "dev": true, + "repository": "https://github.com/babel/babel-polyfills" }, { - "lock": "package-lock.json", - "path": "node_modules/fast-stable-stringify", - "version": "1.0.0", + "ecosystem": "npm", + "name": "babel-plugin-polyfill-corejs3", + "version": "0.14.2", "license": "MIT", - "status": "approved" + "category": "approved", + "dev": true, + "repository": "https://github.com/babel/babel-polyfills" }, { - "lock": "package-lock.json", - "path": "node_modules/fast-string-truncated-width", - "version": "3.0.3", + "ecosystem": "npm", + "name": "babel-plugin-polyfill-regenerator", + "version": "0.6.8", "license": "MIT", - "status": "approved" + "category": "approved", + "dev": true, + "repository": "https://github.com/babel/babel-polyfills" }, { - "lock": "package-lock.json", - "path": "node_modules/fast-string-width", - "version": "3.0.2", + "ecosystem": "npm", + "name": "balanced-match", + "version": "1.0.2", "license": "MIT", - "status": "approved" + "category": "approved", + "dev": true, + "repository": "git://github.com/juliangruber/balanced-match" }, { - "lock": "package-lock.json", - "path": "node_modules/fast-uri", - "version": "3.1.8", - "license": "BSD-3-Clause", - "status": "approved" + "ecosystem": "npm", + "name": "balanced-match", + "version": "4.0.4", + "license": "MIT", + "category": "approved", + "dev": true, + "repository": "git://github.com/juliangruber/balanced-match" }, { - "lock": "package-lock.json", - "path": "node_modules/fast-wrap-ansi", - "version": "0.2.2", + "ecosystem": "npm", + "name": "base-x", + "version": "3.0.11", "license": "MIT", - "status": "approved" + "category": "approved", + "repository": "https://github.com/cryptocoinjs/base-x" }, { - "lock": "package-lock.json", - "path": "node_modules/fdir", - "version": "6.5.0", + "ecosystem": "npm", + "name": "base-x", + "version": "5.0.1", "license": "MIT", - "status": "approved" + "category": "approved", + "repository": "https://github.com/cryptocoinjs/base-x" }, { - "lock": "package-lock.json", - "path": "node_modules/feaxios", - "version": "0.0.23", + "ecosystem": "npm", + "name": "base32.js", + "version": "0.1.0", "license": "MIT", - "status": "approved" + "category": "approved", + "repository": "git://github.com/mikepb/base32.js" }, { - "lock": "package-lock.json", - "path": "node_modules/file-entry-cache", - "version": "8.0.0", + "ecosystem": "npm", + "name": "base64-js", + "version": "1.5.1", "license": "MIT", - "status": "approved" + "category": "approved", + "repository": "git://github.com/beatgammit/base64-js" }, { - "lock": "package-lock.json", - "path": "node_modules/filelist", - "version": "1.0.6", + "ecosystem": "npm", + "name": "baseline-browser-mapping", + "version": "2.11.19", "license": "Apache-2.0", - "status": "approved" + "category": "approved", + "dev": true, + "repository": "https://github.com/web-platform-dx/baseline-browser-mapping" }, { - "lock": "package-lock.json", - "path": "node_modules/filelist/node_modules/brace-expansion", - "version": "2.1.7", + "ecosystem": "npm", + "name": "basic-auth", + "version": "2.0.1", "license": "MIT", - "status": "approved" + "category": "approved", + "repository": "jshttp/basic-auth" }, { - "lock": "package-lock.json", - "path": "node_modules/filelist/node_modules/minimatch", - "version": "5.1.9", - "license": "ISC", - "status": "approved" + "ecosystem": "npm", + "name": "bidi-js", + "version": "1.0.3", + "license": "MIT", + "category": "approved", + "dev": true, + "repository": "https://github.com/lojjic/bidi-js" }, { - "lock": "package-lock.json", - "path": "node_modules/fill-range", - "version": "7.1.1", + "ecosystem": "npm", + "name": "big.js", + "version": "6.2.2", "license": "MIT", - "status": "approved" + "category": "approved", + "repository": "https://github.com/MikeMcl/big.js" }, { - "lock": "package-lock.json", - "path": "node_modules/finalhandler", - "version": "1.3.2", + "ecosystem": "npm", + "name": "bignumber.js", + "version": "11.1.3", "license": "MIT", - "status": "approved" + "category": "approved", + "repository": "https://github.com/MikeMcl/bignumber.js" }, { - "lock": "package-lock.json", - "path": "node_modules/finalhandler/node_modules/debug", - "version": "2.6.9", + "ecosystem": "npm", + "name": "bignumber.js", + "version": "9.3.1", "license": "MIT", - "status": "approved" + "category": "approved", + "repository": "https://github.com/MikeMcl/bignumber.js" }, { - "lock": "package-lock.json", - "path": "node_modules/finalhandler/node_modules/ms", - "version": "2.0.0", + "ecosystem": "npm", + "name": "bip32-path", + "version": "0.4.2", "license": "MIT", - "status": "approved" + "category": "approved", + "repository": "https://github.com/axic/bip32-path" }, { - "lock": "package-lock.json", - "path": "node_modules/find-up", - "version": "4.1.0", + "ecosystem": "npm", + "name": "blakejs", + "version": "1.2.1", "license": "MIT", - "status": "approved" + "category": "approved", + "repository": "https://github.com/dcposch/blakejs" }, { - "lock": "package-lock.json", - "path": "node_modules/flat-cache", - "version": "4.0.1", + "ecosystem": "npm", + "name": "bn.js", + "version": "4.12.4", "license": "MIT", - "status": "approved" + "category": "approved", + "repository": "git@github.com:indutny/bn.js" }, { - "lock": "package-lock.json", - "path": "node_modules/flatted", - "version": "3.4.4", - "license": "ISC", - "status": "approved" + "ecosystem": "npm", + "name": "bn.js", + "version": "5.2.4", + "license": "MIT", + "category": "approved", + "repository": "git@github.com:indutny/bn.js" }, { - "lock": "package-lock.json", - "path": "node_modules/follow-redirects", - "version": "1.16.0", + "ecosystem": "npm", + "name": "body-parser", + "version": "1.20.8", "license": "MIT", - "status": "approved" + "category": "approved", + "repository": "expressjs/body-parser" }, { - "lock": "package-lock.json", - "path": "node_modules/for-each", - "version": "0.3.5", - "license": "MIT", - "status": "approved" + "ecosystem": "npm", + "name": "borsh", + "version": "0.7.0", + "license": "Apache-2.0", + "category": "approved", + "repository": "https://github.com/near/borsh-js" }, { - "lock": "package-lock.json", - "path": "node_modules/foreground-child", - "version": "3.3.1", - "license": "ISC", - "status": "approved" + "ecosystem": "npm", + "name": "borsh", + "version": "1.0.0", + "license": "Apache-2.0", + "category": "approved", + "repository": "https://github.com/near/borsh-js" }, { - "lock": "package-lock.json", - "path": "node_modules/form-data", - "version": "4.0.6", - "license": "MIT", - "status": "approved" + "ecosystem": "npm", + "name": "borsh", + "version": "2.0.0", + "license": "Apache-2.0", + "category": "approved", + "repository": "https://github.com/near/borsh-js" }, { - "lock": "package-lock.json", - "path": "node_modules/formidable", - "version": "3.5.4", + "ecosystem": "npm", + "name": "brace-expansion", + "version": "1.1.18", "license": "MIT", - "status": "approved" + "category": "approved", + "dev": true, + "repository": "git://github.com/juliangruber/brace-expansion" }, { - "lock": "package-lock.json", - "path": "node_modules/forwarded", - "version": "0.2.0", + "ecosystem": "npm", + "name": "brace-expansion", + "version": "2.1.4", "license": "MIT", - "status": "approved" + "category": "approved", + "dev": true, + "repository": "git://github.com/juliangruber/brace-expansion" }, { - "lock": "package-lock.json", - "path": "node_modules/fresh", - "version": "0.5.2", + "ecosystem": "npm", + "name": "brace-expansion", + "version": "5.0.9", "license": "MIT", - "status": "approved" + "category": "approved", + "dev": true, + "repository": "https://github.com/juliangruber/brace-expansion" }, { - "lock": "package-lock.json", - "path": "node_modules/fs-extra", - "version": "9.1.0", + "ecosystem": "npm", + "name": "braces", + "version": "3.0.3", "license": "MIT", - "status": "approved" + "category": "approved", + "dev": true, + "repository": "micromatch/braces" }, { - "lock": "package-lock.json", - "path": "node_modules/fsevents", - "version": "2.3.3", + "ecosystem": "npm", + "name": "brorand", + "version": "1.1.0", "license": "MIT", - "status": "approved" + "category": "approved", + "repository": "git@github.com:indutny/brorand" }, { - "lock": "package-lock.json", - "path": "node_modules/function-bind", - "version": "1.1.2", + "ecosystem": "npm", + "name": "browserslist", + "version": "4.28.8", "license": "MIT", - "status": "approved" + "category": "approved", + "dev": true, + "repository": "browserslist/browserslist" }, { - "lock": "package-lock.json", - "path": "node_modules/function.prototype.name", - "version": "1.2.0", + "ecosystem": "npm", + "name": "bs58", + "version": "4.0.1", "license": "MIT", - "status": "approved" + "category": "approved", + "repository": "https://github.com/cryptocoinjs/bs58" }, { - "lock": "package-lock.json", - "path": "node_modules/functions-have-names", - "version": "1.2.3", + "ecosystem": "npm", + "name": "bs58", + "version": "6.0.0", "license": "MIT", - "status": "approved" + "category": "approved", + "repository": "https://github.com/cryptocoinjs/bs58" }, { - "lock": "package-lock.json", - "path": "node_modules/fuse.js", - "version": "7.5.0", - "license": "Apache-2.0", - "status": "approved" + "ecosystem": "npm", + "name": "buffer", + "version": "6.0.3", + "license": "MIT", + "category": "approved", + "repository": "git://github.com/feross/buffer" }, { - "lock": "package-lock.json", - "path": "node_modules/generator-function", - "version": "2.0.1", + "ecosystem": "npm", + "name": "buffer-from", + "version": "1.1.2", "license": "MIT", - "status": "approved" + "category": "approved", + "dev": true, + "repository": "LinusU/buffer-from" }, { - "lock": "package-lock.json", - "path": "node_modules/gensync", - "version": "1.0.0-beta.2", + "ecosystem": "npm", + "name": "bufferutil", + "version": "4.1.0", "license": "MIT", - "status": "approved" + "category": "approved", + "repository": "https://github.com/websockets/bufferutil" }, { - "lock": "package-lock.json", - "path": "node_modules/get-caller-file", - "version": "2.0.5", - "license": "ISC", - "status": "approved" + "ecosystem": "npm", + "name": "bytes", + "version": "3.1.2", + "license": "MIT", + "category": "approved", + "repository": "visionmedia/bytes.js" }, { - "lock": "package-lock.json", - "path": "node_modules/get-east-asian-width", - "version": "1.7.0", + "ecosystem": "npm", + "name": "bytewise", + "version": "1.1.0", "license": "MIT", - "status": "approved" + "category": "approved", + "repository": "https://github.com/deanlandolt/bytewise" }, { - "lock": "package-lock.json", - "path": "node_modules/get-intrinsic", - "version": "1.3.0", + "ecosystem": "npm", + "name": "bytewise-core", + "version": "1.2.3", "license": "MIT", - "status": "approved" + "category": "approved", + "repository": "https://github.com/deanlandolt/bytewise-core" }, { - "lock": "package-lock.json", - "path": "node_modules/get-own-enumerable-property-symbols", - "version": "3.0.2", - "license": "ISC", - "status": "approved" + "ecosystem": "npm", + "name": "call-bind", + "version": "1.0.9", + "license": "MIT", + "category": "approved", + "dev": true, + "repository": "https://github.com/ljharb/call-bind" }, { - "lock": "package-lock.json", - "path": "node_modules/get-proto", - "version": "1.0.1", + "ecosystem": "npm", + "name": "call-bind-apply-helpers", + "version": "1.0.2", "license": "MIT", - "status": "approved" + "category": "approved", + "repository": "https://github.com/ljharb/call-bind-apply-helpers" }, { - "lock": "package-lock.json", - "path": "node_modules/get-stream", - "version": "8.0.1", + "ecosystem": "npm", + "name": "call-bound", + "version": "1.0.4", "license": "MIT", - "status": "approved" + "category": "approved", + "repository": "https://github.com/ljharb/call-bound" }, { - "lock": "package-lock.json", - "path": "node_modules/get-symbol-description", - "version": "1.1.0", + "ecosystem": "npm", + "name": "callsites", + "version": "3.1.0", "license": "MIT", - "status": "approved" + "category": "approved", + "dev": true, + "repository": "sindresorhus/callsites" }, { - "lock": "package-lock.json", - "path": "node_modules/get-value", - "version": "2.0.6", + "ecosystem": "npm", + "name": "camelcase", + "version": "5.3.1", "license": "MIT", - "status": "approved" + "category": "approved", + "repository": "sindresorhus/camelcase" }, { - "lock": "package-lock.json", - "path": "node_modules/glob", - "version": "11.1.0", - "license": "BlueOak-1.0.0", - "status": "approved" + "ecosystem": "npm", + "name": "caniuse-lite", + "version": "1.0.30001810", + "license": "CC-BY-4.0", + "category": "approved", + "dev": true, + "repository": "browserslist/caniuse-lite" }, { - "lock": "package-lock.json", - "path": "node_modules/glob-parent", - "version": "6.0.2", - "license": "ISC", - "status": "approved" + "ecosystem": "npm", + "name": "chai", + "version": "6.2.2", + "license": "MIT", + "category": "approved", + "dev": true, + "repository": "https://github.com/chaijs/chai" }, { - "lock": "package-lock.json", - "path": "node_modules/glob/node_modules/balanced-match", - "version": "4.0.4", + "ecosystem": "npm", + "name": "chalk", + "version": "4.1.2", "license": "MIT", - "status": "approved" + "category": "approved", + "dev": true, + "repository": "chalk/chalk" }, { - "lock": "package-lock.json", - "path": "node_modules/glob/node_modules/brace-expansion", - "version": "5.0.12", + "ecosystem": "npm", + "name": "chalk", + "version": "5.6.2", "license": "MIT", - "status": "approved" + "category": "approved", + "repository": "chalk/chalk" }, { - "lock": "package-lock.json", - "path": "node_modules/glob/node_modules/minimatch", - "version": "10.2.6", - "license": "BlueOak-1.0.0", - "status": "approved" + "ecosystem": "npm", + "name": "charenc", + "version": "0.0.2", + "license": "BSD-3-Clause", + "category": "approved", + "repository": "git://github.com/pvorb/node-charenc" }, { - "lock": "package-lock.json", - "path": "node_modules/globals", - "version": "14.0.0", + "ecosystem": "npm", + "name": "chokidar", + "version": "5.0.0", "license": "MIT", - "status": "approved" + "category": "approved", + "repository": "https://github.com/paulmillr/chokidar" }, { - "lock": "package-lock.json", - "path": "node_modules/globalthis", - "version": "1.0.4", + "ecosystem": "npm", + "name": "cli-cursor", + "version": "5.0.0", "license": "MIT", - "status": "approved" + "category": "approved", + "dev": true, + "repository": "sindresorhus/cli-cursor" }, { - "lock": "package-lock.json", - "path": "node_modules/gopd", - "version": "1.2.0", + "ecosystem": "npm", + "name": "cli-truncate", + "version": "4.0.0", "license": "MIT", - "status": "approved" + "category": "approved", + "dev": true, + "repository": "sindresorhus/cli-truncate" }, { - "lock": "package-lock.json", - "path": "node_modules/graceful-fs", - "version": "4.2.11", + "ecosystem": "npm", + "name": "cli-width", + "version": "4.1.0", "license": "ISC", - "status": "approved" + "category": "approved", + "dev": true, + "repository": "git@github.com:knownasilya/cli-width" }, { - "lock": "package-lock.json", - "path": "node_modules/graphql", - "version": "16.14.2", + "ecosystem": "npm", + "name": "cliui", + "version": "6.0.0", + "license": "ISC", + "category": "approved", + "repository": "http://github.com/yargs/cliui" + }, + { + "ecosystem": "npm", + "name": "cliui", + "version": "8.0.1", + "license": "ISC", + "category": "approved", + "dev": true, + "repository": "yargs/cliui" + }, + { + "ecosystem": "npm", + "name": "clsx", + "version": "1.2.1", "license": "MIT", - "status": "approved" + "category": "approved", + "repository": "lukeed/clsx" }, { - "lock": "package-lock.json", - "path": "node_modules/h3", - "version": "1.15.11", + "ecosystem": "npm", + "name": "color-convert", + "version": "2.0.1", "license": "MIT", - "status": "approved" + "category": "approved", + "repository": "Qix-/color-convert" }, { - "lock": "package-lock.json", - "path": "node_modules/has-bigints", - "version": "1.1.0", + "ecosystem": "npm", + "name": "color-name", + "version": "1.1.4", "license": "MIT", - "status": "approved" + "category": "approved", + "repository": "git@github.com:colorjs/color-name" }, { - "lock": "package-lock.json", - "path": "node_modules/has-flag", - "version": "4.0.0", + "ecosystem": "npm", + "name": "colorette", + "version": "2.0.20", "license": "MIT", - "status": "approved" + "category": "approved", + "dev": true, + "repository": "jorgebucaran/colorette" }, { - "lock": "package-lock.json", - "path": "node_modules/has-property-descriptors", - "version": "1.0.2", + "ecosystem": "npm", + "name": "combined-stream", + "version": "1.0.8", "license": "MIT", - "status": "approved" + "category": "approved", + "repository": "git://github.com/felixge/node-combined-stream" }, { - "lock": "package-lock.json", - "path": "node_modules/has-proto", - "version": "1.2.0", + "ecosystem": "npm", + "name": "comlink", + "version": "4.4.2", + "license": "Apache-2.0", + "category": "approved", + "repository": "https://github.com/GoogleChromeLabs/comlink" + }, + { + "ecosystem": "npm", + "name": "commander", + "version": "12.1.0", "license": "MIT", - "status": "approved" + "category": "approved", + "repository": "https://github.com/tj/commander.js" }, { - "lock": "package-lock.json", - "path": "node_modules/has-symbols", - "version": "1.1.0", + "ecosystem": "npm", + "name": "commander", + "version": "13.1.0", "license": "MIT", - "status": "approved" + "category": "approved", + "dev": true, + "repository": "https://github.com/tj/commander.js" }, { - "lock": "package-lock.json", - "path": "node_modules/has-tostringtag", - "version": "1.0.2", + "ecosystem": "npm", + "name": "commander", + "version": "14.0.2", "license": "MIT", - "status": "approved" + "category": "approved", + "repository": "https://github.com/tj/commander.js" }, { - "lock": "package-lock.json", - "path": "node_modules/hash.js", - "version": "1.1.7", + "ecosystem": "npm", + "name": "commander", + "version": "14.0.3", "license": "MIT", - "status": "approved" + "category": "approved", + "repository": "https://github.com/tj/commander.js" }, { - "lock": "package-lock.json", - "path": "node_modules/hasown", - "version": "2.0.4", + "ecosystem": "npm", + "name": "commander", + "version": "2.20.3", "license": "MIT", - "status": "approved" + "category": "approved", + "repository": "https://github.com/tj/commander.js" }, { - "lock": "package-lock.json", - "path": "node_modules/headers-polyfill", - "version": "5.0.1", + "ecosystem": "npm", + "name": "common-tags", + "version": "1.8.2", "license": "MIT", - "status": "approved" + "category": "approved", + "dev": true, + "repository": "https://github.com/zspecza/common-tags" }, { - "lock": "package-lock.json", - "path": "node_modules/headers-polyfill/node_modules/set-cookie-parser", - "version": "3.1.2", + "ecosystem": "npm", + "name": "component-emitter", + "version": "1.3.1", "license": "MIT", - "status": "approved" + "category": "approved", + "dev": true, + "repository": "https://github.com/sindresorhus/component-emitter" }, { - "lock": "package-lock.json", - "path": "node_modules/hmac-drbg", - "version": "1.0.1", + "ecosystem": "npm", + "name": "compressible", + "version": "2.0.18", "license": "MIT", - "status": "approved" + "category": "approved", + "dev": true, + "repository": "jshttp/compressible" }, { - "lock": "package-lock.json", - "path": "node_modules/htm", - "version": "3.1.1", - "license": "Apache-2.0", - "status": "approved" + "ecosystem": "npm", + "name": "compression", + "version": "1.8.1", + "license": "MIT", + "category": "approved", + "dev": true, + "repository": "expressjs/compression" }, { - "lock": "package-lock.json", - "path": "node_modules/html-encoding-sniffer", - "version": "6.0.0", + "ecosystem": "npm", + "name": "concat-map", + "version": "0.0.1", "license": "MIT", - "status": "approved" + "category": "approved", + "dev": true, + "repository": "git://github.com/substack/node-concat-map" }, { - "lock": "package-lock.json", - "path": "node_modules/https-proxy-agent", - "version": "5.0.1", + "ecosystem": "npm", + "name": "content-disposition", + "version": "0.5.4", "license": "MIT", - "status": "approved" + "category": "approved", + "repository": "jshttp/content-disposition" }, { - "lock": "package-lock.json", - "path": "node_modules/human-signals", - "version": "5.0.0", - "license": "Apache-2.0", - "status": "approved" + "ecosystem": "npm", + "name": "content-type", + "version": "1.0.5", + "license": "MIT", + "category": "approved", + "repository": "jshttp/content-type" }, { - "lock": "package-lock.json", - "path": "node_modules/humanize-ms", - "version": "1.2.1", + "ecosystem": "npm", + "name": "convert-source-map", + "version": "2.0.0", "license": "MIT", - "status": "approved" + "category": "approved", + "dev": true, + "repository": "git://github.com/thlorenz/convert-source-map" }, { - "lock": "package-lock.json", - "path": "node_modules/husky", - "version": "9.1.7", + "ecosystem": "npm", + "name": "cookie", + "version": "0.7.2", "license": "MIT", - "status": "approved" + "category": "approved", + "repository": "jshttp/cookie" }, { - "lock": "package-lock.json", - "path": "node_modules/iceberg-js", - "version": "0.8.1", + "ecosystem": "npm", + "name": "cookie", + "version": "1.1.1", "license": "MIT", - "status": "approved" + "category": "approved", + "repository": "jshttp/cookie" }, { - "lock": "package-lock.json", - "path": "node_modules/iconv-lite", - "version": "0.4.24", + "ecosystem": "npm", + "name": "cookie-es", + "version": "1.2.3", "license": "MIT", - "status": "approved" + "category": "approved", + "repository": "unjs/cookie-es" }, { - "lock": "package-lock.json", - "path": "node_modules/idb", - "version": "7.1.1", - "license": "ISC", - "status": "approved" + "ecosystem": "npm", + "name": "cookie-signature", + "version": "1.0.7", + "license": "MIT", + "category": "approved", + "repository": "https://github.com/visionmedia/node-cookie-signature" }, { - "lock": "package-lock.json", - "path": "node_modules/idb-keyval", - "version": "6.2.1", - "license": "Apache-2.0", - "status": "approved" + "ecosystem": "npm", + "name": "cookie-signature", + "version": "1.2.2", + "license": "MIT", + "category": "approved", + "dev": true, + "repository": "https://github.com/visionmedia/node-cookie-signature" }, { - "lock": "package-lock.json", - "path": "node_modules/ieee754", - "version": "1.2.1", - "license": "BSD-3-Clause", - "status": "approved" + "ecosystem": "npm", + "name": "cookiejar", + "version": "2.1.4", + "license": "MIT", + "category": "approved", + "dev": true, + "repository": "https://github.com/bmeck/node-cookiejar" }, { - "lock": "package-lock.json", - "path": "node_modules/ignore", - "version": "5.3.2", + "ecosystem": "npm", + "name": "core-js-compat", + "version": "3.50.0", "license": "MIT", - "status": "approved" + "category": "approved", + "dev": true, + "repository": "https://github.com/zloirock/core-js" }, { - "lock": "package-lock.json", - "path": "node_modules/import-fresh", - "version": "3.3.1", + "ecosystem": "npm", + "name": "cors", + "version": "2.8.6", "license": "MIT", - "status": "approved" + "category": "approved", + "repository": "expressjs/cors" }, { - "lock": "package-lock.json", - "path": "node_modules/imurmurhash", - "version": "0.1.4", + "ecosystem": "npm", + "name": "cross-fetch", + "version": "3.2.0", "license": "MIT", - "status": "approved" + "category": "approved", + "repository": "https://github.com/lquixada/cross-fetch" }, { - "lock": "package-lock.json", - "path": "node_modules/indent-string", - "version": "4.0.0", + "ecosystem": "npm", + "name": "cross-spawn", + "version": "7.0.6", "license": "MIT", - "status": "approved" + "category": "approved", + "dev": true, + "repository": "git@github.com:moxystudio/node-cross-spawn" }, { - "lock": "package-lock.json", - "path": "node_modules/inherits", - "version": "2.0.4", - "license": "ISC", - "status": "approved" + "ecosystem": "npm", + "name": "crossws", + "version": "0.3.5", + "license": "MIT", + "category": "approved", + "repository": "h3js/crossws" }, { - "lock": "package-lock.json", - "path": "node_modules/internal-slot", - "version": "1.1.0", + "ecosystem": "npm", + "name": "crypt", + "version": "0.0.2", + "license": "BSD-3-Clause", + "category": "approved", + "repository": "git://github.com/pvorb/node-crypt" + }, + { + "ecosystem": "npm", + "name": "crypto-random-string", + "version": "2.0.0", "license": "MIT", - "status": "approved" + "category": "approved", + "dev": true, + "repository": "sindresorhus/crypto-random-string" }, { - "lock": "package-lock.json", - "path": "node_modules/ipaddr.js", - "version": "1.9.1", + "ecosystem": "npm", + "name": "css-tree", + "version": "3.2.1", + "license": "MIT", + "category": "approved", + "dev": true, + "repository": "csstree/csstree" + }, + { + "ecosystem": "npm", + "name": "css.escape", + "version": "1.5.1", "license": "MIT", - "status": "approved" + "category": "approved", + "dev": true, + "repository": "https://github.com/mathiasbynens/CSS.escape" }, { - "lock": "package-lock.json", - "path": "node_modules/iron-webcrypto", + "ecosystem": "npm", + "name": "cssfontparser", "version": "1.2.1", "license": "MIT", - "status": "approved" + "category": "approved", + "dev": true, + "repository": "git://github.com/tmpvar/cssfontparser" }, { - "lock": "package-lock.json", - "path": "node_modules/is-array-buffer", - "version": "3.0.5", + "ecosystem": "npm", + "name": "csstype", + "version": "3.2.3", "license": "MIT", - "status": "approved" + "category": "approved", + "repository": "https://github.com/frenic/csstype" }, { - "lock": "package-lock.json", - "path": "node_modules/is-async-function", - "version": "2.1.1", + "ecosystem": "npm", + "name": "data-urls", + "version": "7.0.0", "license": "MIT", - "status": "approved" + "category": "approved", + "dev": true, + "repository": "https://github.com/jsdom/data-urls" }, { - "lock": "package-lock.json", - "path": "node_modules/is-bigint", - "version": "1.1.0", + "ecosystem": "npm", + "name": "data-view-buffer", + "version": "1.0.2", "license": "MIT", - "status": "approved" + "category": "approved", + "dev": true, + "repository": "https://github.com/inspect-js/data-view-buffer" }, { - "lock": "package-lock.json", - "path": "node_modules/is-boolean-object", - "version": "1.2.2", + "ecosystem": "npm", + "name": "data-view-byte-length", + "version": "1.0.2", "license": "MIT", - "status": "approved" + "category": "approved", + "dev": true, + "repository": "https://github.com/inspect-js/data-view-byte-length" }, { - "lock": "package-lock.json", - "path": "node_modules/is-buffer", - "version": "1.1.6", + "ecosystem": "npm", + "name": "data-view-byte-offset", + "version": "1.0.1", "license": "MIT", - "status": "approved" + "category": "approved", + "dev": true, + "repository": "https://github.com/inspect-js/data-view-byte-offset" }, { - "lock": "package-lock.json", - "path": "node_modules/is-callable", - "version": "1.2.7", + "ecosystem": "npm", + "name": "dayjs", + "version": "1.11.13", "license": "MIT", - "status": "approved" + "category": "approved", + "repository": "https://github.com/iamkun/dayjs" }, { - "lock": "package-lock.json", - "path": "node_modules/is-core-module", - "version": "2.17.0", + "ecosystem": "npm", + "name": "debug", + "version": "2.6.9", "license": "MIT", - "status": "approved" + "category": "approved", + "repository": "git://github.com/visionmedia/debug" }, { - "lock": "package-lock.json", - "path": "node_modules/is-data-view", - "version": "1.0.2", + "ecosystem": "npm", + "name": "debug", + "version": "4.4.3", "license": "MIT", - "status": "approved" + "category": "approved", + "repository": "git://github.com/debug-js/debug" }, { - "lock": "package-lock.json", - "path": "node_modules/is-date-object", - "version": "1.1.0", + "ecosystem": "npm", + "name": "decamelize", + "version": "1.2.0", "license": "MIT", - "status": "approved" + "category": "approved", + "repository": "sindresorhus/decamelize" }, { - "lock": "package-lock.json", - "path": "node_modules/is-docker", - "version": "3.0.0", + "ecosystem": "npm", + "name": "decimal.js", + "version": "10.6.0", "license": "MIT", - "status": "approved" + "category": "approved", + "dev": true, + "repository": "https://github.com/MikeMcl/decimal.js" }, { - "lock": "package-lock.json", - "path": "node_modules/is-document.all", - "version": "1.0.0", + "ecosystem": "npm", + "name": "deep-is", + "version": "0.1.4", "license": "MIT", - "status": "approved" + "category": "approved", + "dev": true, + "repository": "http://github.com/thlorenz/deep-is" }, { - "lock": "package-lock.json", - "path": "node_modules/is-extendable", - "version": "0.1.1", + "ecosystem": "npm", + "name": "deepmerge", + "version": "4.3.1", "license": "MIT", - "status": "approved" + "category": "approved", + "dev": true, + "repository": "git://github.com/TehShrike/deepmerge" }, { - "lock": "package-lock.json", - "path": "node_modules/is-extglob", - "version": "2.1.1", + "ecosystem": "npm", + "name": "define-data-property", + "version": "1.1.4", "license": "MIT", - "status": "approved" + "category": "approved", + "dev": true, + "repository": "https://github.com/ljharb/define-data-property" }, { - "lock": "package-lock.json", - "path": "node_modules/is-finalizationregistry", - "version": "1.1.1", + "ecosystem": "npm", + "name": "define-lazy-prop", + "version": "2.0.0", "license": "MIT", - "status": "approved" + "category": "approved", + "dev": true, + "repository": "sindresorhus/define-lazy-prop" }, { - "lock": "package-lock.json", - "path": "node_modules/is-fullwidth-code-point", - "version": "3.0.0", + "ecosystem": "npm", + "name": "define-properties", + "version": "1.2.1", "license": "MIT", - "status": "approved" + "category": "approved", + "dev": true, + "repository": "git://github.com/ljharb/define-properties" }, { - "lock": "package-lock.json", - "path": "node_modules/is-generator-function", - "version": "1.1.2", + "ecosystem": "npm", + "name": "defu", + "version": "6.1.7", "license": "MIT", - "status": "approved" + "category": "approved", + "repository": "unjs/defu" }, { - "lock": "package-lock.json", - "path": "node_modules/is-glob", - "version": "4.0.3", + "ecosystem": "npm", + "name": "delay", + "version": "5.0.0", "license": "MIT", - "status": "approved" + "category": "approved", + "repository": "sindresorhus/delay" }, { - "lock": "package-lock.json", - "path": "node_modules/is-in-ssh", + "ecosystem": "npm", + "name": "delayed-stream", "version": "1.0.0", "license": "MIT", - "status": "approved" + "category": "approved", + "repository": "git://github.com/felixge/node-delayed-stream" }, { - "lock": "package-lock.json", - "path": "node_modules/is-inside-container", - "version": "1.0.0", + "ecosystem": "npm", + "name": "depd", + "version": "2.0.0", "license": "MIT", - "status": "approved" + "category": "approved", + "repository": "dougwilson/nodejs-depd" }, { - "lock": "package-lock.json", - "path": "node_modules/is-map", + "ecosystem": "npm", + "name": "dequal", "version": "2.0.3", "license": "MIT", - "status": "approved" + "category": "approved", + "dev": true, + "repository": "lukeed/dequal" }, { - "lock": "package-lock.json", - "path": "node_modules/is-module", - "version": "1.0.0", + "ecosystem": "npm", + "name": "destr", + "version": "2.0.5", "license": "MIT", - "status": "approved" + "category": "approved", + "repository": "unjs/destr" }, { - "lock": "package-lock.json", - "path": "node_modules/is-negative-zero", - "version": "2.0.3", + "ecosystem": "npm", + "name": "destroy", + "version": "1.2.0", "license": "MIT", - "status": "approved" + "category": "approved", + "repository": "stream-utils/destroy" }, { - "lock": "package-lock.json", - "path": "node_modules/is-node-process", - "version": "1.2.0", + "ecosystem": "npm", + "name": "detect-browser", + "version": "5.3.0", "license": "MIT", - "status": "approved" + "category": "approved", + "repository": "https://github.com/DamonOehlman/detect-browser" }, { - "lock": "package-lock.json", - "path": "node_modules/is-number", - "version": "7.0.0", - "license": "MIT", - "status": "approved" + "ecosystem": "npm", + "name": "detect-libc", + "version": "2.1.2", + "license": "Apache-2.0", + "category": "approved", + "repository": "git://github.com/lovell/detect-libc" }, { - "lock": "package-lock.json", - "path": "node_modules/is-number-object", - "version": "1.1.1", + "ecosystem": "npm", + "name": "dezalgo", + "version": "1.0.4", + "license": "ISC", + "category": "approved", + "dev": true, + "repository": "https://github.com/npm/dezalgo" + }, + { + "ecosystem": "npm", + "name": "dijkstrajs", + "version": "1.0.3", "license": "MIT", - "status": "approved" + "category": "approved", + "repository": "git://github.com/tcort/dijkstrajs" }, { - "lock": "package-lock.json", - "path": "node_modules/is-obj", - "version": "1.0.1", + "ecosystem": "npm", + "name": "dom-accessibility-api", + "version": "0.5.16", "license": "MIT", - "status": "approved" + "category": "approved", + "dev": true, + "repository": "https://github.com/eps1lon/dom-accessibility-api" }, { - "lock": "package-lock.json", - "path": "node_modules/is-plain-object", - "version": "2.0.4", + "ecosystem": "npm", + "name": "dom-accessibility-api", + "version": "0.6.3", "license": "MIT", - "status": "approved" + "category": "approved", + "dev": true, + "repository": "https://github.com/eps1lon/dom-accessibility-api" }, { - "lock": "package-lock.json", - "path": "node_modules/is-potential-custom-element-name", + "ecosystem": "npm", + "name": "dunder-proto", "version": "1.0.1", "license": "MIT", - "status": "approved" + "category": "approved", + "repository": "https://github.com/es-shims/dunder-proto" }, { - "lock": "package-lock.json", - "path": "node_modules/is-regex", - "version": "1.2.1", + "ecosystem": "npm", + "name": "ee-first", + "version": "1.1.1", "license": "MIT", - "status": "approved" + "category": "approved", + "repository": "jonathanong/ee-first" }, { - "lock": "package-lock.json", - "path": "node_modules/is-regexp", - "version": "1.0.0", - "license": "MIT", - "status": "approved" + "ecosystem": "npm", + "name": "ejs", + "version": "3.1.10", + "license": "Apache-2.0", + "category": "approved", + "dev": true, + "repository": "git://github.com/mde/ejs" }, { - "lock": "package-lock.json", - "path": "node_modules/is-retry-allowed", - "version": "3.0.0", - "license": "MIT", - "status": "approved" + "ecosystem": "npm", + "name": "electron-to-chromium", + "version": "1.5.415", + "license": "ISC", + "category": "approved", + "dev": true, + "repository": "https://github.com/Kilian/electron-to-chromium" }, { - "lock": "package-lock.json", - "path": "node_modules/is-set", - "version": "2.0.3", + "ecosystem": "npm", + "name": "elliptic", + "version": "6.6.1", "license": "MIT", - "status": "approved" + "category": "approved", + "repository": "git@github.com:indutny/elliptic" }, { - "lock": "package-lock.json", - "path": "node_modules/is-shared-array-buffer", - "version": "1.0.4", + "ecosystem": "npm", + "name": "emoji-regex", + "version": "10.6.0", "license": "MIT", - "status": "approved" + "category": "approved", + "dev": true, + "repository": "https://github.com/mathiasbynens/emoji-regex" }, { - "lock": "package-lock.json", - "path": "node_modules/is-stream", - "version": "3.0.0", + "ecosystem": "npm", + "name": "emoji-regex", + "version": "8.0.0", "license": "MIT", - "status": "approved" + "category": "approved", + "repository": "https://github.com/mathiasbynens/emoji-regex" }, { - "lock": "package-lock.json", - "path": "node_modules/is-string", - "version": "1.1.1", + "ecosystem": "npm", + "name": "encode-utf8", + "version": "1.0.3", "license": "MIT", - "status": "approved" + "category": "approved", + "repository": "LinusU/encode-utf8" }, { - "lock": "package-lock.json", - "path": "node_modules/is-symbol", - "version": "1.1.1", + "ecosystem": "npm", + "name": "encodeurl", + "version": "2.0.0", "license": "MIT", - "status": "approved" + "category": "approved", + "repository": "pillarjs/encodeurl" }, { - "lock": "package-lock.json", - "path": "node_modules/is-typed-array", - "version": "1.1.15", - "license": "MIT", - "status": "approved" + "ecosystem": "npm", + "name": "entities", + "version": "8.0.0", + "license": "BSD-2-Clause", + "category": "approved", + "dev": true, + "repository": "https://github.com/fb55/entities" }, { - "lock": "package-lock.json", - "path": "node_modules/is-weakmap", - "version": "2.0.2", + "ecosystem": "npm", + "name": "environment", + "version": "1.1.0", "license": "MIT", - "status": "approved" + "category": "approved", + "dev": true, + "repository": "sindresorhus/environment" }, { - "lock": "package-lock.json", - "path": "node_modules/is-weakref", - "version": "1.1.1", + "ecosystem": "npm", + "name": "es-abstract", + "version": "1.24.2", "license": "MIT", - "status": "approved" + "category": "approved", + "dev": true, + "repository": "git://github.com/ljharb/es-abstract" }, { - "lock": "package-lock.json", - "path": "node_modules/is-weakset", - "version": "2.0.4", + "ecosystem": "npm", + "name": "es-abstract-get", + "version": "1.0.0", "license": "MIT", - "status": "approved" + "category": "approved", + "dev": true, + "repository": "https://github.com/ljharb/es-abstract-get" }, { - "lock": "package-lock.json", - "path": "node_modules/is-wsl", - "version": "3.1.1", + "ecosystem": "npm", + "name": "es-define-property", + "version": "1.0.1", "license": "MIT", - "status": "approved" + "category": "approved", + "repository": "https://github.com/ljharb/es-define-property" }, { - "lock": "package-lock.json", - "path": "node_modules/isarray", - "version": "2.0.5", + "ecosystem": "npm", + "name": "es-errors", + "version": "1.3.0", "license": "MIT", - "status": "approved" + "category": "approved", + "repository": "https://github.com/ljharb/es-errors" }, { - "lock": "package-lock.json", - "path": "node_modules/isexe", - "version": "2.0.0", - "license": "ISC", - "status": "approved" + "ecosystem": "npm", + "name": "es-module-lexer", + "version": "2.3.1", + "license": "MIT", + "category": "approved", + "dev": true, + "repository": "https://github.com/guybedford/es-module-lexer" }, { - "lock": "package-lock.json", - "path": "node_modules/isobject", - "version": "3.0.1", + "ecosystem": "npm", + "name": "es-object-atoms", + "version": "1.1.2", "license": "MIT", - "status": "approved" + "category": "approved", + "repository": "https://github.com/ljharb/es-object-atoms" }, { - "lock": "package-lock.json", - "path": "node_modules/isomorphic-ws", - "version": "4.0.1", + "ecosystem": "npm", + "name": "es-set-tostringtag", + "version": "2.1.0", "license": "MIT", - "status": "approved" + "category": "approved", + "repository": "https://github.com/es-shims/es-set-tostringtag" }, { - "lock": "package-lock.json", - "path": "node_modules/isows", - "version": "1.0.7", + "ecosystem": "npm", + "name": "es-to-primitive", + "version": "1.3.4", "license": "MIT", - "status": "approved" + "category": "approved", + "dev": true, + "repository": "git://github.com/ljharb/es-to-primitive" }, { - "lock": "package-lock.json", - "path": "node_modules/jackspeak", - "version": "4.2.3", - "license": "BlueOak-1.0.0", - "status": "approved" + "ecosystem": "npm", + "name": "es-toolkit", + "version": "1.39.3", + "license": "MIT", + "category": "approved", + "repository": "https://github.com/toss/es-toolkit" }, { - "lock": "package-lock.json", - "path": "node_modules/jake", - "version": "10.9.4", - "license": "Apache-2.0", - "status": "approved" + "ecosystem": "npm", + "name": "es-toolkit", + "version": "1.44.0", + "license": "MIT", + "category": "approved", + "repository": "https://github.com/toss/es-toolkit" }, { - "lock": "package-lock.json", - "path": "node_modules/jayson", - "version": "4.3.0", + "ecosystem": "npm", + "name": "es6-promise", + "version": "4.2.8", "license": "MIT", - "status": "approved" + "category": "approved", + "repository": "git://github.com/stefanpenner/es6-promise" }, { - "lock": "package-lock.json", - "path": "node_modules/jayson/node_modules/@types/node", - "version": "12.20.55", + "ecosystem": "npm", + "name": "es6-promisify", + "version": "5.0.0", "license": "MIT", - "status": "approved" + "category": "approved", + "repository": "https://github.com/digitaldesignlabs/es6-promisify" }, { - "lock": "package-lock.json", - "path": "node_modules/jayson/node_modules/commander", - "version": "2.20.3", + "ecosystem": "npm", + "name": "escalade", + "version": "3.2.0", "license": "MIT", - "status": "approved" + "category": "approved", + "dev": true, + "repository": "lukeed/escalade" }, { - "lock": "package-lock.json", - "path": "node_modules/jayson/node_modules/ws", - "version": "7.5.11", + "ecosystem": "npm", + "name": "escape-html", + "version": "1.0.3", "license": "MIT", - "status": "approved" + "category": "approved", + "repository": "component/escape-html" }, { - "lock": "package-lock.json", - "path": "node_modules/jose", - "version": "6.2.3", + "ecosystem": "npm", + "name": "escape-string-regexp", + "version": "4.0.0", "license": "MIT", - "status": "approved" + "category": "approved", + "dev": true, + "repository": "sindresorhus/escape-string-regexp" }, { - "lock": "package-lock.json", - "path": "node_modules/js-sha256", - "version": "0.11.1", + "ecosystem": "npm", + "name": "eslint", + "version": "9.39.5", "license": "MIT", - "status": "approved" + "category": "approved", + "dev": true, + "repository": "eslint/eslint" }, { - "lock": "package-lock.json", - "path": "node_modules/js-tokens", - "version": "4.0.0", - "license": "MIT", - "status": "approved" + "ecosystem": "npm", + "name": "eslint-scope", + "version": "8.4.0", + "license": "BSD-2-Clause", + "category": "approved", + "dev": true, + "repository": "https://github.com/eslint/js" }, { - "lock": "package-lock.json", - "path": "node_modules/js-yaml", - "version": "4.3.2", - "license": "MIT", - "status": "approved" + "ecosystem": "npm", + "name": "eslint-visitor-keys", + "version": "3.4.3", + "license": "Apache-2.0", + "category": "approved", + "dev": true, + "repository": "eslint/eslint-visitor-keys" }, { - "lock": "package-lock.json", - "path": "node_modules/jsdom", - "version": "29.1.1", - "license": "MIT", - "status": "approved" + "ecosystem": "npm", + "name": "eslint-visitor-keys", + "version": "4.2.1", + "license": "Apache-2.0", + "category": "approved", + "dev": true, + "repository": "https://github.com/eslint/js" }, { - "lock": "package-lock.json", - "path": "node_modules/jsdom/node_modules/tr46", - "version": "6.0.0", - "license": "MIT", - "status": "approved" + "ecosystem": "npm", + "name": "espree", + "version": "10.4.0", + "license": "BSD-2-Clause", + "category": "approved", + "dev": true, + "repository": "https://github.com/eslint/js" }, { - "lock": "package-lock.json", - "path": "node_modules/jsdom/node_modules/webidl-conversions", - "version": "8.0.1", + "ecosystem": "npm", + "name": "esquery", + "version": "1.7.0", + "license": "BSD-3-Clause", + "category": "approved", + "dev": true, + "repository": "https://github.com/estools/esquery" + }, + { + "ecosystem": "npm", + "name": "esrecurse", + "version": "4.3.0", "license": "BSD-2-Clause", - "status": "approved" + "category": "approved", + "dev": true, + "repository": "https://github.com/estools/esrecurse" }, { - "lock": "package-lock.json", - "path": "node_modules/jsdom/node_modules/whatwg-url", - "version": "16.0.1", - "license": "MIT", - "status": "approved" + "ecosystem": "npm", + "name": "estraverse", + "version": "5.3.0", + "license": "BSD-2-Clause", + "category": "approved", + "dev": true, + "repository": "http://github.com/estools/estraverse" }, { - "lock": "package-lock.json", - "path": "node_modules/jsesc", - "version": "3.1.0", + "ecosystem": "npm", + "name": "estree-walker", + "version": "2.0.2", "license": "MIT", - "status": "approved" + "category": "approved", + "dev": true, + "repository": "https://github.com/Rich-Harris/estree-walker" }, { - "lock": "package-lock.json", - "path": "node_modules/json-buffer", - "version": "3.0.1", + "ecosystem": "npm", + "name": "estree-walker", + "version": "3.0.3", "license": "MIT", - "status": "approved" + "category": "approved", + "dev": true, + "repository": "https://github.com/Rich-Harris/estree-walker" }, { - "lock": "package-lock.json", - "path": "node_modules/json-schema-traverse", - "version": "0.4.1", - "license": "MIT", - "status": "approved" + "ecosystem": "npm", + "name": "esutils", + "version": "2.0.3", + "license": "BSD-2-Clause", + "category": "approved", + "dev": true, + "repository": "http://github.com/estools/esutils" }, { - "lock": "package-lock.json", - "path": "node_modules/json-stable-stringify-without-jsonify", - "version": "1.0.1", + "ecosystem": "npm", + "name": "eta", + "version": "4.6.0", "license": "MIT", - "status": "approved" + "category": "approved", + "dev": true, + "repository": "github:bgub/eta" }, { - "lock": "package-lock.json", - "path": "node_modules/json-stringify-pretty-compact", - "version": "3.0.0", + "ecosystem": "npm", + "name": "etag", + "version": "1.8.1", "license": "MIT", - "status": "approved" + "category": "approved", + "repository": "jshttp/etag" }, { - "lock": "package-lock.json", - "path": "node_modules/json-stringify-safe", + "ecosystem": "npm", + "name": "eventemitter3", "version": "5.0.1", - "license": "ISC", - "status": "approved" + "license": "MIT", + "category": "approved", + "repository": "git://github.com/primus/eventemitter3" }, { - "lock": "package-lock.json", - "path": "node_modules/json5", - "version": "2.2.3", + "ecosystem": "npm", + "name": "events", + "version": "3.3.0", "license": "MIT", - "status": "approved" + "category": "approved", + "repository": "git://github.com/Gozala/events" }, { - "lock": "package-lock.json", - "path": "node_modules/jsonfile", - "version": "6.2.1", + "ecosystem": "npm", + "name": "eventsource", + "version": "4.1.0", "license": "MIT", - "status": "approved" + "category": "approved", + "repository": "git://git@github.com/EventSource/eventsource" }, { - "lock": "package-lock.json", - "path": "node_modules/jsonpointer", - "version": "5.0.1", + "ecosystem": "npm", + "name": "eventsource-parser", + "version": "3.1.0", "license": "MIT", - "status": "approved" + "category": "approved", + "repository": "ssh://git@github.com/rexxars/eventsource-parser" }, { - "lock": "package-lock.json", - "path": "node_modules/keyv", - "version": "4.5.4", + "ecosystem": "npm", + "name": "execa", + "version": "8.0.1", "license": "MIT", - "status": "approved" + "category": "approved", + "dev": true, + "repository": "sindresorhus/execa" }, { - "lock": "package-lock.json", - "path": "node_modules/keyvaluestorage-interface", - "version": "1.0.0", + "ecosystem": "npm", + "name": "expect-type", + "version": "1.4.0", + "license": "Apache-2.0", + "category": "approved", + "dev": true, + "repository": "https://github.com/mmkal/expect-type" + }, + { + "ecosystem": "npm", + "name": "express", + "version": "4.22.2", "license": "MIT", - "status": "approved" + "category": "approved", + "repository": "expressjs/express" }, { - "lock": "package-lock.json", - "path": "node_modules/leven", - "version": "3.1.0", + "ecosystem": "npm", + "name": "express-rate-limit", + "version": "8.6.2", "license": "MIT", - "status": "approved" + "category": "approved", + "repository": "https://github.com/express-rate-limit/express-rate-limit" }, { - "lock": "package-lock.json", - "path": "node_modules/levn", - "version": "0.4.1", + "ecosystem": "npm", + "name": "extend-shallow", + "version": "2.0.1", "license": "MIT", - "status": "approved" + "category": "approved", + "repository": "jonschlinkert/extend-shallow" }, { - "lock": "package-lock.json", - "path": "node_modules/lightningcss", - "version": "1.32.0", - "license": "MPL-2.0", - "status": "review" + "ecosystem": "npm", + "name": "extend-shallow", + "version": "3.0.2", + "license": "MIT", + "category": "approved", + "repository": "jonschlinkert/extend-shallow" }, { - "lock": "package-lock.json", - "path": "node_modules/lightningcss-android-arm64", - "version": "1.32.0", - "license": "MPL-2.0", - "status": "review" + "ecosystem": "npm", + "name": "eyes", + "version": "0.1.8", + "license": "MIT", + "category": "approved" }, { - "lock": "package-lock.json", - "path": "node_modules/lightningcss-darwin-arm64", - "version": "1.32.0", - "license": "MPL-2.0", - "status": "review" + "ecosystem": "npm", + "name": "fake-indexeddb", + "version": "6.2.5", + "license": "Apache-2.0", + "category": "approved", + "dev": true, + "repository": "git://github.com/dumbmatter/fakeIndexedDB" }, { - "lock": "package-lock.json", - "path": "node_modules/lightningcss-darwin-x64", - "version": "1.32.0", - "license": "MPL-2.0", - "status": "review" + "ecosystem": "npm", + "name": "fast-deep-equal", + "version": "3.1.3", + "license": "MIT", + "category": "approved", + "dev": true, + "repository": "https://github.com/epoberezkin/fast-deep-equal" }, { - "lock": "package-lock.json", - "path": "node_modules/lightningcss-freebsd-x64", - "version": "1.32.0", - "license": "MPL-2.0", - "status": "review" + "ecosystem": "npm", + "name": "fast-json-stable-stringify", + "version": "2.1.0", + "license": "MIT", + "category": "approved", + "dev": true, + "repository": "git://github.com/epoberezkin/fast-json-stable-stringify" }, { - "lock": "package-lock.json", - "path": "node_modules/lightningcss-linux-arm-gnueabihf", - "version": "1.32.0", - "license": "MPL-2.0", - "status": "review" + "ecosystem": "npm", + "name": "fast-levenshtein", + "version": "2.0.6", + "license": "MIT", + "category": "approved", + "dev": true, + "repository": "https://github.com/hiddentao/fast-levenshtein" }, { - "lock": "package-lock.json", - "path": "node_modules/lightningcss-linux-arm64-gnu", - "version": "1.32.0", - "license": "MPL-2.0", - "status": "review" + "ecosystem": "npm", + "name": "fast-safe-stringify", + "version": "2.1.1", + "license": "MIT", + "category": "approved", + "dev": true, + "repository": "https://github.com/davidmarkclements/fast-safe-stringify" }, { - "lock": "package-lock.json", - "path": "node_modules/lightningcss-linux-arm64-musl", - "version": "1.32.0", - "license": "MPL-2.0", - "status": "review" + "ecosystem": "npm", + "name": "fast-stable-stringify", + "version": "1.0.0", + "license": "MIT", + "category": "approved", + "repository": "https://github.com/nickyout/fast-stable-stringify" }, { - "lock": "package-lock.json", - "path": "node_modules/lightningcss-linux-x64-gnu", - "version": "1.32.0", - "license": "MPL-2.0", - "status": "review" + "ecosystem": "npm", + "name": "fast-string-truncated-width", + "version": "3.0.3", + "license": "MIT", + "category": "approved", + "dev": true, + "repository": "github:fabiospampinato/fast-string-truncated-width" }, { - "lock": "package-lock.json", - "path": "node_modules/lightningcss-linux-x64-musl", - "version": "1.32.0", - "license": "MPL-2.0", - "status": "review" + "ecosystem": "npm", + "name": "fast-string-width", + "version": "3.0.2", + "license": "MIT", + "category": "approved", + "dev": true, + "repository": "github:fabiospampinato/fast-string-width" }, { - "lock": "package-lock.json", - "path": "node_modules/lightningcss-win32-arm64-msvc", - "version": "1.32.0", - "license": "MPL-2.0", - "status": "review" + "ecosystem": "npm", + "name": "fast-uri", + "version": "3.1.6", + "license": "BSD-3-Clause", + "category": "approved", + "dev": true, + "repository": "https://github.com/fastify/fast-uri" }, { - "lock": "package-lock.json", - "path": "node_modules/lightningcss-win32-x64-msvc", - "version": "1.32.0", - "license": "MPL-2.0", - "status": "review" + "ecosystem": "npm", + "name": "fast-wrap-ansi", + "version": "0.2.2", + "license": "MIT", + "category": "approved", + "dev": true, + "repository": "https://github.com/43081j/fast-wrap-ansi" }, { - "lock": "package-lock.json", - "path": "node_modules/lilconfig", - "version": "3.1.3", + "ecosystem": "npm", + "name": "fdir", + "version": "6.5.0", "license": "MIT", - "status": "approved" + "category": "approved", + "dev": true, + "repository": "https://github.com/thecodrr/fdir" }, { - "lock": "package-lock.json", - "path": "node_modules/lint-staged", - "version": "15.5.2", + "ecosystem": "npm", + "name": "feaxios", + "version": "0.0.23", "license": "MIT", - "status": "approved" + "category": "approved", + "repository": "divyam234/feaxios" }, { - "lock": "package-lock.json", - "path": "node_modules/lint-staged/node_modules/commander", - "version": "13.1.0", + "ecosystem": "npm", + "name": "file-entry-cache", + "version": "8.0.0", "license": "MIT", - "status": "approved" + "category": "approved", + "dev": true, + "repository": "jaredwray/file-entry-cache" }, { - "lock": "package-lock.json", - "path": "node_modules/listr2", - "version": "8.3.3", + "ecosystem": "npm", + "name": "filelist", + "version": "1.0.6", + "license": "Apache-2.0", + "category": "approved", + "dev": true, + "repository": "git://github.com/mde/filelist" + }, + { + "ecosystem": "npm", + "name": "fill-range", + "version": "7.1.1", "license": "MIT", - "status": "approved" + "category": "approved", + "dev": true, + "repository": "jonschlinkert/fill-range" }, { - "lock": "package-lock.json", - "path": "node_modules/listr2/node_modules/ansi-regex", - "version": "6.3.0", + "ecosystem": "npm", + "name": "finalhandler", + "version": "1.3.2", "license": "MIT", - "status": "approved" + "category": "approved", + "repository": "pillarjs/finalhandler" }, { - "lock": "package-lock.json", - "path": "node_modules/listr2/node_modules/ansi-styles", - "version": "6.2.3", + "ecosystem": "npm", + "name": "find-up", + "version": "4.1.0", "license": "MIT", - "status": "approved" + "category": "approved", + "repository": "sindresorhus/find-up" }, { - "lock": "package-lock.json", - "path": "node_modules/listr2/node_modules/emoji-regex", - "version": "10.6.0", + "ecosystem": "npm", + "name": "find-up", + "version": "5.0.0", "license": "MIT", - "status": "approved" + "category": "approved", + "dev": true, + "repository": "sindresorhus/find-up" }, { - "lock": "package-lock.json", - "path": "node_modules/listr2/node_modules/string-width", - "version": "7.2.0", + "ecosystem": "npm", + "name": "flat-cache", + "version": "4.0.1", "license": "MIT", - "status": "approved" + "category": "approved", + "dev": true, + "repository": "jaredwray/flat-cache" }, { - "lock": "package-lock.json", - "path": "node_modules/listr2/node_modules/strip-ansi", - "version": "7.2.0", + "ecosystem": "npm", + "name": "flatted", + "version": "3.4.4", + "license": "ISC", + "category": "approved", + "dev": true, + "repository": "https://github.com/WebReflection/flatted" + }, + { + "ecosystem": "npm", + "name": "follow-redirects", + "version": "1.16.0", "license": "MIT", - "status": "approved" + "category": "approved", + "repository": "ssh://git@github.com/follow-redirects/follow-redirects" }, { - "lock": "package-lock.json", - "path": "node_modules/listr2/node_modules/wrap-ansi", - "version": "9.0.2", + "ecosystem": "npm", + "name": "for-each", + "version": "0.3.5", "license": "MIT", - "status": "approved" + "category": "approved", + "dev": true, + "repository": "https://github.com/Raynos/for-each" }, { - "lock": "package-lock.json", - "path": "node_modules/lit", - "version": "3.3.0", - "license": "BSD-3-Clause", - "status": "approved" + "ecosystem": "npm", + "name": "foreground-child", + "version": "3.3.1", + "license": "ISC", + "category": "approved", + "dev": true, + "repository": "https://github.com/tapjs/foreground-child" }, { - "lock": "package-lock.json", - "path": "node_modules/lit-element", - "version": "4.2.2", - "license": "BSD-3-Clause", - "status": "approved" + "ecosystem": "npm", + "name": "form-data", + "version": "4.0.6", + "license": "MIT", + "category": "approved", + "repository": "git://github.com/form-data/form-data" + }, + { + "ecosystem": "npm", + "name": "formidable", + "version": "3.5.4", + "license": "MIT", + "category": "approved", + "dev": true, + "repository": "node-formidable/formidable" }, { - "lock": "package-lock.json", - "path": "node_modules/lit-html", - "version": "3.3.3", - "license": "BSD-3-Clause", - "status": "approved" + "ecosystem": "npm", + "name": "forwarded", + "version": "0.2.0", + "license": "MIT", + "category": "approved", + "repository": "jshttp/forwarded" }, { - "lock": "package-lock.json", - "path": "node_modules/locate-path", - "version": "5.0.0", + "ecosystem": "npm", + "name": "fresh", + "version": "0.5.2", "license": "MIT", - "status": "approved" + "category": "approved", + "repository": "jshttp/fresh" }, { - "lock": "package-lock.json", - "path": "node_modules/lodash.debounce", - "version": "4.0.8", + "ecosystem": "npm", + "name": "fs-extra", + "version": "9.1.0", "license": "MIT", - "status": "approved" + "category": "approved", + "dev": true, + "repository": "https://github.com/jprichardson/node-fs-extra" }, { - "lock": "package-lock.json", - "path": "node_modules/lodash.merge", - "version": "4.6.2", + "ecosystem": "npm", + "name": "fsevents", + "version": "2.3.2", "license": "MIT", - "status": "approved" + "category": "approved", + "dev": true }, { - "lock": "package-lock.json", - "path": "node_modules/log-update", - "version": "6.1.0", + "ecosystem": "npm", + "name": "fsevents", + "version": "2.3.3", "license": "MIT", - "status": "approved" + "category": "approved", + "dev": true }, { - "lock": "package-lock.json", - "path": "node_modules/log-update/node_modules/ansi-regex", - "version": "6.3.0", + "ecosystem": "npm", + "name": "function-bind", + "version": "1.1.2", "license": "MIT", - "status": "approved" + "category": "approved", + "repository": "https://github.com/Raynos/function-bind" }, { - "lock": "package-lock.json", - "path": "node_modules/log-update/node_modules/ansi-styles", - "version": "6.2.3", + "ecosystem": "npm", + "name": "function.prototype.name", + "version": "1.2.0", "license": "MIT", - "status": "approved" + "category": "approved", + "dev": true, + "repository": "git://github.com/es-shims/Function.prototype.name" }, { - "lock": "package-lock.json", - "path": "node_modules/log-update/node_modules/emoji-regex", - "version": "10.6.0", + "ecosystem": "npm", + "name": "functions-have-names", + "version": "1.2.3", "license": "MIT", - "status": "approved" + "category": "approved", + "dev": true, + "repository": "https://github.com/inspect-js/functions-have-names" }, { - "lock": "package-lock.json", - "path": "node_modules/log-update/node_modules/is-fullwidth-code-point", - "version": "5.1.0", + "ecosystem": "npm", + "name": "generator-function", + "version": "2.0.1", "license": "MIT", - "status": "approved" + "category": "approved", + "dev": true, + "repository": "https://github.com/TimothyGu/generator-function" }, { - "lock": "package-lock.json", - "path": "node_modules/log-update/node_modules/slice-ansi", - "version": "7.1.2", + "ecosystem": "npm", + "name": "gensync", + "version": "1.0.0-beta.2", "license": "MIT", - "status": "approved" + "category": "approved", + "dev": true, + "repository": "https://github.com/loganfsmyth/gensync" }, { - "lock": "package-lock.json", - "path": "node_modules/log-update/node_modules/string-width", - "version": "7.2.0", - "license": "MIT", - "status": "approved" + "ecosystem": "npm", + "name": "get-caller-file", + "version": "2.0.5", + "license": "ISC", + "category": "approved", + "repository": "https://github.com/stefanpenner/get-caller-file" }, { - "lock": "package-lock.json", - "path": "node_modules/log-update/node_modules/strip-ansi", - "version": "7.2.0", + "ecosystem": "npm", + "name": "get-east-asian-width", + "version": "1.6.0", "license": "MIT", - "status": "approved" + "category": "approved", + "dev": true, + "repository": "sindresorhus/get-east-asian-width" }, { - "lock": "package-lock.json", - "path": "node_modules/log-update/node_modules/wrap-ansi", - "version": "9.0.2", + "ecosystem": "npm", + "name": "get-intrinsic", + "version": "1.3.0", "license": "MIT", - "status": "approved" + "category": "approved", + "repository": "https://github.com/ljharb/get-intrinsic" }, { - "lock": "package-lock.json", - "path": "node_modules/lru-cache", - "version": "11.5.1", - "license": "BlueOak-1.0.0", - "status": "approved" + "ecosystem": "npm", + "name": "get-own-enumerable-property-symbols", + "version": "3.0.2", + "license": "ISC", + "category": "approved", + "dev": true, + "repository": "https://github.com/mightyiam/get-own-enumerable-property-symbols" }, { - "lock": "package-lock.json", - "path": "node_modules/magic-string", - "version": "0.30.21", + "ecosystem": "npm", + "name": "get-proto", + "version": "1.0.1", "license": "MIT", - "status": "approved" + "category": "approved", + "repository": "https://github.com/ljharb/get-proto" }, { - "lock": "package-lock.json", - "path": "node_modules/mapbox-gl", - "version": "3.25.0", - "license": "SEE LICENSE IN LICENSE.txt", - "status": "review" + "ecosystem": "npm", + "name": "get-stream", + "version": "8.0.1", + "license": "MIT", + "category": "approved", + "dev": true, + "repository": "sindresorhus/get-stream" }, { - "lock": "package-lock.json", - "path": "node_modules/math-intrinsics", + "ecosystem": "npm", + "name": "get-symbol-description", "version": "1.1.0", "license": "MIT", - "status": "approved" + "category": "approved", + "dev": true, + "repository": "https://github.com/inspect-js/get-symbol-description" }, { - "lock": "package-lock.json", - "path": "node_modules/md5", - "version": "2.3.0", - "license": "BSD-3-Clause", - "status": "approved" + "ecosystem": "npm", + "name": "get-value", + "version": "2.0.6", + "license": "MIT", + "category": "approved", + "repository": "jonschlinkert/get-value" }, { - "lock": "package-lock.json", - "path": "node_modules/mdn-data", - "version": "2.27.1", - "license": "CC0-1.0", - "status": "approved" + "ecosystem": "npm", + "name": "glob", + "version": "11.1.0", + "license": "BlueOak-1.0.0", + "category": "approved", + "dev": true, + "repository": "git@github.com:isaacs/node-glob" }, { - "lock": "package-lock.json", - "path": "node_modules/media-typer", - "version": "0.3.0", - "license": "MIT", - "status": "approved" + "ecosystem": "npm", + "name": "glob-parent", + "version": "6.0.2", + "license": "ISC", + "category": "approved", + "dev": true, + "repository": "gulpjs/glob-parent" }, { - "lock": "package-lock.json", - "path": "node_modules/merge-descriptors", - "version": "1.0.3", + "ecosystem": "npm", + "name": "globals", + "version": "14.0.0", "license": "MIT", - "status": "approved" + "category": "approved", + "dev": true, + "repository": "sindresorhus/globals" }, { - "lock": "package-lock.json", - "path": "node_modules/merge-stream", - "version": "2.0.0", + "ecosystem": "npm", + "name": "globals", + "version": "17.11.0", "license": "MIT", - "status": "approved" + "category": "approved", + "dev": true, + "repository": "sindresorhus/globals" }, { - "lock": "package-lock.json", - "path": "node_modules/methods", - "version": "1.1.2", + "ecosystem": "npm", + "name": "globalthis", + "version": "1.0.4", "license": "MIT", - "status": "approved" + "category": "approved", + "dev": true, + "repository": "git://github.com/ljharb/System.global" }, { - "lock": "package-lock.json", - "path": "node_modules/micromatch", - "version": "4.0.8", + "ecosystem": "npm", + "name": "gopd", + "version": "1.2.0", "license": "MIT", - "status": "approved" + "category": "approved", + "repository": "https://github.com/ljharb/gopd" }, { - "lock": "package-lock.json", - "path": "node_modules/micromatch/node_modules/picomatch", - "version": "2.3.2", - "license": "MIT", - "status": "approved" + "ecosystem": "npm", + "name": "graceful-fs", + "version": "4.2.11", + "license": "ISC", + "category": "approved", + "dev": true, + "repository": "https://github.com/isaacs/node-graceful-fs" }, { - "lock": "package-lock.json", - "path": "node_modules/mime", - "version": "1.6.0", + "ecosystem": "npm", + "name": "graphql", + "version": "16.14.2", "license": "MIT", - "status": "approved" + "category": "approved", + "dev": true, + "repository": "https://github.com/graphql/graphql-js" }, { - "lock": "package-lock.json", - "path": "node_modules/mime-db", - "version": "1.52.0", + "ecosystem": "npm", + "name": "h3", + "version": "1.15.11", "license": "MIT", - "status": "approved" + "category": "approved", + "repository": "h3js/h3" }, { - "lock": "package-lock.json", - "path": "node_modules/mime-types", - "version": "2.1.35", + "ecosystem": "npm", + "name": "has-bigints", + "version": "1.1.0", "license": "MIT", - "status": "approved" + "category": "approved", + "dev": true, + "repository": "https://github.com/ljharb/has-bigints" }, { - "lock": "package-lock.json", - "path": "node_modules/mimic-fn", + "ecosystem": "npm", + "name": "has-flag", "version": "4.0.0", "license": "MIT", - "status": "approved" + "category": "approved", + "dev": true, + "repository": "sindresorhus/has-flag" }, { - "lock": "package-lock.json", - "path": "node_modules/mimic-function", - "version": "5.0.1", + "ecosystem": "npm", + "name": "has-property-descriptors", + "version": "1.0.2", "license": "MIT", - "status": "approved" + "category": "approved", + "dev": true, + "repository": "https://github.com/inspect-js/has-property-descriptors" }, { - "lock": "package-lock.json", - "path": "node_modules/min-indent", - "version": "1.0.1", + "ecosystem": "npm", + "name": "has-proto", + "version": "1.2.0", "license": "MIT", - "status": "approved" + "category": "approved", + "dev": true, + "repository": "https://github.com/inspect-js/has-proto" }, { - "lock": "package-lock.json", - "path": "node_modules/minimalistic-assert", - "version": "1.0.1", - "license": "ISC", - "status": "approved" + "ecosystem": "npm", + "name": "has-symbols", + "version": "1.1.0", + "license": "MIT", + "category": "approved", + "repository": "git://github.com/inspect-js/has-symbols" }, { - "lock": "package-lock.json", - "path": "node_modules/minimalistic-crypto-utils", - "version": "1.0.1", + "ecosystem": "npm", + "name": "has-tostringtag", + "version": "1.0.2", "license": "MIT", - "status": "approved" + "category": "approved", + "repository": "https://github.com/inspect-js/has-tostringtag" }, { - "lock": "package-lock.json", - "path": "node_modules/minimatch", - "version": "3.1.5", - "license": "ISC", - "status": "approved" + "ecosystem": "npm", + "name": "hash.js", + "version": "1.1.7", + "license": "MIT", + "category": "approved", + "repository": "git@github.com:indutny/hash.js" }, { - "lock": "package-lock.json", - "path": "node_modules/minimist", - "version": "1.2.8", + "ecosystem": "npm", + "name": "hasown", + "version": "2.0.4", "license": "MIT", - "status": "approved" + "category": "approved", + "repository": "https://github.com/inspect-js/hasOwn" }, { - "lock": "package-lock.json", - "path": "node_modules/minipass", - "version": "7.1.3", - "license": "BlueOak-1.0.0", - "status": "approved" + "ecosystem": "npm", + "name": "headers-polyfill", + "version": "5.0.1", + "license": "MIT", + "category": "approved", + "dev": true, + "repository": "https://github.com/mswjs/headers-polyfill" }, { - "lock": "package-lock.json", - "path": "node_modules/ms", - "version": "2.1.3", + "ecosystem": "npm", + "name": "hmac-drbg", + "version": "1.0.1", "license": "MIT", - "status": "approved" + "category": "approved", + "repository": "ssh://git@github.com/indutny/hmac-drbg" }, { - "lock": "package-lock.json", - "path": "node_modules/msgpackr", - "version": "1.12.1", - "license": "MIT", - "status": "approved" + "ecosystem": "npm", + "name": "htm", + "version": "3.1.1", + "license": "Apache-2.0", + "category": "approved", + "repository": "developit/htm" }, { - "lock": "package-lock.json", - "path": "node_modules/msgpackr-extract", - "version": "3.0.4", + "ecosystem": "npm", + "name": "html-encoding-sniffer", + "version": "6.0.0", "license": "MIT", - "status": "approved" + "category": "approved", + "dev": true, + "repository": "https://github.com/jsdom/html-encoding-sniffer" }, { - "lock": "package-lock.json", - "path": "node_modules/msw", - "version": "2.15.0", + "ecosystem": "npm", + "name": "html-escaper", + "version": "2.0.2", "license": "MIT", - "status": "approved" + "category": "approved", + "dev": true, + "repository": "https://github.com/WebReflection/html-escaper" }, { - "lock": "package-lock.json", - "path": "node_modules/msw/node_modules/cliui", - "version": "8.0.1", - "license": "ISC", - "status": "approved" + "ecosystem": "npm", + "name": "html-parse-stringify", + "version": "3.1.0", + "license": "MIT", + "category": "approved", + "repository": "https://github.com/henrikjoreteg/html-parse-stringify" }, { - "lock": "package-lock.json", - "path": "node_modules/msw/node_modules/path-to-regexp", - "version": "6.3.0", + "ecosystem": "npm", + "name": "http-errors", + "version": "2.0.1", "license": "MIT", - "status": "approved" + "category": "approved", + "repository": "jshttp/http-errors" }, { - "lock": "package-lock.json", - "path": "node_modules/msw/node_modules/type-fest", - "version": "5.10.0", - "license": "(MIT OR CC0-1.0)", - "status": "approved" + "ecosystem": "npm", + "name": "https-proxy-agent", + "version": "5.0.1", + "license": "MIT", + "category": "approved", + "repository": "git://github.com/TooTallNate/node-https-proxy-agent" }, { - "lock": "package-lock.json", - "path": "node_modules/msw/node_modules/wrap-ansi", - "version": "7.0.0", - "license": "MIT", - "status": "approved" + "ecosystem": "npm", + "name": "human-signals", + "version": "5.0.0", + "license": "Apache-2.0", + "category": "approved", + "dev": true, + "repository": "ehmicky/human-signals" }, { - "lock": "package-lock.json", - "path": "node_modules/msw/node_modules/y18n", - "version": "5.0.8", - "license": "ISC", - "status": "approved" + "ecosystem": "npm", + "name": "humanize-ms", + "version": "1.2.1", + "license": "MIT", + "category": "approved", + "repository": "https://github.com/node-modules/humanize-ms" }, { - "lock": "package-lock.json", - "path": "node_modules/msw/node_modules/yargs", - "version": "17.7.3", + "ecosystem": "npm", + "name": "husky", + "version": "9.1.7", "license": "MIT", - "status": "approved" + "category": "approved", + "dev": true, + "repository": "https://github.com/typicode/husky" }, { - "lock": "package-lock.json", - "path": "node_modules/msw/node_modules/yargs-parser", - "version": "21.1.1", - "license": "ISC", - "status": "approved" + "ecosystem": "npm", + "name": "i18next", + "version": "25.10.10", + "license": "MIT", + "category": "approved", + "repository": "https://github.com/i18next/i18next" }, { - "lock": "package-lock.json", - "path": "node_modules/multiformats", - "version": "9.9.0", - "license": "(Apache-2.0 AND MIT)", - "status": "approved" + "ecosystem": "npm", + "name": "iceberg-js", + "version": "0.8.1", + "license": "MIT", + "category": "approved", + "repository": "https://github.com/supabase/iceberg-js" }, { - "lock": "package-lock.json", - "path": "node_modules/mustache", - "version": "4.0.0", + "ecosystem": "npm", + "name": "iconv-lite", + "version": "0.4.24", "license": "MIT", - "status": "approved" + "category": "approved", + "repository": "git://github.com/ashtuchkin/iconv-lite" }, { - "lock": "package-lock.json", - "path": "node_modules/mute-stream", - "version": "3.0.0", + "ecosystem": "npm", + "name": "idb", + "version": "7.1.1", "license": "ISC", - "status": "approved" + "category": "approved", + "dev": true, + "repository": "git://github.com/jakearchibald/idb" }, { - "lock": "package-lock.json", - "path": "node_modules/nanoid", - "version": "3.3.12", - "license": "MIT", - "status": "approved" + "ecosystem": "npm", + "name": "idb-keyval", + "version": "6.2.1", + "license": "Apache-2.0", + "category": "approved", + "repository": "https://github.com/jakearchibald/idb-keyval" }, { - "lock": "package-lock.json", - "path": "node_modules/natural-compare", - "version": "1.4.0", - "license": "MIT", - "status": "approved" + "ecosystem": "npm", + "name": "ieee754", + "version": "1.2.1", + "license": "BSD-3-Clause", + "category": "approved", + "repository": "git://github.com/feross/ieee754" }, { - "lock": "package-lock.json", - "path": "node_modules/negotiator", - "version": "0.6.3", + "ecosystem": "npm", + "name": "ignore", + "version": "5.3.2", "license": "MIT", - "status": "approved" + "category": "approved", + "dev": true, + "repository": "git@github.com:kaelzhang/node-ignore" }, { - "lock": "package-lock.json", - "path": "node_modules/node-fetch", - "version": "2.7.0", + "ecosystem": "npm", + "name": "import-fresh", + "version": "3.3.1", "license": "MIT", - "status": "approved" + "category": "approved", + "dev": true, + "repository": "sindresorhus/import-fresh" }, { - "lock": "package-lock.json", - "path": "node_modules/node-fetch-native", - "version": "1.6.7", + "ecosystem": "npm", + "name": "imurmurhash", + "version": "0.1.4", "license": "MIT", - "status": "approved" + "category": "approved", + "dev": true, + "repository": "https://github.com/jensyt/imurmurhash-js" }, { - "lock": "package-lock.json", - "path": "node_modules/node-gyp-build", - "version": "4.8.4", + "ecosystem": "npm", + "name": "indent-string", + "version": "4.0.0", "license": "MIT", - "status": "approved" + "category": "approved", + "dev": true, + "repository": "sindresorhus/indent-string" }, { - "lock": "package-lock.json", - "path": "node_modules/node-gyp-build-optional-packages", - "version": "5.2.2", - "license": "MIT", - "status": "approved" + "ecosystem": "npm", + "name": "inherits", + "version": "2.0.4", + "license": "ISC", + "category": "approved", + "repository": "git://github.com/isaacs/inherits" }, { - "lock": "package-lock.json", - "path": "node_modules/node-mock-http", - "version": "1.0.4", + "ecosystem": "npm", + "name": "internal-slot", + "version": "1.1.0", "license": "MIT", - "status": "approved" + "category": "approved", + "dev": true, + "repository": "https://github.com/ljharb/internal-slot" }, { - "lock": "package-lock.json", - "path": "node_modules/node-releases", - "version": "2.0.57", + "ecosystem": "npm", + "name": "ip-address", + "version": "10.5.0", "license": "MIT", - "status": "approved" + "category": "approved", + "repository": "https://github.com/beaugunderson/ip-address" }, { - "lock": "package-lock.json", - "path": "node_modules/normalize-path", - "version": "3.0.0", + "ecosystem": "npm", + "name": "ipaddr.js", + "version": "1.9.1", "license": "MIT", - "status": "approved" + "category": "approved", + "repository": "git://github.com/whitequark/ipaddr.js" }, { - "lock": "package-lock.json", - "path": "node_modules/npm-run-path", - "version": "5.3.0", + "ecosystem": "npm", + "name": "iron-webcrypto", + "version": "1.2.1", "license": "MIT", - "status": "approved" + "category": "approved", + "repository": "github:brc-dd/iron-webcrypto" }, { - "lock": "package-lock.json", - "path": "node_modules/npm-run-path/node_modules/path-key", - "version": "4.0.0", + "ecosystem": "npm", + "name": "is-array-buffer", + "version": "3.0.5", "license": "MIT", - "status": "approved" + "category": "approved", + "dev": true, + "repository": "https://github.com/inspect-js/is-array-buffer" }, { - "lock": "package-lock.json", - "path": "node_modules/object-assign", - "version": "4.1.1", + "ecosystem": "npm", + "name": "is-async-function", + "version": "2.1.1", "license": "MIT", - "status": "approved" + "category": "approved", + "dev": true, + "repository": "git://github.com/inspect-js/is-async-function" }, { - "lock": "package-lock.json", - "path": "node_modules/object-inspect", - "version": "1.13.4", + "ecosystem": "npm", + "name": "is-bigint", + "version": "1.1.0", "license": "MIT", - "status": "approved" + "category": "approved", + "dev": true, + "repository": "https://github.com/inspect-js/is-bigint" }, { - "lock": "package-lock.json", - "path": "node_modules/object-keys", - "version": "1.1.1", + "ecosystem": "npm", + "name": "is-boolean-object", + "version": "1.2.2", "license": "MIT", - "status": "approved" + "category": "approved", + "dev": true, + "repository": "git://github.com/inspect-js/is-boolean-object" }, { - "lock": "package-lock.json", - "path": "node_modules/object.assign", - "version": "4.1.7", + "ecosystem": "npm", + "name": "is-buffer", + "version": "1.1.6", "license": "MIT", - "status": "approved" + "category": "approved", + "repository": "git://github.com/feross/is-buffer" }, { - "lock": "package-lock.json", - "path": "node_modules/obug", - "version": "2.1.4", + "ecosystem": "npm", + "name": "is-callable", + "version": "1.2.7", "license": "MIT", - "status": "approved" + "category": "approved", + "dev": true, + "repository": "git://github.com/inspect-js/is-callable" }, { - "lock": "package-lock.json", - "path": "node_modules/ofetch", - "version": "1.5.1", + "ecosystem": "npm", + "name": "is-core-module", + "version": "2.16.2", "license": "MIT", - "status": "approved" + "category": "approved", + "dev": true, + "repository": "https://github.com/inspect-js/is-core-module" }, { - "lock": "package-lock.json", - "path": "node_modules/on-exit-leak-free", - "version": "2.1.2", + "ecosystem": "npm", + "name": "is-data-view", + "version": "1.0.2", "license": "MIT", - "status": "approved" + "category": "approved", + "dev": true, + "repository": "https://github.com/inspect-js/is-data-view" }, { - "lock": "package-lock.json", - "path": "node_modules/on-finished", - "version": "2.4.1", + "ecosystem": "npm", + "name": "is-date-object", + "version": "1.1.0", "license": "MIT", - "status": "approved" - }, - { - "lock": "package-lock.json", - "path": "node_modules/once", - "version": "1.4.0", - "license": "ISC", - "status": "approved" + "category": "approved", + "dev": true, + "repository": "git://github.com/inspect-js/is-date-object" }, { - "lock": "package-lock.json", - "path": "node_modules/onetime", - "version": "6.0.0", + "ecosystem": "npm", + "name": "is-docker", + "version": "2.2.1", "license": "MIT", - "status": "approved" + "category": "approved", + "dev": true, + "repository": "sindresorhus/is-docker" }, { - "lock": "package-lock.json", - "path": "node_modules/open", - "version": "11.0.4", + "ecosystem": "npm", + "name": "is-document.all", + "version": "1.0.0", "license": "MIT", - "status": "approved" + "category": "approved", + "dev": true, + "repository": "https://github.com/inspect-js/is-document.all" }, { - "lock": "package-lock.json", - "path": "node_modules/optionator", - "version": "0.9.4", + "ecosystem": "npm", + "name": "is-extendable", + "version": "0.1.1", "license": "MIT", - "status": "approved" + "category": "approved", + "repository": "jonschlinkert/is-extendable" }, { - "lock": "package-lock.json", - "path": "node_modules/outvariant", - "version": "1.4.3", + "ecosystem": "npm", + "name": "is-extendable", + "version": "1.0.1", "license": "MIT", - "status": "approved" + "category": "approved", + "repository": "jonschlinkert/is-extendable" }, { - "lock": "package-lock.json", - "path": "node_modules/own-keys", - "version": "1.0.2", + "ecosystem": "npm", + "name": "is-extglob", + "version": "2.1.1", "license": "MIT", - "status": "approved" + "category": "approved", + "dev": true, + "repository": "jonschlinkert/is-extglob" }, { - "lock": "package-lock.json", - "path": "node_modules/ox", - "version": "0.6.9", + "ecosystem": "npm", + "name": "is-finalizationregistry", + "version": "1.1.1", "license": "MIT", - "status": "approved" + "category": "approved", + "dev": true, + "repository": "https://github.com/inspect-js/is-finalizationregistry" }, { - "lock": "package-lock.json", - "path": "node_modules/ox/node_modules/@noble/hashes", - "version": "1.8.0", + "ecosystem": "npm", + "name": "is-fullwidth-code-point", + "version": "3.0.0", "license": "MIT", - "status": "approved" + "category": "approved", + "repository": "sindresorhus/is-fullwidth-code-point" }, { - "lock": "package-lock.json", - "path": "node_modules/p-limit", - "version": "2.3.0", + "ecosystem": "npm", + "name": "is-fullwidth-code-point", + "version": "4.0.0", "license": "MIT", - "status": "approved" + "category": "approved", + "dev": true, + "repository": "sindresorhus/is-fullwidth-code-point" }, { - "lock": "package-lock.json", - "path": "node_modules/p-locate", - "version": "4.1.0", + "ecosystem": "npm", + "name": "is-fullwidth-code-point", + "version": "5.1.0", "license": "MIT", - "status": "approved" + "category": "approved", + "dev": true, + "repository": "sindresorhus/is-fullwidth-code-point" }, { - "lock": "package-lock.json", - "path": "node_modules/p-try", - "version": "2.2.0", + "ecosystem": "npm", + "name": "is-generator-function", + "version": "1.1.2", "license": "MIT", - "status": "approved" + "category": "approved", + "dev": true, + "repository": "git://github.com/inspect-js/is-generator-function" }, { - "lock": "package-lock.json", - "path": "node_modules/package-json-from-dist", - "version": "1.0.1", - "license": "BlueOak-1.0.0", - "status": "approved" + "ecosystem": "npm", + "name": "is-glob", + "version": "4.0.3", + "license": "MIT", + "category": "approved", + "dev": true, + "repository": "micromatch/is-glob" }, { - "lock": "package-lock.json", - "path": "node_modules/pako", - "version": "2.1.0", - "license": "(MIT AND Zlib)", - "status": "review" + "ecosystem": "npm", + "name": "is-map", + "version": "2.0.3", + "license": "MIT", + "category": "approved", + "dev": true, + "repository": "https://github.com/inspect-js/is-map" }, { - "lock": "package-lock.json", - "path": "node_modules/parent-module", - "version": "1.0.1", + "ecosystem": "npm", + "name": "is-module", + "version": "1.0.0", "license": "MIT", - "status": "approved" + "category": "approved", + "dev": true, + "repository": "component/is-module" }, { - "lock": "package-lock.json", - "path": "node_modules/parse5", - "version": "8.0.1", + "ecosystem": "npm", + "name": "is-negative-zero", + "version": "2.0.3", "license": "MIT", - "status": "approved" + "category": "approved", + "dev": true, + "repository": "git://github.com/inspect-js/is-negative-zero" }, { - "lock": "package-lock.json", - "path": "node_modules/parseurl", - "version": "1.3.3", + "ecosystem": "npm", + "name": "is-node-process", + "version": "1.2.0", "license": "MIT", - "status": "approved" + "category": "approved", + "dev": true, + "repository": "https://github.com/mswjs/is-node-process" }, { - "lock": "package-lock.json", - "path": "node_modules/path-exists", - "version": "4.0.0", + "ecosystem": "npm", + "name": "is-number", + "version": "7.0.0", "license": "MIT", - "status": "approved" + "category": "approved", + "dev": true, + "repository": "jonschlinkert/is-number" }, { - "lock": "package-lock.json", - "path": "node_modules/path-key", - "version": "3.1.1", + "ecosystem": "npm", + "name": "is-number-object", + "version": "1.1.1", "license": "MIT", - "status": "approved" + "category": "approved", + "dev": true, + "repository": "git://github.com/inspect-js/is-number-object" }, { - "lock": "package-lock.json", - "path": "node_modules/path-parse", - "version": "1.0.7", + "ecosystem": "npm", + "name": "is-obj", + "version": "1.0.1", "license": "MIT", - "status": "approved" + "category": "approved", + "dev": true, + "repository": "sindresorhus/is-obj" }, { - "lock": "package-lock.json", - "path": "node_modules/path-scurry", - "version": "2.0.2", - "license": "BlueOak-1.0.0", - "status": "approved" + "ecosystem": "npm", + "name": "is-plain-object", + "version": "2.0.4", + "license": "MIT", + "category": "approved", + "repository": "jonschlinkert/is-plain-object" }, { - "lock": "package-lock.json", - "path": "node_modules/path-to-regexp", - "version": "0.1.13", + "ecosystem": "npm", + "name": "is-potential-custom-element-name", + "version": "1.0.1", "license": "MIT", - "status": "approved" + "category": "approved", + "dev": true, + "repository": "https://github.com/mathiasbynens/is-potential-custom-element-name" }, { - "lock": "package-lock.json", - "path": "node_modules/pathe", - "version": "2.0.3", + "ecosystem": "npm", + "name": "is-regex", + "version": "1.2.1", "license": "MIT", - "status": "approved" + "category": "approved", + "dev": true, + "repository": "git://github.com/inspect-js/is-regex" }, { - "lock": "package-lock.json", - "path": "node_modules/pg", - "version": "8.23.0", + "ecosystem": "npm", + "name": "is-regexp", + "version": "1.0.0", "license": "MIT", - "status": "approved" + "category": "approved", + "dev": true, + "repository": "sindresorhus/is-regexp" }, { - "lock": "package-lock.json", - "path": "node_modules/pg-cloudflare", - "version": "1.4.0", + "ecosystem": "npm", + "name": "is-retry-allowed", + "version": "2.2.0", "license": "MIT", - "status": "approved" + "category": "approved", + "repository": "sindresorhus/is-retry-allowed" }, { - "lock": "package-lock.json", - "path": "node_modules/pg-connection-string", - "version": "2.14.0", + "ecosystem": "npm", + "name": "is-retry-allowed", + "version": "3.0.0", "license": "MIT", - "status": "approved" + "category": "approved", + "repository": "sindresorhus/is-retry-allowed" }, { - "lock": "package-lock.json", - "path": "node_modules/pg-int8", - "version": "1.0.1", - "license": "ISC", - "status": "approved" + "ecosystem": "npm", + "name": "is-set", + "version": "2.0.3", + "license": "MIT", + "category": "approved", + "dev": true, + "repository": "https://github.com/inspect-js/is-set" }, { - "lock": "package-lock.json", - "path": "node_modules/pg-pool", - "version": "3.14.0", + "ecosystem": "npm", + "name": "is-shared-array-buffer", + "version": "1.0.4", "license": "MIT", - "status": "approved" + "category": "approved", + "dev": true, + "repository": "https://github.com/inspect-js/is-shared-array-buffer" }, { - "lock": "package-lock.json", - "path": "node_modules/pg-protocol", - "version": "1.16.0", + "ecosystem": "npm", + "name": "is-stream", + "version": "2.0.1", "license": "MIT", - "status": "approved" + "category": "approved", + "dev": true, + "repository": "sindresorhus/is-stream" }, { - "lock": "package-lock.json", - "path": "node_modules/pg-types", - "version": "2.2.0", + "ecosystem": "npm", + "name": "is-stream", + "version": "3.0.0", "license": "MIT", - "status": "approved" + "category": "approved", + "dev": true, + "repository": "sindresorhus/is-stream" }, { - "lock": "package-lock.json", - "path": "node_modules/pgpass", - "version": "1.0.5", + "ecosystem": "npm", + "name": "is-string", + "version": "1.1.1", "license": "MIT", - "status": "approved" + "category": "approved", + "dev": true, + "repository": "git://github.com/inspect-js/is-string" }, { - "lock": "package-lock.json", - "path": "node_modules/picocolors", + "ecosystem": "npm", + "name": "is-symbol", "version": "1.1.1", - "license": "ISC", - "status": "approved" + "license": "MIT", + "category": "approved", + "dev": true, + "repository": "git://github.com/inspect-js/is-symbol" }, { - "lock": "package-lock.json", - "path": "node_modules/picomatch", - "version": "4.0.7", + "ecosystem": "npm", + "name": "is-typed-array", + "version": "1.1.15", "license": "MIT", - "status": "approved" + "category": "approved", + "dev": true, + "repository": "git://github.com/inspect-js/is-typed-array" }, { - "lock": "package-lock.json", - "path": "node_modules/pidtree", - "version": "0.6.1", + "ecosystem": "npm", + "name": "is-weakmap", + "version": "2.0.2", "license": "MIT", - "status": "approved" + "category": "approved", + "dev": true, + "repository": "https://github.com/inspect-js/is-weakmap" }, { - "lock": "package-lock.json", - "path": "node_modules/pino", - "version": "10.0.0", + "ecosystem": "npm", + "name": "is-weakref", + "version": "1.1.1", "license": "MIT", - "status": "approved" + "category": "approved", + "dev": true, + "repository": "https://github.com/inspect-js/is-weakref" }, { - "lock": "package-lock.json", - "path": "node_modules/pino-abstract-transport", - "version": "2.0.0", + "ecosystem": "npm", + "name": "is-weakset", + "version": "2.0.4", "license": "MIT", - "status": "approved" + "category": "approved", + "dev": true, + "repository": "https://github.com/inspect-js/is-weakset" }, { - "lock": "package-lock.json", - "path": "node_modules/pino-std-serializers", - "version": "7.1.0", + "ecosystem": "npm", + "name": "is-wsl", + "version": "2.2.0", "license": "MIT", - "status": "approved" + "category": "approved", + "dev": true, + "repository": "sindresorhus/is-wsl" }, { - "lock": "package-lock.json", - "path": "node_modules/pngjs", - "version": "5.0.0", + "ecosystem": "npm", + "name": "isarray", + "version": "2.0.5", "license": "MIT", - "status": "approved" + "category": "approved", + "dev": true, + "repository": "git://github.com/juliangruber/isarray" }, { - "lock": "package-lock.json", - "path": "node_modules/possible-typed-array-names", - "version": "1.1.0", - "license": "MIT", - "status": "approved" + "ecosystem": "npm", + "name": "isexe", + "version": "2.0.0", + "license": "ISC", + "category": "approved", + "dev": true, + "repository": "https://github.com/isaacs/isexe" }, { - "lock": "package-lock.json", - "path": "node_modules/postcss", - "version": "8.5.15", + "ecosystem": "npm", + "name": "isobject", + "version": "3.0.1", "license": "MIT", - "status": "approved" + "category": "approved", + "repository": "jonschlinkert/isobject" }, { - "lock": "package-lock.json", - "path": "node_modules/postgres-array", - "version": "2.0.0", + "ecosystem": "npm", + "name": "isomorphic-ws", + "version": "4.0.1", "license": "MIT", - "status": "approved" + "category": "approved", + "repository": "https://github.com/heineiuo/isomorphic-ws" }, { - "lock": "package-lock.json", - "path": "node_modules/postgres-bytea", - "version": "1.0.1", + "ecosystem": "npm", + "name": "isomorphic.js", + "version": "0.2.5", "license": "MIT", - "status": "approved" + "category": "approved", + "dev": true, + "repository": "https://github.com/dmonad/isomorphic.js" }, { - "lock": "package-lock.json", - "path": "node_modules/postgres-date", + "ecosystem": "npm", + "name": "isows", "version": "1.0.7", "license": "MIT", - "status": "approved" + "category": "approved", + "repository": "wevm/isows" }, { - "lock": "package-lock.json", - "path": "node_modules/postgres-interval", - "version": "1.2.0", - "license": "MIT", - "status": "approved" + "ecosystem": "npm", + "name": "istanbul-lib-coverage", + "version": "3.2.2", + "license": "BSD-3-Clause", + "category": "approved", + "dev": true, + "repository": "ssh://git@github.com/istanbuljs/istanbuljs" }, { - "lock": "package-lock.json", - "path": "node_modules/powershell-utils", - "version": "0.2.1", - "license": "MIT", - "status": "approved" + "ecosystem": "npm", + "name": "istanbul-lib-report", + "version": "3.0.1", + "license": "BSD-3-Clause", + "category": "approved", + "dev": true, + "repository": "ssh://git@github.com/istanbuljs/istanbuljs" }, { - "lock": "package-lock.json", - "path": "node_modules/preact", - "version": "10.24.2", - "license": "MIT", - "status": "approved" + "ecosystem": "npm", + "name": "istanbul-reports", + "version": "3.2.0", + "license": "BSD-3-Clause", + "category": "approved", + "dev": true, + "repository": "ssh://git@github.com/istanbuljs/istanbuljs" }, { - "lock": "package-lock.json", - "path": "node_modules/prelude-ls", - "version": "1.2.1", - "license": "MIT", - "status": "approved" + "ecosystem": "npm", + "name": "jackspeak", + "version": "4.2.3", + "license": "BlueOak-1.0.0", + "category": "approved", + "dev": true, + "repository": "https://github.com/isaacs/jackspeak" }, { - "lock": "package-lock.json", - "path": "node_modules/pretty-bytes", - "version": "6.1.1", - "license": "MIT", - "status": "approved" + "ecosystem": "npm", + "name": "jake", + "version": "10.9.4", + "license": "Apache-2.0", + "category": "approved", + "dev": true, + "repository": "git://github.com/jakejs/jake" }, { - "lock": "package-lock.json", - "path": "node_modules/process-warning", - "version": "5.0.0", + "ecosystem": "npm", + "name": "jayson", + "version": "4.3.0", "license": "MIT", - "status": "approved" + "category": "approved", + "repository": "git://github.com/tedeh/jayson" }, { - "lock": "package-lock.json", - "path": "node_modules/proxy-addr", - "version": "2.0.7", + "ecosystem": "npm", + "name": "jest-axe", + "version": "11.0.0", "license": "MIT", - "status": "approved" + "category": "approved", + "dev": true, + "repository": "https://github.com/NickColley/jest-axe" }, { - "lock": "package-lock.json", - "path": "node_modules/proxy-compare", - "version": "3.0.1", + "ecosystem": "npm", + "name": "jest-canvas-mock", + "version": "2.5.8", "license": "MIT", - "status": "approved" + "category": "approved", + "dev": true, + "repository": "https://github.com/hustcc/jest-canvas-mock" }, { - "lock": "package-lock.json", - "path": "node_modules/proxy-from-env", - "version": "2.1.0", + "ecosystem": "npm", + "name": "jest-diff", + "version": "30.4.1", "license": "MIT", - "status": "approved" + "category": "approved", + "dev": true, + "repository": "https://github.com/jestjs/jest" }, { - "lock": "package-lock.json", - "path": "node_modules/punycode", - "version": "2.3.1", + "ecosystem": "npm", + "name": "jest-matcher-utils", + "version": "30.4.1", "license": "MIT", - "status": "approved" + "category": "approved", + "dev": true, + "repository": "https://github.com/jestjs/jest" }, { - "lock": "package-lock.json", - "path": "node_modules/qrcode", - "version": "1.5.3", + "ecosystem": "npm", + "name": "jose", + "version": "6.2.3", "license": "MIT", - "status": "approved" + "category": "approved", + "repository": "panva/jose" }, { - "lock": "package-lock.json", - "path": "node_modules/qs", - "version": "6.15.3", - "license": "BSD-3-Clause", - "status": "approved" - }, - { - "lock": "package-lock.json", - "path": "node_modules/quick-format-unescaped", - "version": "4.0.4", + "ecosystem": "npm", + "name": "js-sha256", + "version": "0.11.1", "license": "MIT", - "status": "approved" + "category": "approved", + "repository": "https://github.com/emn178/js-sha256" }, { - "lock": "package-lock.json", - "path": "node_modules/radix3", - "version": "1.1.2", + "ecosystem": "npm", + "name": "js-sha256", + "version": "0.9.0", "license": "MIT", - "status": "approved" + "category": "approved", + "repository": "https://github.com/emn178/js-sha256" }, { - "lock": "package-lock.json", - "path": "node_modules/randombytes", - "version": "2.1.0", + "ecosystem": "npm", + "name": "js-tokens", + "version": "10.0.0", "license": "MIT", - "status": "approved" + "category": "approved", + "dev": true, + "repository": "lydell/js-tokens" }, { - "lock": "package-lock.json", - "path": "node_modules/range-parser", - "version": "1.2.1", + "ecosystem": "npm", + "name": "js-tokens", + "version": "4.0.0", "license": "MIT", - "status": "approved" + "category": "approved", + "dev": true, + "repository": "lydell/js-tokens" }, { - "lock": "package-lock.json", - "path": "node_modules/raw-body", - "version": "2.5.3", + "ecosystem": "npm", + "name": "js-yaml", + "version": "4.3.2", "license": "MIT", - "status": "approved" + "category": "approved", + "dev": true, + "repository": "nodeca/js-yaml" }, { - "lock": "package-lock.json", - "path": "node_modules/raw-body/node_modules/http-errors", - "version": "2.0.1", + "ecosystem": "npm", + "name": "jsdom", + "version": "29.1.1", "license": "MIT", - "status": "approved" + "category": "approved", + "dev": true, + "repository": "https://github.com/jsdom/jsdom" }, { - "lock": "package-lock.json", - "path": "node_modules/raw-body/node_modules/setprototypeof", - "version": "1.2.0", - "license": "ISC", - "status": "approved" + "ecosystem": "npm", + "name": "jsesc", + "version": "3.1.0", + "license": "MIT", + "category": "approved", + "dev": true, + "repository": "https://github.com/mathiasbynens/jsesc" }, { - "lock": "package-lock.json", - "path": "node_modules/raw-body/node_modules/toidentifier", - "version": "1.0.1", + "ecosystem": "npm", + "name": "json-buffer", + "version": "3.0.1", "license": "MIT", - "status": "approved" + "category": "approved", + "dev": true, + "repository": "git://github.com/dominictarr/json-buffer" }, { - "lock": "package-lock.json", - "path": "node_modules/react", - "version": "19.2.7", + "ecosystem": "npm", + "name": "json-schema-traverse", + "version": "0.4.1", "license": "MIT", - "status": "approved" + "category": "approved", + "dev": true, + "repository": "https://github.com/epoberezkin/json-schema-traverse" }, { - "lock": "package-lock.json", - "path": "node_modules/react-dom", - "version": "19.2.7", + "ecosystem": "npm", + "name": "json-schema-traverse", + "version": "1.0.0", "license": "MIT", - "status": "approved" + "category": "approved", + "dev": true, + "repository": "https://github.com/epoberezkin/json-schema-traverse" }, { - "lock": "package-lock.json", - "path": "node_modules/react-map-gl", - "version": "8.1.1", + "ecosystem": "npm", + "name": "json-stable-stringify-without-jsonify", + "version": "1.0.1", "license": "MIT", - "status": "approved" + "category": "approved", + "dev": true, + "repository": "git://github.com/samn/json-stable-stringify" }, { - "lock": "package-lock.json", - "path": "node_modules/react-router", - "version": "7.18.0", + "ecosystem": "npm", + "name": "json-stringify-pretty-compact", + "version": "3.0.0", "license": "MIT", - "status": "approved" + "category": "approved", + "repository": "lydell/json-stringify-pretty-compact" }, { - "lock": "package-lock.json", - "path": "node_modules/react-router-dom", - "version": "7.18.0", - "license": "MIT", - "status": "approved" + "ecosystem": "npm", + "name": "json-stringify-safe", + "version": "5.0.1", + "license": "ISC", + "category": "approved", + "repository": "git://github.com/isaacs/json-stringify-safe" }, { - "lock": "package-lock.json", - "path": "node_modules/readdirp", - "version": "5.0.0", + "ecosystem": "npm", + "name": "json5", + "version": "2.2.3", "license": "MIT", - "status": "approved" + "category": "approved", + "dev": true, + "repository": "https://github.com/json5/json5" }, { - "lock": "package-lock.json", - "path": "node_modules/real-require", - "version": "0.2.0", + "ecosystem": "npm", + "name": "jsonfile", + "version": "6.2.1", "license": "MIT", - "status": "approved" + "category": "approved", + "dev": true, + "repository": "git@github.com:jprichardson/node-jsonfile" }, { - "lock": "package-lock.json", - "path": "node_modules/redent", - "version": "3.0.0", + "ecosystem": "npm", + "name": "jsonpointer", + "version": "5.0.1", "license": "MIT", - "status": "approved" + "category": "approved", + "dev": true, + "repository": "https://github.com/janl/node-jsonpointer" }, { - "lock": "package-lock.json", - "path": "node_modules/reflect.getprototypeof", - "version": "1.0.10", - "license": "MIT", - "status": "approved" + "ecosystem": "npm", + "name": "kdbush", + "version": "4.1.0", + "license": "ISC", + "category": "approved", + "repository": "git://github.com/mourner/kdbush" }, { - "lock": "package-lock.json", - "path": "node_modules/regenerate", - "version": "1.4.2", + "ecosystem": "npm", + "name": "keyv", + "version": "4.5.4", "license": "MIT", - "status": "approved" + "category": "approved", + "dev": true, + "repository": "https://github.com/jaredwray/keyv" }, { - "lock": "package-lock.json", - "path": "node_modules/regenerate-unicode-properties", - "version": "10.2.2", + "ecosystem": "npm", + "name": "keyvaluestorage-interface", + "version": "1.0.0", "license": "MIT", - "status": "approved" + "category": "approved", + "repository": "https://github.com/pedrouid/keyvaluestorage-interface" }, { - "lock": "package-lock.json", - "path": "node_modules/regexp.prototype.flags", - "version": "1.5.4", + "ecosystem": "npm", + "name": "leven", + "version": "3.1.0", "license": "MIT", - "status": "approved" + "category": "approved", + "dev": true, + "repository": "sindresorhus/leven" }, { - "lock": "package-lock.json", - "path": "node_modules/regexpu-core", - "version": "6.4.0", + "ecosystem": "npm", + "name": "levn", + "version": "0.4.1", "license": "MIT", - "status": "approved" + "category": "approved", + "dev": true, + "repository": "git://github.com/gkz/levn" }, { - "lock": "package-lock.json", - "path": "node_modules/regjsgen", - "version": "0.8.0", + "ecosystem": "npm", + "name": "lib0", + "version": "0.2.117", "license": "MIT", - "status": "approved" + "category": "approved", + "dev": true, + "repository": "https://github.com/dmonad/lib0" }, { - "lock": "package-lock.json", - "path": "node_modules/regjsparser", - "version": "0.13.3", - "license": "BSD-2-Clause", - "status": "approved" + "ecosystem": "npm", + "name": "lightningcss", + "version": "1.32.0", + "license": "MPL-2.0", + "category": "review", + "dev": true, + "repository": "https://github.com/parcel-bundler/lightningcss" }, { - "lock": "package-lock.json", - "path": "node_modules/require-directory", - "version": "2.1.1", - "license": "MIT", - "status": "approved" + "ecosystem": "npm", + "name": "lightningcss-android-arm64", + "version": "1.32.0", + "license": "MPL-2.0", + "category": "review", + "dev": true }, { - "lock": "package-lock.json", - "path": "node_modules/require-from-string", - "version": "2.0.2", - "license": "MIT", - "status": "approved" + "ecosystem": "npm", + "name": "lightningcss-darwin-arm64", + "version": "1.32.0", + "license": "MPL-2.0", + "category": "review", + "dev": true }, { - "lock": "package-lock.json", - "path": "node_modules/require-main-filename", - "version": "2.0.0", - "license": "ISC", - "status": "approved" + "ecosystem": "npm", + "name": "lightningcss-darwin-x64", + "version": "1.32.0", + "license": "MPL-2.0", + "category": "review", + "dev": true }, { - "lock": "package-lock.json", - "path": "node_modules/resolve", - "version": "1.22.12", - "license": "MIT", - "status": "approved" + "ecosystem": "npm", + "name": "lightningcss-freebsd-x64", + "version": "1.32.0", + "license": "MPL-2.0", + "category": "review", + "dev": true }, { - "lock": "package-lock.json", - "path": "node_modules/resolve-from", - "version": "4.0.0", - "license": "MIT", - "status": "approved" + "ecosystem": "npm", + "name": "lightningcss-linux-arm-gnueabihf", + "version": "1.32.0", + "license": "MPL-2.0", + "category": "review", + "dev": true }, { - "lock": "package-lock.json", - "path": "node_modules/restore-cursor", - "version": "5.1.0", - "license": "MIT", - "status": "approved" + "ecosystem": "npm", + "name": "lightningcss-linux-arm64-gnu", + "version": "1.32.0", + "license": "MPL-2.0", + "category": "review", + "dev": true }, { - "lock": "package-lock.json", - "path": "node_modules/restore-cursor/node_modules/onetime", - "version": "7.0.0", - "license": "MIT", - "status": "approved" + "ecosystem": "npm", + "name": "lightningcss-linux-arm64-musl", + "version": "1.32.0", + "license": "MPL-2.0", + "category": "review", + "dev": true }, { - "lock": "package-lock.json", - "path": "node_modules/rettime", - "version": "0.11.11", - "license": "MIT", - "status": "approved" + "ecosystem": "npm", + "name": "lightningcss-linux-x64-gnu", + "version": "1.32.0", + "license": "MPL-2.0", + "category": "review", + "dev": true, + "repository": "https://github.com/parcel-bundler/lightningcss" }, { - "lock": "package-lock.json", - "path": "node_modules/rfdc", - "version": "1.4.1", - "license": "MIT", - "status": "approved" + "ecosystem": "npm", + "name": "lightningcss-linux-x64-musl", + "version": "1.32.0", + "license": "MPL-2.0", + "category": "review", + "dev": true, + "repository": "https://github.com/parcel-bundler/lightningcss" }, { - "lock": "package-lock.json", - "path": "node_modules/rolldown", - "version": "1.0.3", - "license": "MIT", - "status": "approved" + "ecosystem": "npm", + "name": "lightningcss-win32-arm64-msvc", + "version": "1.32.0", + "license": "MPL-2.0", + "category": "review", + "dev": true }, { - "lock": "package-lock.json", - "path": "node_modules/rollup", - "version": "4.63.5", - "license": "MIT", - "status": "approved" + "ecosystem": "npm", + "name": "lightningcss-win32-x64-msvc", + "version": "1.32.0", + "license": "MPL-2.0", + "category": "review", + "dev": true }, { - "lock": "package-lock.json", - "path": "node_modules/rollup-plugin-visualizer", - "version": "7.1.1", + "ecosystem": "npm", + "name": "lilconfig", + "version": "3.1.3", "license": "MIT", - "status": "approved" + "category": "approved", + "dev": true, + "repository": "https://github.com/antonk52/lilconfig" }, { - "lock": "package-lock.json", - "path": "node_modules/rollup-plugin-visualizer/node_modules/ansi-regex", - "version": "6.3.0", + "ecosystem": "npm", + "name": "lint-staged", + "version": "15.5.2", "license": "MIT", - "status": "approved" + "category": "approved", + "dev": true, + "repository": "https://github.com/lint-staged/lint-staged" }, { - "lock": "package-lock.json", - "path": "node_modules/rollup-plugin-visualizer/node_modules/ansi-styles", - "version": "6.2.3", + "ecosystem": "npm", + "name": "listr2", + "version": "8.3.3", "license": "MIT", - "status": "approved" + "category": "approved", + "dev": true, + "repository": "https://github.com/listr2/listr2" }, { - "lock": "package-lock.json", - "path": "node_modules/rollup-plugin-visualizer/node_modules/cliui", - "version": "9.0.1", - "license": "ISC", - "status": "approved" + "ecosystem": "npm", + "name": "lit", + "version": "3.3.0", + "license": "BSD-3-Clause", + "category": "approved", + "repository": "https://github.com/lit/lit" }, { - "lock": "package-lock.json", - "path": "node_modules/rollup-plugin-visualizer/node_modules/cliui/node_modules/string-width", - "version": "7.2.0", - "license": "MIT", - "status": "approved" + "ecosystem": "npm", + "name": "lit-element", + "version": "4.2.2", + "license": "BSD-3-Clause", + "category": "approved", + "repository": "https://github.com/lit/lit" }, { - "lock": "package-lock.json", - "path": "node_modules/rollup-plugin-visualizer/node_modules/emoji-regex", - "version": "10.6.0", - "license": "MIT", - "status": "approved" + "ecosystem": "npm", + "name": "lit-html", + "version": "3.3.3", + "license": "BSD-3-Clause", + "category": "approved", + "repository": "https://github.com/lit/lit" }, { - "lock": "package-lock.json", - "path": "node_modules/rollup-plugin-visualizer/node_modules/string-width", - "version": "8.3.0", + "ecosystem": "npm", + "name": "locate-path", + "version": "5.0.0", "license": "MIT", - "status": "approved" + "category": "approved", + "repository": "sindresorhus/locate-path" }, { - "lock": "package-lock.json", - "path": "node_modules/rollup-plugin-visualizer/node_modules/strip-ansi", - "version": "7.2.0", + "ecosystem": "npm", + "name": "locate-path", + "version": "6.0.0", "license": "MIT", - "status": "approved" + "category": "approved", + "dev": true, + "repository": "sindresorhus/locate-path" }, { - "lock": "package-lock.json", - "path": "node_modules/rollup-plugin-visualizer/node_modules/wrap-ansi", - "version": "9.0.2", + "ecosystem": "npm", + "name": "lodash.debounce", + "version": "4.0.8", "license": "MIT", - "status": "approved" + "category": "approved", + "dev": true, + "repository": "lodash/lodash" }, { - "lock": "package-lock.json", - "path": "node_modules/rollup-plugin-visualizer/node_modules/wrap-ansi/node_modules/string-width", - "version": "7.2.0", + "ecosystem": "npm", + "name": "lodash.merge", + "version": "4.6.2", "license": "MIT", - "status": "approved" - }, - { - "lock": "package-lock.json", - "path": "node_modules/rollup-plugin-visualizer/node_modules/y18n", - "version": "5.0.8", - "license": "ISC", - "status": "approved" + "category": "approved", + "dev": true, + "repository": "lodash/lodash" }, { - "lock": "package-lock.json", - "path": "node_modules/rollup-plugin-visualizer/node_modules/yargs", - "version": "18.2.0", + "ecosystem": "npm", + "name": "log-update", + "version": "6.1.0", "license": "MIT", - "status": "approved" + "category": "approved", + "dev": true, + "repository": "sindresorhus/log-update" }, { - "lock": "package-lock.json", - "path": "node_modules/rollup-plugin-visualizer/node_modules/yargs-parser", - "version": "22.0.0", - "license": "ISC", - "status": "approved" + "ecosystem": "npm", + "name": "lru-cache", + "version": "11.5.1", + "license": "BlueOak-1.0.0", + "category": "approved", + "repository": "ssh://git@github.com/isaacs/node-lru-cache" }, { - "lock": "package-lock.json", - "path": "node_modules/rpc-websockets", - "version": "9.3.9", - "license": "LGPL-3.0-only", - "status": "review" + "ecosystem": "npm", + "name": "lru-cache", + "version": "5.1.1", + "license": "ISC", + "category": "approved", + "dev": true, + "repository": "git://github.com/isaacs/node-lru-cache" }, { - "lock": "package-lock.json", - "path": "node_modules/rpc-websockets/node_modules/@types/ws", - "version": "8.18.1", + "ecosystem": "npm", + "name": "lz-string", + "version": "1.5.0", "license": "MIT", - "status": "approved" + "category": "approved", + "dev": true, + "repository": "https://github.com/pieroxy/lz-string" }, { - "lock": "package-lock.json", - "path": "node_modules/rpc-websockets/node_modules/uuid", - "version": "14.0.1", + "ecosystem": "npm", + "name": "magic-string", + "version": "0.30.21", "license": "MIT", - "status": "approved" + "category": "approved", + "dev": true, + "repository": "https://github.com/Rich-Harris/magic-string" }, { - "lock": "package-lock.json", - "path": "node_modules/run-applescript", - "version": "7.1.0", + "ecosystem": "npm", + "name": "magicast", + "version": "0.5.4", "license": "MIT", - "status": "approved" + "category": "approved", + "dev": true, + "repository": "unjs/magicast" }, { - "lock": "package-lock.json", - "path": "node_modules/rw", - "version": "1.3.3", - "license": "BSD-3-Clause", - "status": "approved" + "ecosystem": "npm", + "name": "make-dir", + "version": "4.0.0", + "license": "MIT", + "category": "approved", + "dev": true, + "repository": "sindresorhus/make-dir" }, { - "lock": "package-lock.json", - "path": "node_modules/rxjs", - "version": "7.8.2", - "license": "Apache-2.0", - "status": "approved" + "ecosystem": "npm", + "name": "mapbox-gl", + "version": "3.25.0", + "license": "SEE LICENSE IN LICENSE.txt", + "category": "review", + "repository": "git://github.com/mapbox/mapbox-gl-js" }, { - "lock": "package-lock.json", - "path": "node_modules/safe-array-concat", - "version": "1.1.4", + "ecosystem": "npm", + "name": "math-intrinsics", + "version": "1.1.0", "license": "MIT", - "status": "approved" + "category": "approved", + "repository": "https://github.com/es-shims/math-intrinsics" }, { - "lock": "package-lock.json", - "path": "node_modules/safe-buffer", - "version": "5.2.1", - "license": "MIT", - "status": "approved" + "ecosystem": "npm", + "name": "md5", + "version": "2.3.0", + "license": "BSD-3-Clause", + "category": "approved", + "repository": "git://github.com/pvorb/node-md5" }, { - "lock": "package-lock.json", - "path": "node_modules/safe-push-apply", - "version": "1.0.0", - "license": "MIT", - "status": "approved" + "ecosystem": "npm", + "name": "mdn-data", + "version": "2.27.1", + "license": "CC0-1.0", + "category": "approved", + "dev": true, + "repository": "https://github.com/mdn/data" }, { - "lock": "package-lock.json", - "path": "node_modules/safe-regex-test", - "version": "1.1.0", + "ecosystem": "npm", + "name": "media-typer", + "version": "0.3.0", "license": "MIT", - "status": "approved" + "category": "approved", + "repository": "jshttp/media-typer" }, { - "lock": "package-lock.json", - "path": "node_modules/safe-stable-stringify", - "version": "2.5.0", + "ecosystem": "npm", + "name": "merge-descriptors", + "version": "1.0.3", "license": "MIT", - "status": "approved" + "category": "approved", + "repository": "sindresorhus/merge-descriptors" }, { - "lock": "package-lock.json", - "path": "node_modules/safer-buffer", - "version": "2.1.2", + "ecosystem": "npm", + "name": "merge-stream", + "version": "2.0.0", "license": "MIT", - "status": "approved" + "category": "approved", + "dev": true, + "repository": "grncdr/merge-stream" }, { - "lock": "package-lock.json", - "path": "node_modules/saxes", - "version": "6.0.0", - "license": "ISC", - "status": "approved" + "ecosystem": "npm", + "name": "methods", + "version": "1.1.2", + "license": "MIT", + "category": "approved", + "repository": "jshttp/methods" }, { - "lock": "package-lock.json", - "path": "node_modules/scheduler", - "version": "0.27.0", + "ecosystem": "npm", + "name": "micromatch", + "version": "4.0.8", "license": "MIT", - "status": "approved" + "category": "approved", + "dev": true, + "repository": "micromatch/micromatch" }, { - "lock": "package-lock.json", - "path": "node_modules/secp256k1", - "version": "5.0.1", + "ecosystem": "npm", + "name": "mime", + "version": "1.6.0", "license": "MIT", - "status": "approved" + "category": "approved", + "repository": "https://github.com/broofa/node-mime" }, { - "lock": "package-lock.json", - "path": "node_modules/secp256k1/node_modules/node-addon-api", - "version": "5.1.0", + "ecosystem": "npm", + "name": "mime", + "version": "2.6.0", "license": "MIT", - "status": "approved" + "category": "approved", + "dev": true, + "repository": "https://github.com/broofa/mime" }, { - "lock": "package-lock.json", - "path": "node_modules/semver", - "version": "7.7.2", - "license": "ISC", - "status": "approved" + "ecosystem": "npm", + "name": "mime-db", + "version": "1.52.0", + "license": "MIT", + "category": "approved", + "repository": "jshttp/mime-db" }, { - "lock": "package-lock.json", - "path": "node_modules/send", - "version": "0.19.2", + "ecosystem": "npm", + "name": "mime-types", + "version": "2.1.35", "license": "MIT", - "status": "approved" + "category": "approved", + "repository": "jshttp/mime-types" }, { - "lock": "package-lock.json", - "path": "node_modules/send/node_modules/debug", - "version": "2.6.9", + "ecosystem": "npm", + "name": "mimic-fn", + "version": "4.0.0", "license": "MIT", - "status": "approved" + "category": "approved", + "dev": true, + "repository": "sindresorhus/mimic-fn" }, { - "lock": "package-lock.json", - "path": "node_modules/send/node_modules/debug/node_modules/ms", - "version": "2.0.0", + "ecosystem": "npm", + "name": "mimic-function", + "version": "5.0.1", "license": "MIT", - "status": "approved" + "category": "approved", + "dev": true, + "repository": "sindresorhus/mimic-function" }, { - "lock": "package-lock.json", - "path": "node_modules/send/node_modules/http-errors", - "version": "2.0.1", + "ecosystem": "npm", + "name": "min-indent", + "version": "1.0.1", "license": "MIT", - "status": "approved" + "category": "approved", + "dev": true, + "repository": "https://github.com/thejameskyle/min-indent" }, { - "lock": "package-lock.json", - "path": "node_modules/send/node_modules/setprototypeof", - "version": "1.2.0", + "ecosystem": "npm", + "name": "minimalistic-assert", + "version": "1.0.1", "license": "ISC", - "status": "approved" + "category": "approved", + "repository": "https://github.com/calvinmetcalf/minimalistic-assert" }, { - "lock": "package-lock.json", - "path": "node_modules/send/node_modules/toidentifier", + "ecosystem": "npm", + "name": "minimalistic-crypto-utils", "version": "1.0.1", "license": "MIT", - "status": "approved" - }, - { - "lock": "package-lock.json", - "path": "node_modules/serialize-javascript", - "version": "7.1.2", - "license": "BSD-3-Clause", - "status": "approved" + "category": "approved", + "repository": "ssh://git@github.com/indutny/minimalistic-crypto-utils" }, { - "lock": "package-lock.json", - "path": "node_modules/serve-static", - "version": "1.16.3", - "license": "MIT", - "status": "approved" + "ecosystem": "npm", + "name": "minimatch", + "version": "10.2.6", + "license": "BlueOak-1.0.0", + "category": "approved", + "dev": true, + "repository": "git@github.com:isaacs/minimatch" }, { - "lock": "package-lock.json", - "path": "node_modules/set-blocking", - "version": "2.0.0", + "ecosystem": "npm", + "name": "minimatch", + "version": "3.1.5", "license": "ISC", - "status": "approved" + "category": "approved", + "dev": true, + "repository": "git://github.com/isaacs/minimatch" }, { - "lock": "package-lock.json", - "path": "node_modules/set-cookie-parser", - "version": "2.7.2", - "license": "MIT", - "status": "approved" + "ecosystem": "npm", + "name": "minimatch", + "version": "5.1.9", + "license": "ISC", + "category": "approved", + "dev": true, + "repository": "git://github.com/isaacs/minimatch" }, { - "lock": "package-lock.json", - "path": "node_modules/set-function-length", - "version": "1.2.2", + "ecosystem": "npm", + "name": "minimist", + "version": "1.2.8", "license": "MIT", - "status": "approved" + "category": "approved", + "repository": "git://github.com/minimistjs/minimist" }, { - "lock": "package-lock.json", - "path": "node_modules/set-function-name", - "version": "2.0.2", - "license": "MIT", - "status": "approved" + "ecosystem": "npm", + "name": "minipass", + "version": "7.1.3", + "license": "BlueOak-1.0.0", + "category": "approved", + "dev": true, + "repository": "https://github.com/isaacs/minipass" }, { - "lock": "package-lock.json", - "path": "node_modules/set-proto", - "version": "1.0.0", + "ecosystem": "npm", + "name": "moo-color", + "version": "1.0.3", "license": "MIT", - "status": "approved" + "category": "approved", + "dev": true, + "repository": "https://github.com/archco/moo-color" }, { - "lock": "package-lock.json", - "path": "node_modules/set-value", - "version": "2.0.1", + "ecosystem": "npm", + "name": "morgan", + "version": "1.12.1", "license": "MIT", - "status": "approved" - }, - { - "lock": "package-lock.json", - "path": "node_modules/sha1", - "version": "1.1.1", - "license": "BSD-3-Clause", - "status": "approved" + "category": "approved", + "repository": "expressjs/morgan" }, { - "lock": "package-lock.json", - "path": "node_modules/shebang-command", + "ecosystem": "npm", + "name": "ms", "version": "2.0.0", "license": "MIT", - "status": "approved" + "category": "approved", + "repository": "zeit/ms" }, { - "lock": "package-lock.json", - "path": "node_modules/shebang-regex", - "version": "3.0.0", + "ecosystem": "npm", + "name": "ms", + "version": "2.1.3", "license": "MIT", - "status": "approved" + "category": "approved", + "repository": "vercel/ms" }, { - "lock": "package-lock.json", - "path": "node_modules/side-channel", - "version": "1.1.1", + "ecosystem": "npm", + "name": "msgpackr", + "version": "1.12.1", "license": "MIT", - "status": "approved" + "category": "approved", + "repository": "http://github.com/kriszyp/msgpackr" }, { - "lock": "package-lock.json", - "path": "node_modules/side-channel-list", - "version": "1.0.1", + "ecosystem": "npm", + "name": "msgpackr-extract", + "version": "3.0.4", "license": "MIT", - "status": "approved" + "category": "approved", + "repository": "http://github.com/kriszyp/msgpackr-extract" }, { - "lock": "package-lock.json", - "path": "node_modules/side-channel-map", - "version": "1.0.1", + "ecosystem": "npm", + "name": "msw", + "version": "2.15.0", "license": "MIT", - "status": "approved" + "category": "approved", + "dev": true, + "repository": "https://github.com/mswjs/msw" }, { - "lock": "package-lock.json", - "path": "node_modules/side-channel-weakmap", - "version": "1.0.2", - "license": "MIT", - "status": "approved" + "ecosystem": "npm", + "name": "multiformats", + "version": "9.9.0", + "license": "(Apache-2.0 AND MIT)", + "category": "approved", + "repository": "https://github.com/multiformats/js-multiformats" }, { - "lock": "package-lock.json", - "path": "node_modules/siginfo", - "version": "2.0.0", - "license": "ISC", - "status": "approved" + "ecosystem": "npm", + "name": "mustache", + "version": "4.0.0", + "license": "MIT", + "category": "approved", + "repository": "https://github.com/janl/mustache.js" }, { - "lock": "package-lock.json", - "path": "node_modules/signal-exit", - "version": "4.1.0", + "ecosystem": "npm", + "name": "mute-stream", + "version": "3.0.0", "license": "ISC", - "status": "approved" + "category": "approved", + "dev": true, + "repository": "https://github.com/npm/mute-stream" }, { - "lock": "package-lock.json", - "path": "node_modules/slice-ansi", - "version": "5.0.0", + "ecosystem": "npm", + "name": "nanoid", + "version": "3.3.19", "license": "MIT", - "status": "approved" + "category": "approved", + "dev": true, + "repository": "ai/nanoid" }, { - "lock": "package-lock.json", - "path": "node_modules/slice-ansi/node_modules/ansi-styles", - "version": "6.2.3", + "ecosystem": "npm", + "name": "natural-compare", + "version": "1.4.0", "license": "MIT", - "status": "approved" + "category": "approved", + "dev": true, + "repository": "git://github.com/litejs/natural-compare-lite" }, { - "lock": "package-lock.json", - "path": "node_modules/slice-ansi/node_modules/is-fullwidth-code-point", - "version": "4.0.0", + "ecosystem": "npm", + "name": "negotiator", + "version": "0.6.3", "license": "MIT", - "status": "approved" + "category": "approved", + "repository": "jshttp/negotiator" }, { - "lock": "package-lock.json", - "path": "node_modules/slow-redact", - "version": "0.3.2", + "ecosystem": "npm", + "name": "negotiator", + "version": "0.6.4", "license": "MIT", - "status": "approved" + "category": "approved", + "dev": true, + "repository": "jshttp/negotiator" }, { - "lock": "package-lock.json", - "path": "node_modules/smob", - "version": "1.6.2", + "ecosystem": "npm", + "name": "node-addon-api", + "version": "5.1.0", "license": "MIT", - "status": "approved" + "category": "approved", + "repository": "git://github.com/nodejs/node-addon-api" }, { - "lock": "package-lock.json", - "path": "node_modules/smol-toml", - "version": "1.6.1", - "license": "BSD-3-Clause", - "status": "approved" + "ecosystem": "npm", + "name": "node-fetch", + "version": "2.7.0", + "license": "MIT", + "category": "approved", + "repository": "https://github.com/bitinn/node-fetch" }, { - "lock": "package-lock.json", - "path": "node_modules/sonic-boom", - "version": "4.2.1", + "ecosystem": "npm", + "name": "node-fetch-native", + "version": "1.6.7", "license": "MIT", - "status": "approved" + "category": "approved", + "repository": "unjs/node-fetch-native" }, { - "lock": "package-lock.json", - "path": "node_modules/sort-asc", - "version": "0.2.0", + "ecosystem": "npm", + "name": "node-gyp-build", + "version": "4.8.4", "license": "MIT", - "status": "approved" + "category": "approved", + "repository": "https://github.com/prebuild/node-gyp-build" }, { - "lock": "package-lock.json", - "path": "node_modules/sort-desc", - "version": "0.2.0", + "ecosystem": "npm", + "name": "node-gyp-build-optional-packages", + "version": "5.2.2", "license": "MIT", - "status": "approved" + "category": "approved", + "repository": "https://github.com/prebuild/node-gyp-build" }, { - "lock": "package-lock.json", - "path": "node_modules/sort-object", - "version": "3.0.3", + "ecosystem": "npm", + "name": "node-mock-http", + "version": "1.0.4", "license": "MIT", - "status": "approved" + "category": "approved", + "repository": "unjs/node-mock-http" }, { - "lock": "package-lock.json", - "path": "node_modules/source-map", - "version": "0.8.0", - "license": "BSD-3-Clause", - "status": "approved" + "ecosystem": "npm", + "name": "node-releases", + "version": "2.0.54", + "license": "MIT", + "category": "approved", + "dev": true, + "repository": "https://github.com/chicoxyzzy/node-releases" }, { - "lock": "package-lock.json", - "path": "node_modules/source-map-js", - "version": "1.2.1", - "license": "BSD-3-Clause", - "status": "approved" + "ecosystem": "npm", + "name": "normalize-path", + "version": "3.0.0", + "license": "MIT", + "category": "approved", + "repository": "jonschlinkert/normalize-path" }, { - "lock": "package-lock.json", - "path": "node_modules/source-map-support", - "version": "0.5.21", + "ecosystem": "npm", + "name": "npm-run-path", + "version": "5.3.0", "license": "MIT", - "status": "approved" + "category": "approved", + "dev": true, + "repository": "sindresorhus/npm-run-path" }, { - "lock": "package-lock.json", - "path": "node_modules/source-map-support/node_modules/source-map", - "version": "0.6.1", - "license": "BSD-3-Clause", - "status": "approved" + "ecosystem": "npm", + "name": "object-assign", + "version": "4.1.1", + "license": "MIT", + "category": "approved", + "repository": "sindresorhus/object-assign" }, { - "lock": "package-lock.json", - "path": "node_modules/split-string", - "version": "3.1.0", + "ecosystem": "npm", + "name": "object-inspect", + "version": "1.13.4", "license": "MIT", - "status": "approved" + "category": "approved", + "repository": "git://github.com/inspect-js/object-inspect" }, { - "lock": "package-lock.json", - "path": "node_modules/split-string/node_modules/extend-shallow", - "version": "3.0.2", + "ecosystem": "npm", + "name": "object-keys", + "version": "1.1.1", "license": "MIT", - "status": "approved" + "category": "approved", + "dev": true, + "repository": "git://github.com/ljharb/object-keys" }, { - "lock": "package-lock.json", - "path": "node_modules/split-string/node_modules/is-extendable", - "version": "1.0.1", + "ecosystem": "npm", + "name": "object.assign", + "version": "4.1.7", "license": "MIT", - "status": "approved" + "category": "approved", + "dev": true, + "repository": "git://github.com/ljharb/object.assign" }, { - "lock": "package-lock.json", - "path": "node_modules/split2", - "version": "4.2.0", - "license": "ISC", - "status": "approved" + "ecosystem": "npm", + "name": "obug", + "version": "2.1.4", + "license": "MIT", + "category": "approved", + "dev": true, + "repository": "https://github.com/sxzz/obug" }, { - "lock": "package-lock.json", - "path": "node_modules/stackback", - "version": "0.0.2", + "ecosystem": "npm", + "name": "ofetch", + "version": "1.5.1", "license": "MIT", - "status": "approved" + "category": "approved", + "repository": "unjs/ofetch" }, { - "lock": "package-lock.json", - "path": "node_modules/statuses", - "version": "2.0.2", + "ecosystem": "npm", + "name": "on-exit-leak-free", + "version": "2.1.2", "license": "MIT", - "status": "approved" + "category": "approved", + "repository": "https://github.com/mcollina/on-exit-or-gc" }, { - "lock": "package-lock.json", - "path": "node_modules/std-env", - "version": "4.2.0", + "ecosystem": "npm", + "name": "on-finished", + "version": "2.4.1", "license": "MIT", - "status": "approved" + "category": "approved", + "repository": "jshttp/on-finished" }, { - "lock": "package-lock.json", - "path": "node_modules/stop-iteration-iterator", + "ecosystem": "npm", + "name": "on-headers", "version": "1.1.0", "license": "MIT", - "status": "approved" - }, - { - "lock": "package-lock.json", - "path": "node_modules/stream-chain", - "version": "2.2.5", - "license": "BSD-3-Clause", - "status": "approved" + "category": "approved", + "repository": "jshttp/on-headers" }, { - "lock": "package-lock.json", - "path": "node_modules/stream-json", - "version": "1.9.1", - "license": "BSD-3-Clause", - "status": "approved" + "ecosystem": "npm", + "name": "once", + "version": "1.4.0", + "license": "ISC", + "category": "approved", + "dev": true, + "repository": "git://github.com/isaacs/once" }, { - "lock": "package-lock.json", - "path": "node_modules/strict-event-emitter", - "version": "0.5.1", + "ecosystem": "npm", + "name": "onetime", + "version": "6.0.0", "license": "MIT", - "status": "approved" + "category": "approved", + "dev": true, + "repository": "sindresorhus/onetime" }, { - "lock": "package-lock.json", - "path": "node_modules/string-argv", - "version": "0.3.2", + "ecosystem": "npm", + "name": "onetime", + "version": "7.0.0", "license": "MIT", - "status": "approved" + "category": "approved", + "dev": true, + "repository": "sindresorhus/onetime" }, { - "lock": "package-lock.json", - "path": "node_modules/string-width", - "version": "4.2.3", + "ecosystem": "npm", + "name": "open", + "version": "8.4.2", "license": "MIT", - "status": "approved" + "category": "approved", + "dev": true, + "repository": "sindresorhus/open" }, { - "lock": "package-lock.json", - "path": "node_modules/string.prototype.matchall", - "version": "4.1.0", + "ecosystem": "npm", + "name": "optionator", + "version": "0.9.4", "license": "MIT", - "status": "approved" + "category": "approved", + "dev": true, + "repository": "git://github.com/gkz/optionator" }, { - "lock": "package-lock.json", - "path": "node_modules/string.prototype.trim", - "version": "1.2.11", + "ecosystem": "npm", + "name": "outvariant", + "version": "1.4.3", "license": "MIT", - "status": "approved" + "category": "approved", + "dev": true, + "repository": "https://github.com/open-draft/outvariant" }, { - "lock": "package-lock.json", - "path": "node_modules/string.prototype.trimend", - "version": "1.0.10", + "ecosystem": "npm", + "name": "own-keys", + "version": "1.0.2", "license": "MIT", - "status": "approved" + "category": "approved", + "dev": true, + "repository": "https://github.com/ljharb/own-keys" }, { - "lock": "package-lock.json", - "path": "node_modules/string.prototype.trimstart", - "version": "1.0.8", + "ecosystem": "npm", + "name": "ox", + "version": "0.14.29", "license": "MIT", - "status": "approved" - }, - { - "lock": "package-lock.json", - "path": "node_modules/stringify-object", - "version": "3.3.0", - "license": "BSD-2-Clause", - "status": "approved" + "category": "approved", + "repository": "wevm/ox" }, { - "lock": "package-lock.json", - "path": "node_modules/strip-ansi", - "version": "6.0.1", + "ecosystem": "npm", + "name": "ox", + "version": "0.6.9", "license": "MIT", - "status": "approved" + "category": "approved", + "repository": "wevm/ox" }, { - "lock": "package-lock.json", - "path": "node_modules/strip-comments", - "version": "2.0.1", + "ecosystem": "npm", + "name": "ox", + "version": "0.9.3", "license": "MIT", - "status": "approved" + "category": "approved", + "repository": "wevm/ox" }, { - "lock": "package-lock.json", - "path": "node_modules/strip-final-newline", - "version": "3.0.0", + "ecosystem": "npm", + "name": "p-limit", + "version": "2.3.0", "license": "MIT", - "status": "approved" + "category": "approved", + "repository": "sindresorhus/p-limit" }, { - "lock": "package-lock.json", - "path": "node_modules/strip-indent", - "version": "3.0.0", + "ecosystem": "npm", + "name": "p-limit", + "version": "3.1.0", "license": "MIT", - "status": "approved" + "category": "approved", + "dev": true, + "repository": "sindresorhus/p-limit" }, { - "lock": "package-lock.json", - "path": "node_modules/strip-json-comments", - "version": "3.1.1", + "ecosystem": "npm", + "name": "p-locate", + "version": "4.1.0", "license": "MIT", - "status": "approved" + "category": "approved", + "repository": "sindresorhus/p-locate" }, { - "lock": "package-lock.json", - "path": "node_modules/style-vendorizer", - "version": "2.2.3", + "ecosystem": "npm", + "name": "p-locate", + "version": "5.0.0", "license": "MIT", - "status": "approved" + "category": "approved", + "dev": true, + "repository": "sindresorhus/p-locate" }, { - "lock": "package-lock.json", - "path": "node_modules/superagent", - "version": "10.4.1", + "ecosystem": "npm", + "name": "p-try", + "version": "2.2.0", "license": "MIT", - "status": "approved" + "category": "approved", + "repository": "sindresorhus/p-try" }, { - "lock": "package-lock.json", - "path": "node_modules/superagent/node_modules/mime", - "version": "2.6.0", - "license": "MIT", - "status": "approved" + "ecosystem": "npm", + "name": "package-json-from-dist", + "version": "1.0.1", + "license": "BlueOak-1.0.0", + "category": "approved", + "dev": true, + "repository": "https://github.com/isaacs/package-json-from-dist" }, { - "lock": "package-lock.json", - "path": "node_modules/superstruct", - "version": "2.0.2", - "license": "MIT", - "status": "approved" + "ecosystem": "npm", + "name": "pako", + "version": "2.1.0", + "license": "(MIT AND Zlib)", + "category": "approved", + "repository": "nodeca/pako" }, { - "lock": "package-lock.json", - "path": "node_modules/supertest", - "version": "7.3.0", + "ecosystem": "npm", + "name": "parent-module", + "version": "1.0.1", "license": "MIT", - "status": "approved" + "category": "approved", + "dev": true, + "repository": "sindresorhus/parent-module" }, { - "lock": "package-lock.json", - "path": "node_modules/supertest/node_modules/cookie-signature", - "version": "1.2.2", + "ecosystem": "npm", + "name": "parse5", + "version": "8.0.1", "license": "MIT", - "status": "approved" + "category": "approved", + "dev": true, + "repository": "git://github.com/inikulin/parse5" }, { - "lock": "package-lock.json", - "path": "node_modules/supports-color", - "version": "7.2.0", + "ecosystem": "npm", + "name": "parseurl", + "version": "1.3.3", "license": "MIT", - "status": "approved" + "category": "approved", + "repository": "pillarjs/parseurl" }, { - "lock": "package-lock.json", - "path": "node_modules/supports-preserve-symlinks-flag", - "version": "1.0.0", + "ecosystem": "npm", + "name": "path-exists", + "version": "4.0.0", "license": "MIT", - "status": "approved" + "category": "approved", + "repository": "sindresorhus/path-exists" }, { - "lock": "package-lock.json", - "path": "node_modules/symbol-tree", - "version": "3.2.4", + "ecosystem": "npm", + "name": "path-key", + "version": "3.1.1", "license": "MIT", - "status": "approved" + "category": "approved", + "dev": true, + "repository": "sindresorhus/path-key" }, { - "lock": "package-lock.json", - "path": "node_modules/tagged-tag", - "version": "1.0.0", + "ecosystem": "npm", + "name": "path-key", + "version": "4.0.0", "license": "MIT", - "status": "approved" + "category": "approved", + "dev": true, + "repository": "sindresorhus/path-key" }, { - "lock": "package-lock.json", - "path": "node_modules/temp-dir", - "version": "2.0.0", + "ecosystem": "npm", + "name": "path-parse", + "version": "1.0.7", "license": "MIT", - "status": "approved" + "category": "approved", + "dev": true, + "repository": "https://github.com/jbgutierrez/path-parse" }, { - "lock": "package-lock.json", - "path": "node_modules/tempy", - "version": "0.6.0", - "license": "MIT", - "status": "approved" + "ecosystem": "npm", + "name": "path-scurry", + "version": "2.0.2", + "license": "BlueOak-1.0.0", + "category": "approved", + "dev": true, + "repository": "https://github.com/isaacs/path-scurry" }, { - "lock": "package-lock.json", - "path": "node_modules/tempy/node_modules/is-stream", - "version": "2.0.1", + "ecosystem": "npm", + "name": "path-to-regexp", + "version": "0.1.13", "license": "MIT", - "status": "approved" + "category": "approved", + "repository": "https://github.com/pillarjs/path-to-regexp" }, { - "lock": "package-lock.json", - "path": "node_modules/terser", - "version": "5.51.2", - "license": "BSD-2-Clause", - "status": "approved" + "ecosystem": "npm", + "name": "path-to-regexp", + "version": "6.3.0", + "license": "MIT", + "category": "approved", + "dev": true, + "repository": "https://github.com/pillarjs/path-to-regexp" }, { - "lock": "package-lock.json", - "path": "node_modules/terser/node_modules/commander", - "version": "2.20.3", + "ecosystem": "npm", + "name": "pathe", + "version": "2.0.3", "license": "MIT", - "status": "approved" + "category": "approved", + "dev": true, + "repository": "unjs/pathe" }, { - "lock": "package-lock.json", - "path": "node_modules/text-encoding-utf-8", - "version": "1.0.2", - "license": "UNKNOWN", - "status": "review" + "ecosystem": "npm", + "name": "picocolors", + "version": "1.1.1", + "license": "ISC", + "category": "approved", + "dev": true, + "repository": "alexeyraspopov/picocolors" }, { - "lock": "package-lock.json", - "path": "node_modules/thread-stream", - "version": "3.2.0", + "ecosystem": "npm", + "name": "picomatch", + "version": "2.3.2", "license": "MIT", - "status": "approved" + "category": "approved", + "repository": "micromatch/picomatch" }, { - "lock": "package-lock.json", - "path": "node_modules/tinybench", - "version": "2.9.0", + "ecosystem": "npm", + "name": "picomatch", + "version": "4.0.4", "license": "MIT", - "status": "approved" + "category": "approved", + "dev": true, + "repository": "micromatch/picomatch" }, { - "lock": "package-lock.json", - "path": "node_modules/tinyexec", - "version": "1.2.4", + "ecosystem": "npm", + "name": "pidtree", + "version": "0.6.1", "license": "MIT", - "status": "approved" + "category": "approved", + "dev": true, + "repository": "github:simonepri/pidtree" }, { - "lock": "package-lock.json", - "path": "node_modules/tinyglobby", - "version": "0.2.17", + "ecosystem": "npm", + "name": "pino", + "version": "10.0.0", "license": "MIT", - "status": "approved" + "category": "approved", + "repository": "https://github.com/pinojs/pino" }, { - "lock": "package-lock.json", - "path": "node_modules/tinyrainbow", - "version": "3.1.0", + "ecosystem": "npm", + "name": "pino", + "version": "9.14.0", "license": "MIT", - "status": "approved" + "category": "approved", + "repository": "https://github.com/pinojs/pino" }, { - "lock": "package-lock.json", - "path": "node_modules/tldts", - "version": "7.4.9", + "ecosystem": "npm", + "name": "pino-abstract-transport", + "version": "2.0.0", "license": "MIT", - "status": "approved" + "category": "approved", + "repository": "https://github.com/pinojs/pino-abstract-transport" }, { - "lock": "package-lock.json", - "path": "node_modules/tldts-core", - "version": "7.4.9", + "ecosystem": "npm", + "name": "pino-std-serializers", + "version": "7.1.0", "license": "MIT", - "status": "approved" + "category": "approved", + "repository": "ssh://git@github.com/pinojs/pino-std-serializers" }, { - "lock": "package-lock.json", - "path": "node_modules/to-regex-range", - "version": "5.0.1", - "license": "MIT", - "status": "approved" + "ecosystem": "npm", + "name": "playwright", + "version": "1.62.1", + "license": "Apache-2.0", + "category": "approved", + "dev": true, + "repository": "https://github.com/microsoft/playwright" }, { - "lock": "package-lock.json", - "path": "node_modules/tough-cookie", - "version": "6.0.2", - "license": "BSD-3-Clause", - "status": "approved" + "ecosystem": "npm", + "name": "playwright-core", + "version": "1.62.1", + "license": "Apache-2.0", + "category": "approved", + "dev": true, + "repository": "https://github.com/microsoft/playwright" }, { - "lock": "package-lock.json", - "path": "node_modules/tr46", - "version": "0.0.3", + "ecosystem": "npm", + "name": "pngjs", + "version": "5.0.0", "license": "MIT", - "status": "approved" + "category": "approved", + "repository": "git://github.com/lukeapage/pngjs" }, { - "lock": "package-lock.json", - "path": "node_modules/ts-mixer", - "version": "6.0.4", + "ecosystem": "npm", + "name": "possible-typed-array-names", + "version": "1.1.0", "license": "MIT", - "status": "approved" - }, - { - "lock": "package-lock.json", - "path": "node_modules/tslib", - "version": "2.8.1", - "license": "0BSD", - "status": "approved" + "category": "approved", + "dev": true, + "repository": "https://github.com/ljharb/possible-typed-array-names" }, { - "lock": "package-lock.json", - "path": "node_modules/tsx", - "version": "4.23.15", + "ecosystem": "npm", + "name": "postcss", + "version": "8.5.28", "license": "MIT", - "status": "approved" - }, - { - "lock": "package-lock.json", - "path": "node_modules/tweetnacl", - "version": "1.0.3", - "license": "Unlicense", - "status": "approved" + "category": "approved", + "dev": true, + "repository": "postcss/postcss" }, { - "lock": "package-lock.json", - "path": "node_modules/tweetnacl-util", - "version": "0.15.1", - "license": "Unlicense", - "status": "approved" + "ecosystem": "npm", + "name": "preact", + "version": "10.24.2", + "license": "MIT", + "category": "approved", + "repository": "preactjs/preact" }, { - "lock": "package-lock.json", - "path": "node_modules/type-check", - "version": "0.4.0", + "ecosystem": "npm", + "name": "preact", + "version": "10.29.3", "license": "MIT", - "status": "approved" + "category": "approved", + "repository": "preactjs/preact" }, { - "lock": "package-lock.json", - "path": "node_modules/type-fest", - "version": "0.16.0", - "license": "(MIT OR CC0-1.0)", - "status": "approved" + "ecosystem": "npm", + "name": "prelude-ls", + "version": "1.2.1", + "license": "MIT", + "category": "approved", + "dev": true, + "repository": "git://github.com/gkz/prelude-ls" }, { - "lock": "package-lock.json", - "path": "node_modules/type-is", - "version": "1.6.18", + "ecosystem": "npm", + "name": "prettier", + "version": "3.9.6", "license": "MIT", - "status": "approved" + "category": "approved", + "dev": true, + "repository": "prettier/prettier" }, { - "lock": "package-lock.json", - "path": "node_modules/typed-array-buffer", - "version": "1.0.3", + "ecosystem": "npm", + "name": "pretty-bytes", + "version": "5.6.0", "license": "MIT", - "status": "approved" + "category": "approved", + "dev": true, + "repository": "sindresorhus/pretty-bytes" }, { - "lock": "package-lock.json", - "path": "node_modules/typed-array-byte-length", - "version": "1.0.3", + "ecosystem": "npm", + "name": "pretty-bytes", + "version": "6.1.1", "license": "MIT", - "status": "approved" + "category": "approved", + "dev": true, + "repository": "sindresorhus/pretty-bytes" }, { - "lock": "package-lock.json", - "path": "node_modules/typed-array-byte-offset", - "version": "1.0.5", + "ecosystem": "npm", + "name": "pretty-format", + "version": "27.5.1", "license": "MIT", - "status": "approved" + "category": "approved", + "dev": true, + "repository": "https://github.com/facebook/jest" }, { - "lock": "package-lock.json", - "path": "node_modules/typed-array-length", - "version": "1.0.8", + "ecosystem": "npm", + "name": "pretty-format", + "version": "30.4.1", "license": "MIT", - "status": "approved" + "category": "approved", + "dev": true, + "repository": "https://github.com/jestjs/jest" }, { - "lock": "package-lock.json", - "path": "node_modules/typescript", - "version": "5.9.3", - "license": "Apache-2.0", - "status": "approved" + "ecosystem": "npm", + "name": "process-warning", + "version": "5.0.0", + "license": "MIT", + "category": "approved", + "repository": "https://github.com/fastify/process-warning" }, { - "lock": "package-lock.json", - "path": "node_modules/typewise", - "version": "1.0.3", + "ecosystem": "npm", + "name": "proxy-addr", + "version": "2.0.7", "license": "MIT", - "status": "approved" + "category": "approved", + "repository": "jshttp/proxy-addr" }, { - "lock": "package-lock.json", - "path": "node_modules/typewise-core", - "version": "1.2.0", + "ecosystem": "npm", + "name": "proxy-compare", + "version": "3.0.1", "license": "MIT", - "status": "approved" + "category": "approved", + "repository": "https://github.com/dai-shi/proxy-compare" }, { - "lock": "package-lock.json", - "path": "node_modules/ufo", - "version": "1.6.4", + "ecosystem": "npm", + "name": "proxy-from-env", + "version": "2.1.0", "license": "MIT", - "status": "approved" + "category": "approved", + "repository": "https://github.com/Rob--W/proxy-from-env" }, { - "lock": "package-lock.json", - "path": "node_modules/uint8array-extras", - "version": "1.5.0", + "ecosystem": "npm", + "name": "punycode", + "version": "2.3.1", "license": "MIT", - "status": "approved" + "category": "approved", + "dev": true, + "repository": "https://github.com/mathiasbynens/punycode.js" }, { - "lock": "package-lock.json", - "path": "node_modules/uint8arrays", - "version": "3.1.1", + "ecosystem": "npm", + "name": "qrcode", + "version": "1.5.3", "license": "MIT", - "status": "approved" + "category": "approved", + "repository": "git://github.com/soldair/node-qrcode" }, { - "lock": "package-lock.json", - "path": "node_modules/unbox-primitive", - "version": "1.1.0", - "license": "MIT", - "status": "approved" + "ecosystem": "npm", + "name": "qs", + "version": "6.16.0", + "license": "BSD-3-Clause", + "category": "approved", + "repository": "https://github.com/ljharb/qs" }, { - "lock": "package-lock.json", - "path": "node_modules/uncrypto", - "version": "0.1.3", + "ecosystem": "npm", + "name": "quick-format-unescaped", + "version": "4.0.4", "license": "MIT", - "status": "approved" + "category": "approved", + "repository": "https://github.com/davidmarkclements/quick-format" }, { - "lock": "package-lock.json", - "path": "node_modules/undici", - "version": "7.29.0", + "ecosystem": "npm", + "name": "radix3", + "version": "1.1.2", "license": "MIT", - "status": "approved" + "category": "approved", + "repository": "unjs/radix3" }, { - "lock": "package-lock.json", - "path": "node_modules/undici-types", - "version": "7.28.0", + "ecosystem": "npm", + "name": "randombytes", + "version": "2.1.0", "license": "MIT", - "status": "approved" + "category": "approved", + "repository": "git@github.com:crypto-browserify/randombytes" }, { - "lock": "package-lock.json", - "path": "node_modules/unicode-canonical-property-names-ecmascript", - "version": "2.0.1", + "ecosystem": "npm", + "name": "range-parser", + "version": "1.2.1", "license": "MIT", - "status": "approved" + "category": "approved", + "repository": "jshttp/range-parser" }, { - "lock": "package-lock.json", - "path": "node_modules/unicode-match-property-ecmascript", - "version": "2.0.0", + "ecosystem": "npm", + "name": "raw-body", + "version": "2.5.3", "license": "MIT", - "status": "approved" + "category": "approved", + "repository": "stream-utils/raw-body" }, { - "lock": "package-lock.json", - "path": "node_modules/unicode-match-property-value-ecmascript", - "version": "2.2.1", + "ecosystem": "npm", + "name": "react", + "version": "19.2.7", "license": "MIT", - "status": "approved" + "category": "approved", + "repository": "https://github.com/facebook/react" }, { - "lock": "package-lock.json", - "path": "node_modules/unicode-property-aliases-ecmascript", - "version": "2.2.0", + "ecosystem": "npm", + "name": "react-dom", + "version": "19.2.7", "license": "MIT", - "status": "approved" + "category": "approved", + "repository": "https://github.com/facebook/react" }, { - "lock": "package-lock.json", - "path": "node_modules/union-value", - "version": "1.0.1", + "ecosystem": "npm", + "name": "react-i18next", + "version": "15.7.4", "license": "MIT", - "status": "approved" + "category": "approved", + "repository": "https://github.com/i18next/react-i18next" }, { - "lock": "package-lock.json", - "path": "node_modules/unique-string", - "version": "2.0.0", + "ecosystem": "npm", + "name": "react-is", + "version": "17.0.2", "license": "MIT", - "status": "approved" + "category": "approved", + "dev": true, + "repository": "https://github.com/facebook/react" }, { - "lock": "package-lock.json", - "path": "node_modules/universalify", - "version": "2.0.1", + "ecosystem": "npm", + "name": "react-is-18", + "version": "18.3.1", "license": "MIT", - "status": "approved" + "category": "approved", + "dev": true, + "repository": "https://github.com/facebook/react" }, { - "lock": "package-lock.json", - "path": "node_modules/unpipe", - "version": "1.0.0", + "ecosystem": "npm", + "name": "react-is-19", + "version": "19.2.8", "license": "MIT", - "status": "approved" + "category": "approved", + "dev": true, + "repository": "https://github.com/react/react" }, { - "lock": "package-lock.json", - "path": "node_modules/unstorage", - "version": "1.17.5", + "ecosystem": "npm", + "name": "react-map-gl", + "version": "8.1.1", "license": "MIT", - "status": "approved" + "category": "approved", + "repository": "https://github.com/visgl/react-map-gl" }, { - "lock": "package-lock.json", - "path": "node_modules/until-async", - "version": "3.0.2", + "ecosystem": "npm", + "name": "react-router", + "version": "7.18.4", "license": "MIT", - "status": "approved" + "category": "approved", + "repository": "https://github.com/remix-run/react-router" }, { - "lock": "package-lock.json", - "path": "node_modules/upath", - "version": "1.2.0", + "ecosystem": "npm", + "name": "react-router-dom", + "version": "7.18.0", "license": "MIT", - "status": "approved" + "category": "approved", + "repository": "https://github.com/remix-run/react-router" }, { - "lock": "package-lock.json", - "path": "node_modules/update-browserslist-db", - "version": "1.3.3", + "ecosystem": "npm", + "name": "readdirp", + "version": "5.0.0", "license": "MIT", - "status": "approved" + "category": "approved", + "repository": "https://github.com/paulmillr/readdirp" }, { - "lock": "package-lock.json", - "path": "node_modules/uri-js", - "version": "4.4.1", - "license": "BSD-2-Clause", - "status": "approved" + "ecosystem": "npm", + "name": "real-require", + "version": "0.2.0", + "license": "MIT", + "category": "approved", + "repository": "https://github.com/pinojs/real-require" }, { - "lock": "package-lock.json", - "path": "node_modules/utf-8-validate", - "version": "6.0.6", + "ecosystem": "npm", + "name": "redent", + "version": "3.0.0", "license": "MIT", - "status": "approved" + "category": "approved", + "dev": true, + "repository": "sindresorhus/redent" }, { - "lock": "package-lock.json", - "path": "node_modules/utils-merge", - "version": "1.0.1", + "ecosystem": "npm", + "name": "reflect.getprototypeof", + "version": "1.0.10", "license": "MIT", - "status": "approved" + "category": "approved", + "dev": true, + "repository": "https://github.com/es-shims/Reflect.getPrototypeOf" }, { - "lock": "package-lock.json", - "path": "node_modules/uuid", - "version": "8.3.2", + "ecosystem": "npm", + "name": "regenerate", + "version": "1.4.2", "license": "MIT", - "status": "approved" + "category": "approved", + "dev": true, + "repository": "https://github.com/mathiasbynens/regenerate" }, { - "lock": "package-lock.json", - "path": "node_modules/uuid4", - "version": "2.0.3", - "license": "ISC", - "status": "approved" + "ecosystem": "npm", + "name": "regenerate-unicode-properties", + "version": "10.2.2", + "license": "MIT", + "category": "approved", + "dev": true, + "repository": "https://github.com/mathiasbynens/regenerate-unicode-properties" }, { - "lock": "package-lock.json", - "path": "node_modules/valtio", - "version": "2.1.7", + "ecosystem": "npm", + "name": "regexp.prototype.flags", + "version": "1.5.4", "license": "MIT", - "status": "approved" + "category": "approved", + "dev": true, + "repository": "git://github.com/es-shims/RegExp.prototype.flags" }, { - "lock": "package-lock.json", - "path": "node_modules/vary", - "version": "1.1.2", + "ecosystem": "npm", + "name": "regexpu-core", + "version": "6.4.0", "license": "MIT", - "status": "approved" + "category": "approved", + "dev": true, + "repository": "https://github.com/mathiasbynens/regexpu-core" }, { - "lock": "package-lock.json", - "path": "node_modules/viem", - "version": "2.53.1", + "ecosystem": "npm", + "name": "regjsgen", + "version": "0.8.0", "license": "MIT", - "status": "approved" + "category": "approved", + "dev": true, + "repository": "https://github.com/bnjmnt4n/regjsgen" }, { - "lock": "package-lock.json", - "path": "node_modules/viem/node_modules/@noble/curves", - "version": "1.9.1", - "license": "MIT", - "status": "approved" + "ecosystem": "npm", + "name": "regjsparser", + "version": "0.13.2", + "license": "BSD-2-Clause", + "category": "approved", + "dev": true, + "repository": "ssh://git@github.com/jviereck/regjsparser" }, { - "lock": "package-lock.json", - "path": "node_modules/viem/node_modules/@noble/hashes", - "version": "1.8.0", + "ecosystem": "npm", + "name": "require-directory", + "version": "2.1.1", "license": "MIT", - "status": "approved" + "category": "approved", + "repository": "git://github.com/troygoode/node-require-directory" }, { - "lock": "package-lock.json", - "path": "node_modules/viem/node_modules/abitype", - "version": "1.2.3", + "ecosystem": "npm", + "name": "require-from-string", + "version": "2.0.2", "license": "MIT", - "status": "approved" + "category": "approved", + "dev": true, + "repository": "floatdrop/require-from-string" }, { - "lock": "package-lock.json", - "path": "node_modules/viem/node_modules/ox", - "version": "0.14.29", - "license": "MIT", - "status": "approved" + "ecosystem": "npm", + "name": "require-main-filename", + "version": "2.0.0", + "license": "ISC", + "category": "approved", + "repository": "ssh://git@github.com/yargs/require-main-filename" }, { - "lock": "package-lock.json", - "path": "node_modules/viem/node_modules/ws", - "version": "8.20.1", + "ecosystem": "npm", + "name": "resolve", + "version": "1.22.12", "license": "MIT", - "status": "approved" + "category": "approved", + "dev": true, + "repository": "ssh://github.com/browserify/resolve" }, { - "lock": "package-lock.json", - "path": "node_modules/vite", - "version": "8.0.16", + "ecosystem": "npm", + "name": "resolve-from", + "version": "4.0.0", "license": "MIT", - "status": "approved" + "category": "approved", + "dev": true, + "repository": "sindresorhus/resolve-from" }, { - "lock": "package-lock.json", - "path": "node_modules/vite-plugin-pwa", - "version": "1.3.0", + "ecosystem": "npm", + "name": "restore-cursor", + "version": "5.1.0", "license": "MIT", - "status": "approved" + "category": "approved", + "dev": true, + "repository": "sindresorhus/restore-cursor" }, { - "lock": "package-lock.json", - "path": "node_modules/vitest", - "version": "4.1.10", + "ecosystem": "npm", + "name": "rettime", + "version": "0.11.11", "license": "MIT", - "status": "approved" + "category": "approved", + "dev": true, + "repository": "https://github.com/kettanaito/rettime" }, { - "lock": "package-lock.json", - "path": "node_modules/w3c-xmlserializer", - "version": "5.0.0", + "ecosystem": "npm", + "name": "rfdc", + "version": "1.4.1", "license": "MIT", - "status": "approved" - }, - { - "lock": "package-lock.json", - "path": "node_modules/webidl-conversions", - "version": "3.0.1", - "license": "BSD-2-Clause", - "status": "approved" + "category": "approved", + "dev": true, + "repository": "https://github.com/davidmarkclements/rfdc" }, { - "lock": "package-lock.json", - "path": "node_modules/whatwg-mimetype", - "version": "5.0.0", + "ecosystem": "npm", + "name": "rolldown", + "version": "1.0.3", "license": "MIT", - "status": "approved" + "category": "approved", + "dev": true, + "repository": "https://github.com/rolldown/rolldown" }, { - "lock": "package-lock.json", - "path": "node_modules/whatwg-url", - "version": "5.0.0", + "ecosystem": "npm", + "name": "rollup", + "version": "4.63.0", "license": "MIT", - "status": "approved" + "category": "approved", + "dev": true, + "repository": "https://github.com/rollup/rollup" }, { - "lock": "package-lock.json", - "path": "node_modules/which", - "version": "2.0.2", - "license": "ISC", - "status": "approved" + "ecosystem": "npm", + "name": "rollup-plugin-visualizer", + "version": "5.14.0", + "license": "MIT", + "category": "approved", + "dev": true, + "repository": "git@github.com:btd/rollup-plugin-visualizer" }, { - "lock": "package-lock.json", - "path": "node_modules/which-boxed-primitive", - "version": "1.1.1", - "license": "MIT", - "status": "approved" + "ecosystem": "npm", + "name": "rpc-websockets", + "version": "9.3.9", + "license": "LGPL-3.0-only", + "category": "review", + "repository": "https://github.com/elpheria/rpc-websockets" }, { - "lock": "package-lock.json", - "path": "node_modules/which-builtin-type", - "version": "1.2.1", - "license": "MIT", - "status": "approved" + "ecosystem": "npm", + "name": "rw", + "version": "1.3.3", + "license": "BSD-3-Clause", + "category": "approved", + "repository": "http://github.com/mbostock/rw" }, { - "lock": "package-lock.json", - "path": "node_modules/which-collection", - "version": "1.0.2", - "license": "MIT", - "status": "approved" + "ecosystem": "npm", + "name": "rxjs", + "version": "7.8.1", + "license": "Apache-2.0", + "category": "approved", + "repository": "https://github.com/reactivex/rxjs" }, { - "lock": "package-lock.json", - "path": "node_modules/which-module", - "version": "2.0.1", - "license": "ISC", - "status": "approved" + "ecosystem": "npm", + "name": "rxjs", + "version": "7.8.2", + "license": "Apache-2.0", + "category": "approved", + "repository": "https://github.com/reactivex/rxjs" }, { - "lock": "package-lock.json", - "path": "node_modules/which-typed-array", - "version": "1.1.24", + "ecosystem": "npm", + "name": "safe-array-concat", + "version": "1.1.4", "license": "MIT", - "status": "approved" + "category": "approved", + "dev": true, + "repository": "https://github.com/ljharb/safe-array-concat" }, { - "lock": "package-lock.json", - "path": "node_modules/why-is-node-running", - "version": "2.3.0", + "ecosystem": "npm", + "name": "safe-buffer", + "version": "5.1.2", "license": "MIT", - "status": "approved" + "category": "approved", + "repository": "git://github.com/feross/safe-buffer" }, { - "lock": "package-lock.json", - "path": "node_modules/word-wrap", - "version": "1.2.5", + "ecosystem": "npm", + "name": "safe-buffer", + "version": "5.2.1", "license": "MIT", - "status": "approved" + "category": "approved", + "repository": "git://github.com/feross/safe-buffer" }, { - "lock": "package-lock.json", - "path": "node_modules/workbox-background-sync", - "version": "7.4.1", + "ecosystem": "npm", + "name": "safe-push-apply", + "version": "1.0.0", "license": "MIT", - "status": "approved" + "category": "approved", + "dev": true, + "repository": "https://github.com/ljharb/safe-push-apply" }, { - "lock": "package-lock.json", - "path": "node_modules/workbox-broadcast-update", - "version": "7.4.1", + "ecosystem": "npm", + "name": "safe-regex-test", + "version": "1.1.0", "license": "MIT", - "status": "approved" + "category": "approved", + "dev": true, + "repository": "https://github.com/ljharb/safe-regex-test" }, { - "lock": "package-lock.json", - "path": "node_modules/workbox-build", - "version": "7.4.1", + "ecosystem": "npm", + "name": "safe-stable-stringify", + "version": "2.5.0", "license": "MIT", - "status": "approved" + "category": "approved", + "repository": "https://github.com/BridgeAR/safe-stable-stringify" }, { - "lock": "package-lock.json", - "path": "node_modules/workbox-build/node_modules/ajv", - "version": "8.20.0", + "ecosystem": "npm", + "name": "safer-buffer", + "version": "2.1.2", "license": "MIT", - "status": "approved" + "category": "approved", + "repository": "https://github.com/ChALkeR/safer-buffer" }, { - "lock": "package-lock.json", - "path": "node_modules/workbox-build/node_modules/json-schema-traverse", - "version": "1.0.0", - "license": "MIT", - "status": "approved" + "ecosystem": "npm", + "name": "saxes", + "version": "6.0.0", + "license": "ISC", + "category": "approved", + "dev": true, + "repository": "https://github.com/lddubeau/saxes" }, { - "lock": "package-lock.json", - "path": "node_modules/workbox-build/node_modules/pretty-bytes", - "version": "5.6.0", + "ecosystem": "npm", + "name": "scheduler", + "version": "0.27.0", "license": "MIT", - "status": "approved" + "category": "approved", + "repository": "https://github.com/facebook/react" }, { - "lock": "package-lock.json", - "path": "node_modules/workbox-cacheable-response", - "version": "7.4.1", + "ecosystem": "npm", + "name": "secp256k1", + "version": "5.0.1", "license": "MIT", - "status": "approved" + "category": "approved", + "repository": "https://github.com/cryptocoinjs/secp256k1-node" }, { - "lock": "package-lock.json", - "path": "node_modules/workbox-core", - "version": "7.4.1", - "license": "MIT", - "status": "approved" + "ecosystem": "npm", + "name": "semver", + "version": "6.3.1", + "license": "ISC", + "category": "approved", + "dev": true, + "repository": "https://github.com/npm/node-semver" }, { - "lock": "package-lock.json", - "path": "node_modules/workbox-expiration", - "version": "7.4.1", - "license": "MIT", - "status": "approved" + "ecosystem": "npm", + "name": "semver", + "version": "7.7.1", + "license": "ISC", + "category": "approved", + "repository": "https://github.com/npm/node-semver" }, { - "lock": "package-lock.json", - "path": "node_modules/workbox-google-analytics", - "version": "7.4.1", - "license": "MIT", - "status": "approved" + "ecosystem": "npm", + "name": "semver", + "version": "7.7.2", + "license": "ISC", + "category": "approved", + "repository": "https://github.com/npm/node-semver" }, { - "lock": "package-lock.json", - "path": "node_modules/workbox-navigation-preload", - "version": "7.4.1", + "ecosystem": "npm", + "name": "send", + "version": "0.19.2", "license": "MIT", - "status": "approved" + "category": "approved", + "repository": "pillarjs/send" }, { - "lock": "package-lock.json", - "path": "node_modules/workbox-precaching", - "version": "7.4.1", - "license": "MIT", - "status": "approved" + "ecosystem": "npm", + "name": "serialize-javascript", + "version": "7.1.0", + "license": "BSD-3-Clause", + "category": "approved", + "dev": true, + "repository": "https://github.com/yahoo/serialize-javascript" }, { - "lock": "package-lock.json", - "path": "node_modules/workbox-range-requests", - "version": "7.4.1", + "ecosystem": "npm", + "name": "serve-static", + "version": "1.16.3", "license": "MIT", - "status": "approved" + "category": "approved", + "repository": "expressjs/serve-static" }, { - "lock": "package-lock.json", - "path": "node_modules/workbox-recipes", - "version": "7.4.1", - "license": "MIT", - "status": "approved" + "ecosystem": "npm", + "name": "set-blocking", + "version": "2.0.0", + "license": "ISC", + "category": "approved", + "repository": "https://github.com/yargs/set-blocking" }, { - "lock": "package-lock.json", - "path": "node_modules/workbox-routing", - "version": "7.4.1", + "ecosystem": "npm", + "name": "set-cookie-parser", + "version": "2.7.2", "license": "MIT", - "status": "approved" + "category": "approved", + "repository": "nfriedly/set-cookie-parser" }, { - "lock": "package-lock.json", - "path": "node_modules/workbox-strategies", - "version": "7.4.1", + "ecosystem": "npm", + "name": "set-cookie-parser", + "version": "3.1.2", "license": "MIT", - "status": "approved" + "category": "approved", + "dev": true, + "repository": "nfriedly/set-cookie-parser" }, { - "lock": "package-lock.json", - "path": "node_modules/workbox-streams", - "version": "7.4.1", + "ecosystem": "npm", + "name": "set-function-length", + "version": "1.2.2", "license": "MIT", - "status": "approved" + "category": "approved", + "dev": true, + "repository": "https://github.com/ljharb/set-function-length" }, { - "lock": "package-lock.json", - "path": "node_modules/workbox-sw", - "version": "7.4.1", + "ecosystem": "npm", + "name": "set-function-name", + "version": "2.0.2", "license": "MIT", - "status": "approved" + "category": "approved", + "dev": true, + "repository": "https://github.com/ljharb/set-function-name" }, { - "lock": "package-lock.json", - "path": "node_modules/workbox-window", - "version": "7.4.1", + "ecosystem": "npm", + "name": "set-proto", + "version": "1.0.0", "license": "MIT", - "status": "approved" + "category": "approved", + "dev": true, + "repository": "https://github.com/ljharb/set-proto" }, { - "lock": "package-lock.json", - "path": "node_modules/wrap-ansi", - "version": "6.2.0", + "ecosystem": "npm", + "name": "set-value", + "version": "2.0.1", "license": "MIT", - "status": "approved" + "category": "approved", + "repository": "jonschlinkert/set-value" }, { - "lock": "package-lock.json", - "path": "node_modules/wrappy", - "version": "1.0.2", + "ecosystem": "npm", + "name": "setprototypeof", + "version": "1.2.0", "license": "ISC", - "status": "approved" + "category": "approved", + "repository": "https://github.com/wesleytodd/setprototypeof" }, { - "lock": "package-lock.json", - "path": "node_modules/ws", - "version": "8.21.0", - "license": "MIT", - "status": "approved" + "ecosystem": "npm", + "name": "sha1", + "version": "1.1.1", + "license": "BSD-3-Clause", + "category": "approved", + "repository": "git://github.com/pvorb/node-sha1" }, { - "lock": "package-lock.json", - "path": "node_modules/wsl-utils", - "version": "1.0.0", + "ecosystem": "npm", + "name": "shebang-command", + "version": "2.0.0", "license": "MIT", - "status": "approved" + "category": "approved", + "dev": true, + "repository": "kevva/shebang-command" }, { - "lock": "package-lock.json", - "path": "node_modules/wsl-utils/node_modules/powershell-utils", - "version": "0.1.0", + "ecosystem": "npm", + "name": "shebang-regex", + "version": "3.0.0", "license": "MIT", - "status": "approved" + "category": "approved", + "dev": true, + "repository": "sindresorhus/shebang-regex" }, { - "lock": "package-lock.json", - "path": "node_modules/xml-name-validator", - "version": "5.0.0", - "license": "Apache-2.0", - "status": "approved" + "ecosystem": "npm", + "name": "side-channel", + "version": "1.1.1", + "license": "MIT", + "category": "approved", + "repository": "https://github.com/ljharb/side-channel" }, { - "lock": "package-lock.json", - "path": "node_modules/xmlchars", - "version": "2.2.0", + "ecosystem": "npm", + "name": "side-channel-list", + "version": "1.0.1", "license": "MIT", - "status": "approved" + "category": "approved", + "repository": "https://github.com/ljharb/side-channel-list" }, { - "lock": "package-lock.json", - "path": "node_modules/xtend", - "version": "4.0.2", + "ecosystem": "npm", + "name": "side-channel-map", + "version": "1.0.1", "license": "MIT", - "status": "approved" + "category": "approved", + "repository": "https://github.com/ljharb/side-channel-map" }, { - "lock": "package-lock.json", - "path": "node_modules/y18n", - "version": "4.0.3", - "license": "ISC", - "status": "approved" + "ecosystem": "npm", + "name": "side-channel-weakmap", + "version": "1.0.2", + "license": "MIT", + "category": "approved", + "repository": "https://github.com/ljharb/side-channel-weakmap" }, { - "lock": "package-lock.json", - "path": "node_modules/yallist", - "version": "3.1.1", + "ecosystem": "npm", + "name": "siginfo", + "version": "2.0.0", "license": "ISC", - "status": "approved" + "category": "approved", + "dev": true, + "repository": "https://github.com/emilbayes/siginfo" }, { - "lock": "package-lock.json", - "path": "node_modules/yaml", - "version": "2.9.1", + "ecosystem": "npm", + "name": "signal-exit", + "version": "4.1.0", "license": "ISC", - "status": "approved" + "category": "approved", + "dev": true, + "repository": "https://github.com/tapjs/signal-exit" }, { - "lock": "package-lock.json", - "path": "node_modules/yargs", - "version": "15.4.1", + "ecosystem": "npm", + "name": "slice-ansi", + "version": "5.0.0", "license": "MIT", - "status": "approved" + "category": "approved", + "dev": true, + "repository": "chalk/slice-ansi" }, { - "lock": "package-lock.json", - "path": "node_modules/yargs-parser", - "version": "18.1.3", - "license": "ISC", - "status": "approved" + "ecosystem": "npm", + "name": "slice-ansi", + "version": "7.1.2", + "license": "MIT", + "category": "approved", + "dev": true, + "repository": "chalk/slice-ansi" }, { - "lock": "package-lock.json", - "path": "node_modules/yocto-queue", - "version": "0.1.0", + "ecosystem": "npm", + "name": "slow-redact", + "version": "0.3.2", "license": "MIT", - "status": "approved" + "category": "approved", + "repository": "https://github.com/pinojs/slow-redact" }, { - "lock": "package-lock.json", - "path": "node_modules/zod", - "version": "3.25.76", + "ecosystem": "npm", + "name": "smob", + "version": "1.6.2", "license": "MIT", - "status": "approved" + "category": "approved", + "dev": true, + "repository": "https://github.com/Tada5hi/smob" }, { - "lock": "package-lock.json", - "path": "node_modules/zustand", - "version": "5.0.3", - "license": "MIT", - "status": "approved" + "ecosystem": "npm", + "name": "smol-toml", + "version": "1.9.0", + "license": "BSD-3-Clause", + "category": "approved", + "repository": "github:squirrelchat/smol-toml" }, { - "lock": "server/package-lock.json", - "path": "node_modules/@aztec/bb.js", - "version": "0.87.9", + "ecosystem": "npm", + "name": "sonic-boom", + "version": "4.2.1", "license": "MIT", - "status": "approved" + "category": "approved", + "repository": "https://github.com/pinojs/sonic-boom" }, { - "lock": "server/package-lock.json", - "path": "node_modules/@msgpackr-extract/msgpackr-extract-darwin-arm64", - "version": "3.0.4", + "ecosystem": "npm", + "name": "sort-asc", + "version": "0.2.0", "license": "MIT", - "status": "approved" + "category": "approved", + "repository": "jonschlinkert/sort-asc" }, { - "lock": "server/package-lock.json", - "path": "node_modules/@msgpackr-extract/msgpackr-extract-darwin-x64", - "version": "3.0.4", + "ecosystem": "npm", + "name": "sort-desc", + "version": "0.2.0", "license": "MIT", - "status": "approved" + "category": "approved", + "repository": "jonschlinkert/sort-desc" }, { - "lock": "server/package-lock.json", - "path": "node_modules/@msgpackr-extract/msgpackr-extract-linux-arm", - "version": "3.0.4", + "ecosystem": "npm", + "name": "sort-object", + "version": "3.0.3", "license": "MIT", - "status": "approved" + "category": "approved", + "repository": "doowb/sort-object" }, { - "lock": "server/package-lock.json", - "path": "node_modules/@msgpackr-extract/msgpackr-extract-linux-arm64", - "version": "3.0.4", - "license": "MIT", - "status": "approved" + "ecosystem": "npm", + "name": "source-map", + "version": "0.6.1", + "license": "BSD-3-Clause", + "category": "approved", + "dev": true, + "repository": "http://github.com/mozilla/source-map" }, { - "lock": "server/package-lock.json", - "path": "node_modules/@msgpackr-extract/msgpackr-extract-linux-x64", - "version": "3.0.4", - "license": "MIT", - "status": "approved" + "ecosystem": "npm", + "name": "source-map", + "version": "0.7.6", + "license": "BSD-3-Clause", + "category": "approved", + "dev": true, + "repository": "http://github.com/mozilla/source-map" }, { - "lock": "server/package-lock.json", - "path": "node_modules/@msgpackr-extract/msgpackr-extract-win32-x64", - "version": "3.0.4", + "ecosystem": "npm", + "name": "source-map", + "version": "0.8.0", + "license": "BSD-3-Clause", + "category": "approved", + "dev": true, + "repository": "ssh://git@github.com/mozilla/source-map" + }, + { + "ecosystem": "npm", + "name": "source-map-js", + "version": "1.2.1", + "license": "BSD-3-Clause", + "category": "approved", + "dev": true, + "repository": "7rulnik/source-map-js" + }, + { + "ecosystem": "npm", + "name": "source-map-support", + "version": "0.5.21", "license": "MIT", - "status": "approved" + "category": "approved", + "dev": true, + "repository": "https://github.com/evanw/node-source-map-support" }, { - "lock": "server/package-lock.json", - "path": "node_modules/@noble/ed25519", + "ecosystem": "npm", + "name": "split-string", "version": "3.1.0", "license": "MIT", - "status": "approved" + "category": "approved", + "repository": "jonschlinkert/split-string" }, { - "lock": "server/package-lock.json", - "path": "node_modules/@noble/hashes", - "version": "2.3.0", + "ecosystem": "npm", + "name": "split2", + "version": "4.2.0", + "license": "ISC", + "category": "approved", + "repository": "https://github.com/mcollina/split2" + }, + { + "ecosystem": "npm", + "name": "stackback", + "version": "0.0.2", "license": "MIT", - "status": "approved" + "category": "approved", + "dev": true, + "repository": "git://github.com/shtylman/node-stackback" }, { - "lock": "server/package-lock.json", - "path": "node_modules/@noir-lang/acvm_js", - "version": "1.0.0-beta.26", + "ecosystem": "npm", + "name": "statuses", + "version": "2.0.2", "license": "MIT", - "status": "approved" + "category": "approved", + "repository": "jshttp/statuses" }, { - "lock": "server/package-lock.json", - "path": "node_modules/@noir-lang/noir_js", - "version": "1.0.0-beta.26", - "license": "(MIT OR Apache-2.0)", - "status": "approved" + "ecosystem": "npm", + "name": "std-env", + "version": "4.2.0", + "license": "MIT", + "category": "approved", + "dev": true, + "repository": "unjs/std-env" }, { - "lock": "server/package-lock.json", - "path": "node_modules/@noir-lang/noir_js/node_modules/pako", - "version": "3.0.1", - "license": "(MIT AND Zlib)", - "status": "review" + "ecosystem": "npm", + "name": "stop-iteration-iterator", + "version": "1.1.0", + "license": "MIT", + "category": "approved", + "dev": true, + "repository": "https://github.com/ljharb/stop-iteration-iterator" }, { - "lock": "server/package-lock.json", - "path": "node_modules/@noir-lang/noirc_abi", - "version": "1.0.0-beta.26", - "license": "(MIT OR Apache-2.0)", - "status": "approved" + "ecosystem": "npm", + "name": "stream-chain", + "version": "2.2.5", + "license": "BSD-3-Clause", + "category": "approved", + "repository": "https://github.com/uhop/stream-chain" }, { - "lock": "server/package-lock.json", - "path": "node_modules/@noir-lang/types", - "version": "1.0.0-beta.26", - "license": "(MIT OR Apache-2.0)", - "status": "approved" + "ecosystem": "npm", + "name": "stream-json", + "version": "1.9.1", + "license": "BSD-3-Clause", + "category": "approved", + "repository": "git://github.com/uhop/stream-json" }, { - "lock": "server/package-lock.json", - "path": "node_modules/@paralleldrive/cuid2", - "version": "2.3.1", + "ecosystem": "npm", + "name": "strict-event-emitter", + "version": "0.5.1", "license": "MIT", - "status": "approved" + "category": "approved", + "dev": true, + "repository": "git@github.com:open-draft/strict-event-emitter" }, { - "lock": "server/package-lock.json", - "path": "node_modules/@paralleldrive/cuid2/node_modules/@noble/hashes", - "version": "1.8.0", + "ecosystem": "npm", + "name": "string-argv", + "version": "0.3.2", "license": "MIT", - "status": "approved" + "category": "approved", + "dev": true, + "repository": "https://github.com/mccormicka/string-argv" }, { - "lock": "server/package-lock.json", - "path": "node_modules/@pinojs/redact", - "version": "0.4.0", + "ecosystem": "npm", + "name": "string-width", + "version": "4.2.3", "license": "MIT", - "status": "approved" + "category": "approved", + "repository": "sindresorhus/string-width" }, { - "lock": "server/package-lock.json", - "path": "node_modules/@stellar/js-xdr", - "version": "4.0.0", - "license": "Apache-2.0", - "status": "approved" + "ecosystem": "npm", + "name": "string-width", + "version": "7.2.0", + "license": "MIT", + "category": "approved", + "dev": true, + "repository": "sindresorhus/string-width" }, { - "lock": "server/package-lock.json", - "path": "node_modules/@stellar/stellar-sdk", - "version": "16.2.0", - "license": "Apache-2.0", - "status": "approved" + "ecosystem": "npm", + "name": "string.prototype.matchall", + "version": "4.0.12", + "license": "MIT", + "category": "approved", + "dev": true, + "repository": "https://github.com/es-shims/String.prototype.matchAll" }, { - "lock": "server/package-lock.json", - "path": "node_modules/@stellar/stellar-sdk/node_modules/commander", - "version": "14.0.3", + "ecosystem": "npm", + "name": "string.prototype.trim", + "version": "1.2.11", "license": "MIT", - "status": "approved" + "category": "approved", + "dev": true, + "repository": "git://github.com/es-shims/String.prototype.trim" }, { - "lock": "server/package-lock.json", - "path": "node_modules/accepts", - "version": "1.3.8", + "ecosystem": "npm", + "name": "string.prototype.trimend", + "version": "1.0.10", "license": "MIT", - "status": "approved" + "category": "approved", + "dev": true, + "repository": "git://github.com/es-shims/String.prototype.trimEnd" }, { - "lock": "server/package-lock.json", - "path": "node_modules/agent-base", - "version": "6.0.2", + "ecosystem": "npm", + "name": "string.prototype.trimstart", + "version": "1.0.8", "license": "MIT", - "status": "approved" + "category": "approved", + "dev": true, + "repository": "git://github.com/es-shims/String.prototype.trimStart" }, { - "lock": "server/package-lock.json", - "path": "node_modules/agent-base/node_modules/debug", - "version": "4.4.3", + "ecosystem": "npm", + "name": "stringify-object", + "version": "3.3.0", + "license": "BSD-2-Clause", + "category": "approved", + "dev": true, + "repository": "yeoman/stringify-object" + }, + { + "ecosystem": "npm", + "name": "strip-ansi", + "version": "6.0.1", "license": "MIT", - "status": "approved" + "category": "approved", + "repository": "chalk/strip-ansi" }, { - "lock": "server/package-lock.json", - "path": "node_modules/agent-base/node_modules/ms", - "version": "2.1.3", + "ecosystem": "npm", + "name": "strip-ansi", + "version": "7.2.0", "license": "MIT", - "status": "approved" + "category": "approved", + "dev": true, + "repository": "chalk/strip-ansi" }, { - "lock": "server/package-lock.json", - "path": "node_modules/array-flatten", - "version": "1.1.1", + "ecosystem": "npm", + "name": "strip-comments", + "version": "2.0.1", "license": "MIT", - "status": "approved" + "category": "approved", + "dev": true, + "repository": "jonschlinkert/strip-comments" }, { - "lock": "server/package-lock.json", - "path": "node_modules/asap", - "version": "2.0.6", + "ecosystem": "npm", + "name": "strip-final-newline", + "version": "3.0.0", "license": "MIT", - "status": "approved" + "category": "approved", + "dev": true, + "repository": "sindresorhus/strip-final-newline" }, { - "lock": "server/package-lock.json", - "path": "node_modules/asynckit", - "version": "0.4.0", + "ecosystem": "npm", + "name": "strip-indent", + "version": "3.0.0", "license": "MIT", - "status": "approved" + "category": "approved", + "dev": true, + "repository": "sindresorhus/strip-indent" }, { - "lock": "server/package-lock.json", - "path": "node_modules/atomic-sleep", - "version": "1.0.0", + "ecosystem": "npm", + "name": "strip-json-comments", + "version": "3.1.1", "license": "MIT", - "status": "approved" + "category": "approved", + "dev": true, + "repository": "sindresorhus/strip-json-comments" }, { - "lock": "server/package-lock.json", - "path": "node_modules/axios", - "version": "1.18.0", + "ecosystem": "npm", + "name": "style-vendorizer", + "version": "2.2.3", "license": "MIT", - "status": "approved" + "category": "approved", + "repository": "kripod/style-vendorizer" }, { - "lock": "server/package-lock.json", - "path": "node_modules/base32.js", - "version": "0.1.0", + "ecosystem": "npm", + "name": "superagent", + "version": "10.3.0", "license": "MIT", - "status": "approved" + "category": "approved", + "dev": true, + "repository": "git://github.com/ladjs/superagent" }, { - "lock": "server/package-lock.json", - "path": "node_modules/base64-js", - "version": "1.5.1", + "ecosystem": "npm", + "name": "supercluster", + "version": "9.0.0", + "license": "ISC", + "category": "approved", + "repository": "git://github.com/mapbox/supercluster" + }, + { + "ecosystem": "npm", + "name": "superstruct", + "version": "2.0.2", "license": "MIT", - "status": "approved" + "category": "approved", + "repository": "git://github.com/ianstormtaylor/superstruct" }, { - "lock": "server/package-lock.json", - "path": "node_modules/bignumber.js", - "version": "11.1.5", + "ecosystem": "npm", + "name": "supertest", + "version": "7.2.2", "license": "MIT", - "status": "approved" + "category": "approved", + "dev": true, + "repository": "https://github.com/ladjs/supertest" }, { - "lock": "server/package-lock.json", - "path": "node_modules/body-parser", - "version": "1.20.6", + "ecosystem": "npm", + "name": "supports-color", + "version": "7.2.0", "license": "MIT", - "status": "approved" + "category": "approved", + "dev": true, + "repository": "chalk/supports-color" }, { - "lock": "server/package-lock.json", - "path": "node_modules/buffer", - "version": "6.0.3", + "ecosystem": "npm", + "name": "supports-preserve-symlinks-flag", + "version": "1.0.0", "license": "MIT", - "status": "approved" + "category": "approved", + "dev": true, + "repository": "https://github.com/inspect-js/node-supports-preserve-symlinks-flag" }, { - "lock": "server/package-lock.json", - "path": "node_modules/bytes", - "version": "3.1.2", + "ecosystem": "npm", + "name": "symbol-tree", + "version": "3.2.4", "license": "MIT", - "status": "approved" + "category": "approved", + "dev": true, + "repository": "https://github.com/jsdom/js-symbol-tree" }, { - "lock": "server/package-lock.json", - "path": "node_modules/call-bind-apply-helpers", - "version": "1.0.2", + "ecosystem": "npm", + "name": "tagged-tag", + "version": "1.0.0", "license": "MIT", - "status": "approved" + "category": "approved", + "dev": true, + "repository": "sindresorhus/tagged-tag" }, { - "lock": "server/package-lock.json", - "path": "node_modules/call-bound", - "version": "1.0.4", + "ecosystem": "npm", + "name": "temp-dir", + "version": "2.0.0", "license": "MIT", - "status": "approved" + "category": "approved", + "dev": true, + "repository": "sindresorhus/temp-dir" }, { - "lock": "server/package-lock.json", - "path": "node_modules/combined-stream", - "version": "1.0.8", + "ecosystem": "npm", + "name": "tempy", + "version": "0.6.0", "license": "MIT", - "status": "approved" + "category": "approved", + "dev": true, + "repository": "sindresorhus/tempy" }, { - "lock": "server/package-lock.json", - "path": "node_modules/comlink", - "version": "4.4.2", - "license": "Apache-2.0", - "status": "approved" + "ecosystem": "npm", + "name": "terser", + "version": "5.51.2", + "license": "BSD-2-Clause", + "category": "approved", + "dev": true, + "repository": "https://github.com/terser/terser" }, { - "lock": "server/package-lock.json", - "path": "node_modules/commander", - "version": "12.1.0", + "ecosystem": "npm", + "name": "text-encoding-utf-8", + "version": "1.0.2", + "license": "UNKNOWN", + "category": "review", + "repository": "https://github.com/arv/text-encoding-utf-8" + }, + { + "ecosystem": "npm", + "name": "thread-stream", + "version": "3.2.0", "license": "MIT", - "status": "approved" + "category": "approved", + "repository": "https://github.com/mcollina/thread-stream" }, { - "lock": "server/package-lock.json", - "path": "node_modules/component-emitter", - "version": "1.3.1", + "ecosystem": "npm", + "name": "tinybench", + "version": "2.9.0", "license": "MIT", - "status": "approved" + "category": "approved", + "dev": true, + "repository": "tinylibs/tinybench" }, { - "lock": "server/package-lock.json", - "path": "node_modules/content-disposition", - "version": "0.5.4", + "ecosystem": "npm", + "name": "tinyexec", + "version": "1.2.4", "license": "MIT", - "status": "approved" + "category": "approved", + "dev": true, + "repository": "https://github.com/tinylibs/tinyexec" }, { - "lock": "server/package-lock.json", - "path": "node_modules/content-type", - "version": "1.0.5", + "ecosystem": "npm", + "name": "tinyglobby", + "version": "0.2.17", "license": "MIT", - "status": "approved" + "category": "approved", + "dev": true, + "repository": "https://github.com/SuperchupuDev/tinyglobby" }, { - "lock": "server/package-lock.json", - "path": "node_modules/cookie", - "version": "0.7.2", + "ecosystem": "npm", + "name": "tinyrainbow", + "version": "3.1.0", "license": "MIT", - "status": "approved" + "category": "approved", + "dev": true, + "repository": "https://github.com/tinylibs/tinyrainbow" }, { - "lock": "server/package-lock.json", - "path": "node_modules/cookie-signature", - "version": "1.0.7", + "ecosystem": "npm", + "name": "tldts", + "version": "7.4.9", "license": "MIT", - "status": "approved" + "category": "approved", + "dev": true, + "repository": "ssh://git@github.com/remusao/tldts" }, { - "lock": "server/package-lock.json", - "path": "node_modules/cookiejar", - "version": "2.1.4", + "ecosystem": "npm", + "name": "tldts-core", + "version": "7.4.9", + "license": "MIT", + "category": "approved", + "dev": true, + "repository": "ssh://git@github.com/remusao/tldts" + }, + { + "ecosystem": "npm", + "name": "to-regex-range", + "version": "5.0.1", "license": "MIT", - "status": "approved" + "category": "approved", + "dev": true, + "repository": "micromatch/to-regex-range" }, { - "lock": "server/package-lock.json", - "path": "node_modules/cors", - "version": "2.8.6", + "ecosystem": "npm", + "name": "toidentifier", + "version": "1.0.1", "license": "MIT", - "status": "approved" + "category": "approved", + "repository": "component/toidentifier" }, { - "lock": "server/package-lock.json", - "path": "node_modules/debug", - "version": "2.6.9", - "license": "MIT", - "status": "approved" + "ecosystem": "npm", + "name": "tough-cookie", + "version": "6.0.2", + "license": "BSD-3-Clause", + "category": "approved", + "dev": true, + "repository": "git://github.com/salesforce/tough-cookie" }, { - "lock": "server/package-lock.json", - "path": "node_modules/delayed-stream", - "version": "1.0.0", + "ecosystem": "npm", + "name": "tr46", + "version": "0.0.3", "license": "MIT", - "status": "approved" + "category": "approved", + "repository": "https://github.com/Sebmaster/tr46.js" }, { - "lock": "server/package-lock.json", - "path": "node_modules/depd", - "version": "2.0.0", + "ecosystem": "npm", + "name": "tr46", + "version": "6.0.0", "license": "MIT", - "status": "approved" + "category": "approved", + "dev": true, + "repository": "https://github.com/jsdom/tr46" }, { - "lock": "server/package-lock.json", - "path": "node_modules/destroy", - "version": "1.2.0", + "ecosystem": "npm", + "name": "ts-mixer", + "version": "6.0.4", "license": "MIT", - "status": "approved" + "category": "approved", + "repository": "https://github.com/tannerntannern/ts-mixer" }, { - "lock": "server/package-lock.json", - "path": "node_modules/detect-libc", - "version": "2.1.2", - "license": "Apache-2.0", - "status": "approved" + "ecosystem": "npm", + "name": "tslib", + "version": "1.14.1", + "license": "0BSD", + "category": "approved", + "repository": "https://github.com/Microsoft/tslib" }, { - "lock": "server/package-lock.json", - "path": "node_modules/dezalgo", - "version": "1.0.4", - "license": "ISC", - "status": "approved" + "ecosystem": "npm", + "name": "tslib", + "version": "2.8.1", + "license": "0BSD", + "category": "approved", + "repository": "https://github.com/Microsoft/tslib" }, { - "lock": "server/package-lock.json", - "path": "node_modules/dunder-proto", - "version": "1.0.1", - "license": "MIT", - "status": "approved" + "ecosystem": "npm", + "name": "tweetnacl", + "version": "1.0.3", + "license": "Unlicense", + "category": "approved", + "repository": "https://github.com/dchest/tweetnacl-js" }, { - "lock": "server/package-lock.json", - "path": "node_modules/ee-first", - "version": "1.1.1", - "license": "MIT", - "status": "approved" + "ecosystem": "npm", + "name": "tweetnacl-util", + "version": "0.15.1", + "license": "Unlicense", + "category": "approved", + "repository": "https://github.com/dchest/tweetnacl-util-js" }, { - "lock": "server/package-lock.json", - "path": "node_modules/encodeurl", - "version": "2.0.0", + "ecosystem": "npm", + "name": "type-check", + "version": "0.4.0", "license": "MIT", - "status": "approved" + "category": "approved", + "dev": true, + "repository": "git://github.com/gkz/type-check" }, { - "lock": "server/package-lock.json", - "path": "node_modules/es-define-property", - "version": "1.0.1", - "license": "MIT", - "status": "approved" + "ecosystem": "npm", + "name": "type-fest", + "version": "0.16.0", + "license": "(MIT OR CC0-1.0)", + "category": "approved", + "dev": true, + "repository": "sindresorhus/type-fest" }, { - "lock": "server/package-lock.json", - "path": "node_modules/es-errors", - "version": "1.3.0", - "license": "MIT", - "status": "approved" + "ecosystem": "npm", + "name": "type-fest", + "version": "5.8.0", + "license": "(MIT OR CC0-1.0)", + "category": "approved", + "dev": true, + "repository": "sindresorhus/type-fest" }, { - "lock": "server/package-lock.json", - "path": "node_modules/es-object-atoms", - "version": "1.1.2", + "ecosystem": "npm", + "name": "type-is", + "version": "1.6.18", "license": "MIT", - "status": "approved" + "category": "approved", + "repository": "jshttp/type-is" }, { - "lock": "server/package-lock.json", - "path": "node_modules/es-set-tostringtag", - "version": "2.1.0", + "ecosystem": "npm", + "name": "typed-array-buffer", + "version": "1.0.3", "license": "MIT", - "status": "approved" + "category": "approved", + "dev": true, + "repository": "https://github.com/inspect-js/typed-array-buffer" }, { - "lock": "server/package-lock.json", - "path": "node_modules/escape-html", + "ecosystem": "npm", + "name": "typed-array-byte-length", "version": "1.0.3", "license": "MIT", - "status": "approved" + "category": "approved", + "dev": true, + "repository": "https://github.com/inspect-js/typed-array-byte-length" }, { - "lock": "server/package-lock.json", - "path": "node_modules/etag", - "version": "1.8.1", + "ecosystem": "npm", + "name": "typed-array-byte-offset", + "version": "1.0.4", "license": "MIT", - "status": "approved" + "category": "approved", + "dev": true, + "repository": "https://github.com/inspect-js/typed-array-byte-offset" }, { - "lock": "server/package-lock.json", - "path": "node_modules/eventsource", - "version": "4.1.1", + "ecosystem": "npm", + "name": "typed-array-length", + "version": "1.0.8", "license": "MIT", - "status": "approved" + "category": "approved", + "dev": true, + "repository": "https://github.com/inspect-js/typed-array-length" }, { - "lock": "server/package-lock.json", - "path": "node_modules/eventsource-parser", - "version": "3.1.1", - "license": "MIT", - "status": "approved" + "ecosystem": "npm", + "name": "typescript", + "version": "7.0.2", + "license": "Apache-2.0", + "category": "approved", + "dev": true, + "repository": "https://github.com/microsoft/TypeScript" }, { - "lock": "server/package-lock.json", - "path": "node_modules/express", - "version": "4.22.2", + "ecosystem": "npm", + "name": "typewise", + "version": "1.0.3", "license": "MIT", - "status": "approved" + "category": "approved", + "repository": "https://github.com/deanlandolt/typewise" }, { - "lock": "server/package-lock.json", - "path": "node_modules/fast-safe-stringify", - "version": "2.1.1", + "ecosystem": "npm", + "name": "typewise-core", + "version": "1.2.0", "license": "MIT", - "status": "approved" + "category": "approved", + "repository": "https://github.com/deanlandolt/typewise-core" }, { - "lock": "server/package-lock.json", - "path": "node_modules/feaxios", - "version": "0.0.23", + "ecosystem": "npm", + "name": "ufo", + "version": "1.6.4", "license": "MIT", - "status": "approved" + "category": "approved", + "repository": "unjs/ufo" }, { - "lock": "server/package-lock.json", - "path": "node_modules/finalhandler", - "version": "1.3.2", + "ecosystem": "npm", + "name": "uint8array-extras", + "version": "1.5.0", "license": "MIT", - "status": "approved" + "category": "approved", + "repository": "sindresorhus/uint8array-extras" }, { - "lock": "server/package-lock.json", - "path": "node_modules/follow-redirects", - "version": "1.16.0", + "ecosystem": "npm", + "name": "uint8arrays", + "version": "3.1.1", "license": "MIT", - "status": "approved" + "category": "approved", + "repository": "https://github.com/achingbrain/uint8arrays" }, { - "lock": "server/package-lock.json", - "path": "node_modules/form-data", - "version": "4.0.6", + "ecosystem": "npm", + "name": "unbox-primitive", + "version": "1.1.0", "license": "MIT", - "status": "approved" + "category": "approved", + "dev": true, + "repository": "https://github.com/ljharb/unbox-primitive" }, { - "lock": "server/package-lock.json", - "path": "node_modules/formidable", - "version": "3.5.4", + "ecosystem": "npm", + "name": "uncrypto", + "version": "0.1.3", "license": "MIT", - "status": "approved" + "category": "approved", + "repository": "unjs/uncrypto" }, { - "lock": "server/package-lock.json", - "path": "node_modules/forwarded", - "version": "0.2.0", + "ecosystem": "npm", + "name": "undici", + "version": "7.29.0", "license": "MIT", - "status": "approved" + "category": "approved", + "dev": true, + "repository": "https://github.com/nodejs/undici" }, { - "lock": "server/package-lock.json", - "path": "node_modules/fresh", - "version": "0.5.2", + "ecosystem": "npm", + "name": "undici-types", + "version": "6.21.0", "license": "MIT", - "status": "approved" + "category": "approved", + "repository": "https://github.com/nodejs/undici" }, { - "lock": "server/package-lock.json", - "path": "node_modules/function-bind", - "version": "1.1.2", + "ecosystem": "npm", + "name": "undici-types", + "version": "7.28.0", "license": "MIT", - "status": "approved" + "category": "approved", + "repository": "https://github.com/nodejs/undici" }, { - "lock": "server/package-lock.json", - "path": "node_modules/get-intrinsic", - "version": "1.3.0", + "ecosystem": "npm", + "name": "unicode-canonical-property-names-ecmascript", + "version": "2.0.1", "license": "MIT", - "status": "approved" + "category": "approved", + "dev": true, + "repository": "https://github.com/mathiasbynens/unicode-canonical-property-names-ecmascript" }, { - "lock": "server/package-lock.json", - "path": "node_modules/get-proto", - "version": "1.0.1", + "ecosystem": "npm", + "name": "unicode-match-property-ecmascript", + "version": "2.0.0", "license": "MIT", - "status": "approved" + "category": "approved", + "dev": true, + "repository": "https://github.com/mathiasbynens/unicode-match-property-ecmascript" }, { - "lock": "server/package-lock.json", - "path": "node_modules/gopd", - "version": "1.2.0", + "ecosystem": "npm", + "name": "unicode-match-property-value-ecmascript", + "version": "2.2.1", "license": "MIT", - "status": "approved" + "category": "approved", + "dev": true, + "repository": "https://github.com/mathiasbynens/unicode-match-property-value-ecmascript" }, { - "lock": "server/package-lock.json", - "path": "node_modules/has-symbols", - "version": "1.1.0", + "ecosystem": "npm", + "name": "unicode-property-aliases-ecmascript", + "version": "2.2.0", "license": "MIT", - "status": "approved" + "category": "approved", + "dev": true, + "repository": "https://github.com/mathiasbynens/unicode-property-aliases-ecmascript" }, { - "lock": "server/package-lock.json", - "path": "node_modules/has-tostringtag", - "version": "1.0.2", + "ecosystem": "npm", + "name": "union-value", + "version": "1.0.1", "license": "MIT", - "status": "approved" + "category": "approved", + "repository": "jonschlinkert/union-value" }, { - "lock": "server/package-lock.json", - "path": "node_modules/hasown", - "version": "2.0.4", + "ecosystem": "npm", + "name": "unique-string", + "version": "2.0.0", "license": "MIT", - "status": "approved" + "category": "approved", + "dev": true, + "repository": "sindresorhus/unique-string" }, { - "lock": "server/package-lock.json", - "path": "node_modules/http-errors", + "ecosystem": "npm", + "name": "universalify", "version": "2.0.1", "license": "MIT", - "status": "approved" + "category": "approved", + "dev": true, + "repository": "https://github.com/RyanZim/universalify" }, { - "lock": "server/package-lock.json", - "path": "node_modules/https-proxy-agent", - "version": "5.0.1", + "ecosystem": "npm", + "name": "unpipe", + "version": "1.0.0", "license": "MIT", - "status": "approved" + "category": "approved", + "repository": "stream-utils/unpipe" }, { - "lock": "server/package-lock.json", - "path": "node_modules/https-proxy-agent/node_modules/debug", - "version": "4.4.3", + "ecosystem": "npm", + "name": "unstorage", + "version": "1.17.5", "license": "MIT", - "status": "approved" + "category": "approved", + "repository": "unjs/unstorage" }, { - "lock": "server/package-lock.json", - "path": "node_modules/https-proxy-agent/node_modules/ms", - "version": "2.1.3", + "ecosystem": "npm", + "name": "until-async", + "version": "3.0.2", "license": "MIT", - "status": "approved" + "category": "approved", + "dev": true, + "repository": "https://github.com/kettanaito/until-async" }, { - "lock": "server/package-lock.json", - "path": "node_modules/iconv-lite", - "version": "0.4.24", + "ecosystem": "npm", + "name": "upath", + "version": "1.2.0", "license": "MIT", - "status": "approved" + "category": "approved", + "dev": true, + "repository": "git://github.com/anodynos/upath" }, { - "lock": "server/package-lock.json", - "path": "node_modules/idb-keyval", - "version": "6.3.0", - "license": "Apache-2.0", - "status": "approved" - }, - { - "lock": "server/package-lock.json", - "path": "node_modules/ieee754", - "version": "1.2.1", - "license": "BSD-3-Clause", - "status": "approved" + "ecosystem": "npm", + "name": "update-browserslist-db", + "version": "1.3.2", + "license": "MIT", + "category": "approved", + "dev": true, + "repository": "browserslist/update-db" }, { - "lock": "server/package-lock.json", - "path": "node_modules/inherits", - "version": "2.0.4", - "license": "ISC", - "status": "approved" + "ecosystem": "npm", + "name": "uri-js", + "version": "4.4.1", + "license": "BSD-2-Clause", + "category": "approved", + "dev": true, + "repository": "http://github.com/garycourt/uri-js" }, { - "lock": "server/package-lock.json", - "path": "node_modules/ipaddr.js", - "version": "1.9.1", + "ecosystem": "npm", + "name": "utf-8-validate", + "version": "6.0.6", "license": "MIT", - "status": "approved" + "category": "approved", + "repository": "https://github.com/websockets/utf-8-validate" }, { - "lock": "server/package-lock.json", - "path": "node_modules/is-retry-allowed", - "version": "3.0.0", + "ecosystem": "npm", + "name": "utils-merge", + "version": "1.0.1", "license": "MIT", - "status": "approved" + "category": "approved", + "repository": "git://github.com/jaredhanson/utils-merge" }, { - "lock": "server/package-lock.json", - "path": "node_modules/math-intrinsics", - "version": "1.1.0", + "ecosystem": "npm", + "name": "uuid", + "version": "14.0.1", "license": "MIT", - "status": "approved" + "category": "approved", + "repository": "https://github.com/uuidjs/uuid" }, { - "lock": "server/package-lock.json", - "path": "node_modules/media-typer", - "version": "0.3.0", + "ecosystem": "npm", + "name": "uuid", + "version": "8.3.2", "license": "MIT", - "status": "approved" + "category": "approved", + "repository": "https://github.com/uuidjs/uuid" }, { - "lock": "server/package-lock.json", - "path": "node_modules/merge-descriptors", - "version": "1.0.3", - "license": "MIT", - "status": "approved" + "ecosystem": "npm", + "name": "uuid4", + "version": "2.0.3", + "license": "ISC", + "category": "approved", + "repository": "https://github.com/tracker1/node-uuid4" }, { - "lock": "server/package-lock.json", - "path": "node_modules/methods", - "version": "1.1.2", + "ecosystem": "npm", + "name": "valtio", + "version": "2.1.7", "license": "MIT", - "status": "approved" + "category": "approved", + "repository": "https://github.com/pmndrs/valtio" }, { - "lock": "server/package-lock.json", - "path": "node_modules/mime", - "version": "1.6.0", + "ecosystem": "npm", + "name": "vary", + "version": "1.1.2", "license": "MIT", - "status": "approved" + "category": "approved", + "repository": "jshttp/vary" }, { - "lock": "server/package-lock.json", - "path": "node_modules/mime-db", - "version": "1.52.0", + "ecosystem": "npm", + "name": "viem", + "version": "2.53.1", "license": "MIT", - "status": "approved" + "category": "approved", + "repository": "https://github.com/wevm/viem" }, { - "lock": "server/package-lock.json", - "path": "node_modules/mime-types", - "version": "2.1.35", + "ecosystem": "npm", + "name": "vite", + "version": "8.0.16", "license": "MIT", - "status": "approved" + "category": "approved", + "dev": true, + "repository": "https://github.com/vitejs/vite" }, { - "lock": "server/package-lock.json", - "path": "node_modules/ms", - "version": "2.0.0", + "ecosystem": "npm", + "name": "vite-plugin-pwa", + "version": "0.21.2", "license": "MIT", - "status": "approved" + "category": "approved", + "dev": true, + "repository": "https://github.com/vite-pwa/vite-plugin-pwa" }, { - "lock": "server/package-lock.json", - "path": "node_modules/msgpackr", - "version": "1.12.1", + "ecosystem": "npm", + "name": "vitest", + "version": "4.1.11", "license": "MIT", - "status": "approved" + "category": "approved", + "dev": true, + "repository": "https://github.com/vitest-dev/vitest" }, { - "lock": "server/package-lock.json", - "path": "node_modules/msgpackr-extract", - "version": "3.0.4", + "ecosystem": "npm", + "name": "void-elements", + "version": "3.1.0", "license": "MIT", - "status": "approved" + "category": "approved", + "repository": "pugjs/void-elements" }, { - "lock": "server/package-lock.json", - "path": "node_modules/negotiator", - "version": "0.6.3", + "ecosystem": "npm", + "name": "w3c-xmlserializer", + "version": "5.0.0", "license": "MIT", - "status": "approved" + "category": "approved", + "dev": true, + "repository": "jsdom/w3c-xmlserializer" }, { - "lock": "server/package-lock.json", - "path": "node_modules/node-gyp-build-optional-packages", - "version": "5.2.2", - "license": "MIT", - "status": "approved" + "ecosystem": "npm", + "name": "webidl-conversions", + "version": "3.0.1", + "license": "BSD-2-Clause", + "category": "approved", + "repository": "jsdom/webidl-conversions" }, { - "lock": "server/package-lock.json", - "path": "node_modules/object-assign", - "version": "4.1.1", - "license": "MIT", - "status": "approved" + "ecosystem": "npm", + "name": "webidl-conversions", + "version": "8.0.1", + "license": "BSD-2-Clause", + "category": "approved", + "dev": true, + "repository": "https://github.com/jsdom/webidl-conversions" }, { - "lock": "server/package-lock.json", - "path": "node_modules/object-inspect", - "version": "1.13.4", + "ecosystem": "npm", + "name": "whatwg-mimetype", + "version": "5.0.0", "license": "MIT", - "status": "approved" + "category": "approved", + "dev": true, + "repository": "jsdom/whatwg-mimetype" }, { - "lock": "server/package-lock.json", - "path": "node_modules/on-exit-leak-free", - "version": "2.1.2", + "ecosystem": "npm", + "name": "whatwg-url", + "version": "16.0.1", "license": "MIT", - "status": "approved" + "category": "approved", + "dev": true, + "repository": "https://github.com/jsdom/whatwg-url" }, { - "lock": "server/package-lock.json", - "path": "node_modules/on-finished", - "version": "2.4.1", + "ecosystem": "npm", + "name": "whatwg-url", + "version": "5.0.0", "license": "MIT", - "status": "approved" + "category": "approved", + "repository": "jsdom/whatwg-url" }, { - "lock": "server/package-lock.json", - "path": "node_modules/once", - "version": "1.4.0", + "ecosystem": "npm", + "name": "which", + "version": "2.0.2", "license": "ISC", - "status": "approved" - }, - { - "lock": "server/package-lock.json", - "path": "node_modules/pako", - "version": "2.2.0", - "license": "(MIT AND Zlib)", - "status": "review" + "category": "approved", + "dev": true, + "repository": "git://github.com/isaacs/node-which" }, { - "lock": "server/package-lock.json", - "path": "node_modules/parseurl", - "version": "1.3.3", + "ecosystem": "npm", + "name": "which-boxed-primitive", + "version": "1.1.1", "license": "MIT", - "status": "approved" + "category": "approved", + "dev": true, + "repository": "https://github.com/inspect-js/which-boxed-primitive" }, { - "lock": "server/package-lock.json", - "path": "node_modules/path-to-regexp", - "version": "0.1.13", + "ecosystem": "npm", + "name": "which-builtin-type", + "version": "1.2.1", "license": "MIT", - "status": "approved" + "category": "approved", + "dev": true, + "repository": "https://github.com/inspect-js/which-builtin-type" }, { - "lock": "server/package-lock.json", - "path": "node_modules/pino", - "version": "9.14.0", + "ecosystem": "npm", + "name": "which-collection", + "version": "1.0.2", "license": "MIT", - "status": "approved" + "category": "approved", + "dev": true, + "repository": "https://github.com/inspect-js/which-collection" }, { - "lock": "server/package-lock.json", - "path": "node_modules/pino-abstract-transport", - "version": "2.0.0", - "license": "MIT", - "status": "approved" + "ecosystem": "npm", + "name": "which-module", + "version": "2.0.1", + "license": "ISC", + "category": "approved", + "repository": "https://github.com/nexdrew/which-module" }, { - "lock": "server/package-lock.json", - "path": "node_modules/pino-std-serializers", - "version": "7.1.0", + "ecosystem": "npm", + "name": "which-typed-array", + "version": "1.1.22", "license": "MIT", - "status": "approved" + "category": "approved", + "dev": true, + "repository": "git://github.com/inspect-js/which-typed-array" }, { - "lock": "server/package-lock.json", - "path": "node_modules/process-warning", - "version": "5.1.0", + "ecosystem": "npm", + "name": "why-is-node-running", + "version": "2.3.0", "license": "MIT", - "status": "approved" + "category": "approved", + "dev": true, + "repository": "https://github.com/mafintosh/why-is-node-running" }, { - "lock": "server/package-lock.json", - "path": "node_modules/proxy-addr", - "version": "2.0.7", + "ecosystem": "npm", + "name": "word-wrap", + "version": "1.2.5", "license": "MIT", - "status": "approved" + "category": "approved", + "dev": true, + "repository": "jonschlinkert/word-wrap" }, { - "lock": "server/package-lock.json", - "path": "node_modules/proxy-from-env", - "version": "2.1.0", + "ecosystem": "npm", + "name": "workbox-background-sync", + "version": "7.4.1", "license": "MIT", - "status": "approved" + "category": "approved", + "dev": true, + "repository": "https://github.com/googlechrome/workbox" }, { - "lock": "server/package-lock.json", - "path": "node_modules/qs", - "version": "6.15.3", - "license": "BSD-3-Clause", - "status": "approved" + "ecosystem": "npm", + "name": "workbox-broadcast-update", + "version": "7.4.1", + "license": "MIT", + "category": "approved", + "dev": true, + "repository": "https://github.com/googlechrome/workbox" }, { - "lock": "server/package-lock.json", - "path": "node_modules/quick-format-unescaped", - "version": "4.0.4", + "ecosystem": "npm", + "name": "workbox-build", + "version": "7.4.1", "license": "MIT", - "status": "approved" + "category": "approved", + "dev": true, + "repository": "https://github.com/googlechrome/workbox" }, { - "lock": "server/package-lock.json", - "path": "node_modules/range-parser", - "version": "1.2.1", + "ecosystem": "npm", + "name": "workbox-cacheable-response", + "version": "7.4.1", "license": "MIT", - "status": "approved" + "category": "approved", + "dev": true, + "repository": "https://github.com/googlechrome/workbox" }, { - "lock": "server/package-lock.json", - "path": "node_modules/raw-body", - "version": "2.5.3", + "ecosystem": "npm", + "name": "workbox-core", + "version": "7.4.1", "license": "MIT", - "status": "approved" + "category": "approved", + "dev": true, + "repository": "https://github.com/googlechrome/workbox" }, { - "lock": "server/package-lock.json", - "path": "node_modules/real-require", - "version": "0.2.0", + "ecosystem": "npm", + "name": "workbox-expiration", + "version": "7.4.1", "license": "MIT", - "status": "approved" + "category": "approved", + "dev": true, + "repository": "https://github.com/googlechrome/workbox" }, { - "lock": "server/package-lock.json", - "path": "node_modules/safe-buffer", - "version": "5.2.1", + "ecosystem": "npm", + "name": "workbox-google-analytics", + "version": "7.4.1", "license": "MIT", - "status": "approved" + "category": "approved", + "dev": true, + "repository": "https://github.com/googlechrome/workbox" }, { - "lock": "server/package-lock.json", - "path": "node_modules/safe-stable-stringify", - "version": "2.5.0", + "ecosystem": "npm", + "name": "workbox-navigation-preload", + "version": "7.4.1", "license": "MIT", - "status": "approved" + "category": "approved", + "dev": true, + "repository": "https://github.com/googlechrome/workbox" }, { - "lock": "server/package-lock.json", - "path": "node_modules/safer-buffer", - "version": "2.1.2", + "ecosystem": "npm", + "name": "workbox-precaching", + "version": "7.4.1", "license": "MIT", - "status": "approved" + "category": "approved", + "dev": true, + "repository": "https://github.com/googlechrome/workbox" }, { - "lock": "server/package-lock.json", - "path": "node_modules/send", - "version": "0.19.2", + "ecosystem": "npm", + "name": "workbox-range-requests", + "version": "7.4.1", "license": "MIT", - "status": "approved" + "category": "approved", + "dev": true, + "repository": "https://github.com/googlechrome/workbox" }, { - "lock": "server/package-lock.json", - "path": "node_modules/send/node_modules/ms", - "version": "2.1.3", + "ecosystem": "npm", + "name": "workbox-recipes", + "version": "7.4.1", "license": "MIT", - "status": "approved" + "category": "approved", + "dev": true, + "repository": "https://github.com/googlechrome/workbox" }, { - "lock": "server/package-lock.json", - "path": "node_modules/serve-static", - "version": "1.16.3", + "ecosystem": "npm", + "name": "workbox-routing", + "version": "7.4.1", "license": "MIT", - "status": "approved" + "category": "approved", + "dev": true, + "repository": "https://github.com/googlechrome/workbox" }, { - "lock": "server/package-lock.json", - "path": "node_modules/setprototypeof", - "version": "1.2.0", - "license": "ISC", - "status": "approved" + "ecosystem": "npm", + "name": "workbox-strategies", + "version": "7.4.1", + "license": "MIT", + "category": "approved", + "dev": true, + "repository": "https://github.com/googlechrome/workbox" }, { - "lock": "server/package-lock.json", - "path": "node_modules/side-channel", - "version": "1.1.1", + "ecosystem": "npm", + "name": "workbox-streams", + "version": "7.4.1", "license": "MIT", - "status": "approved" + "category": "approved", + "dev": true, + "repository": "https://github.com/googlechrome/workbox" }, { - "lock": "server/package-lock.json", - "path": "node_modules/side-channel-list", - "version": "1.0.1", + "ecosystem": "npm", + "name": "workbox-sw", + "version": "7.4.1", "license": "MIT", - "status": "approved" + "category": "approved", + "dev": true, + "repository": "https://github.com/googlechrome/workbox" }, { - "lock": "server/package-lock.json", - "path": "node_modules/side-channel-map", - "version": "1.0.1", + "ecosystem": "npm", + "name": "workbox-window", + "version": "7.4.1", "license": "MIT", - "status": "approved" + "category": "approved", + "dev": true, + "repository": "https://github.com/googlechrome/workbox" }, { - "lock": "server/package-lock.json", - "path": "node_modules/side-channel-weakmap", - "version": "1.0.2", + "ecosystem": "npm", + "name": "wrap-ansi", + "version": "6.2.0", "license": "MIT", - "status": "approved" + "category": "approved", + "repository": "chalk/wrap-ansi" }, { - "lock": "server/package-lock.json", - "path": "node_modules/smol-toml", - "version": "1.8.0", - "license": "BSD-3-Clause", - "status": "approved" + "ecosystem": "npm", + "name": "wrap-ansi", + "version": "7.0.0", + "license": "MIT", + "category": "approved", + "dev": true, + "repository": "chalk/wrap-ansi" }, { - "lock": "server/package-lock.json", - "path": "node_modules/sonic-boom", - "version": "4.2.1", + "ecosystem": "npm", + "name": "wrap-ansi", + "version": "9.0.2", "license": "MIT", - "status": "approved" + "category": "approved", + "dev": true, + "repository": "chalk/wrap-ansi" }, { - "lock": "server/package-lock.json", - "path": "node_modules/split2", - "version": "4.2.0", + "ecosystem": "npm", + "name": "wrappy", + "version": "1.0.2", "license": "ISC", - "status": "approved" + "category": "approved", + "dev": true, + "repository": "https://github.com/npm/wrappy" }, { - "lock": "server/package-lock.json", - "path": "node_modules/statuses", - "version": "2.0.2", + "ecosystem": "npm", + "name": "ws", + "version": "7.5.11", "license": "MIT", - "status": "approved" + "category": "approved", + "repository": "websockets/ws" }, { - "lock": "server/package-lock.json", - "path": "node_modules/superagent", - "version": "10.3.0", + "ecosystem": "npm", + "name": "ws", + "version": "8.21.0", "license": "MIT", - "status": "approved" + "category": "approved", + "repository": "https://github.com/websockets/ws" }, { - "lock": "server/package-lock.json", - "path": "node_modules/superagent/node_modules/debug", - "version": "4.4.3", - "license": "MIT", - "status": "approved" + "ecosystem": "npm", + "name": "xml-name-validator", + "version": "5.0.0", + "license": "Apache-2.0", + "category": "approved", + "dev": true, + "repository": "jsdom/xml-name-validator" }, { - "lock": "server/package-lock.json", - "path": "node_modules/superagent/node_modules/mime", - "version": "2.6.0", + "ecosystem": "npm", + "name": "xmlchars", + "version": "2.2.0", "license": "MIT", - "status": "approved" + "category": "approved", + "dev": true, + "repository": "https://github.com/lddubeau/xmlchars" }, { - "lock": "server/package-lock.json", - "path": "node_modules/superagent/node_modules/ms", - "version": "2.1.3", - "license": "MIT", - "status": "approved" + "ecosystem": "npm", + "name": "y18n", + "version": "4.0.3", + "license": "ISC", + "category": "approved", + "repository": "git@github.com:yargs/y18n" }, { - "lock": "server/package-lock.json", - "path": "node_modules/supertest", - "version": "7.2.2", - "license": "MIT", - "status": "approved" + "ecosystem": "npm", + "name": "y18n", + "version": "5.0.8", + "license": "ISC", + "category": "approved", + "dev": true, + "repository": "yargs/y18n" }, { - "lock": "server/package-lock.json", - "path": "node_modules/supertest/node_modules/cookie-signature", - "version": "1.2.2", - "license": "MIT", - "status": "approved" + "ecosystem": "npm", + "name": "yallist", + "version": "3.1.1", + "license": "ISC", + "category": "approved", + "dev": true, + "repository": "https://github.com/isaacs/yallist" }, { - "lock": "server/package-lock.json", - "path": "node_modules/thread-stream", - "version": "3.2.0", + "ecosystem": "npm", + "name": "yaml", + "version": "2.9.0", + "license": "ISC", + "category": "approved", + "dev": true, + "repository": "github:eemeli/yaml" + }, + { + "ecosystem": "npm", + "name": "yargs", + "version": "15.4.1", "license": "MIT", - "status": "approved" + "category": "approved", + "repository": "https://github.com/yargs/yargs" }, { - "lock": "server/package-lock.json", - "path": "node_modules/toidentifier", - "version": "1.0.1", + "ecosystem": "npm", + "name": "yargs", + "version": "17.7.3", "license": "MIT", - "status": "approved" + "category": "approved", + "dev": true, + "repository": "https://github.com/yargs/yargs" }, { - "lock": "server/package-lock.json", - "path": "node_modules/tslib", - "version": "2.8.1", - "license": "0BSD", - "status": "approved" + "ecosystem": "npm", + "name": "yargs-parser", + "version": "18.1.3", + "license": "ISC", + "category": "approved", + "repository": "https://github.com/yargs/yargs-parser" }, { - "lock": "server/package-lock.json", - "path": "node_modules/type-is", - "version": "1.6.18", - "license": "MIT", - "status": "approved" + "ecosystem": "npm", + "name": "yargs-parser", + "version": "21.1.1", + "license": "ISC", + "category": "approved", + "dev": true, + "repository": "https://github.com/yargs/yargs-parser" }, { - "lock": "server/package-lock.json", - "path": "node_modules/uint8array-extras", - "version": "1.5.0", + "ecosystem": "npm", + "name": "yjs", + "version": "13.6.33", "license": "MIT", - "status": "approved" + "category": "approved", + "dev": true, + "repository": "https://github.com/yjs/yjs" }, { - "lock": "server/package-lock.json", - "path": "node_modules/unpipe", - "version": "1.0.0", + "ecosystem": "npm", + "name": "yocto-queue", + "version": "0.1.0", "license": "MIT", - "status": "approved" + "category": "approved", + "dev": true, + "repository": "sindresorhus/yocto-queue" }, { - "lock": "server/package-lock.json", - "path": "node_modules/utils-merge", - "version": "1.0.1", + "ecosystem": "npm", + "name": "zod", + "version": "3.22.4", "license": "MIT", - "status": "approved" + "category": "approved", + "repository": "https://github.com/colinhacks/zod" }, { - "lock": "server/package-lock.json", - "path": "node_modules/vary", - "version": "1.1.2", + "ecosystem": "npm", + "name": "zod", + "version": "3.25.76", "license": "MIT", - "status": "approved" + "category": "approved", + "repository": "https://github.com/colinhacks/zod" }, { - "lock": "server/package-lock.json", - "path": "node_modules/wrappy", - "version": "1.0.2", - "license": "ISC", - "status": "approved" + "ecosystem": "npm", + "name": "zustand", + "version": "5.0.3", + "license": "MIT", + "category": "approved", + "repository": "https://github.com/pmndrs/zustand" } ] } diff --git a/package.json b/package.json index 882bd34f..df6dda3c 100644 --- a/package.json +++ b/package.json @@ -8,9 +8,9 @@ "dev": "node scripts/dev.mjs", "predev": "npm run zk:shard", "dev:vite": "vite", - "server": "tsx server/index.js", + "server": "node --experimental-strip-types server/index.ts", "server:js": "node server/index.js", - "start": "tsx server/index.js", + "start": "node --experimental-strip-types server/index.ts", "dev:all": "node scripts/dev.mjs", "build": "vite build", "prebuild": "npm run zk:shard", @@ -34,7 +34,7 @@ "test:ws-cluster": "node server/tests/ws-cluster.js", "zk:shard": "python circuits/scripts/shard-aegis.py circuits/target/aegis.json public/zk-assets", "test:watch": "vitest", - "test:update-snapshots": "vitest run test/snapshots.test.jsx -u", + "test:update-snapshots": "vitest run -u", "test:e2e:throttling": "playwright test --project=throttling", "test:layout": "playwright test --project=\"layout-*\"", "test:layout:generate": "playwright test --project=\"layout-*\" --update-snapshots", @@ -45,7 +45,38 @@ "export:state": "bash scripts/export-contract-state.sh", "bindings:soroban": "node scripts/generate-soroban-bindings.js", "prepare": "husky", - "db:migrate": "tsx server/db/migrator.ts" + "db:migrate": "tsx server/db/migrator.ts", + "start:all": "node scripts/dev.mjs", + "build:secure": "node scripts/security/env_firewall.js --exec npx vite build", + "security:audit-bundle": "node scripts/security/env_firewall.js --audit dist", + "security:licenses": "node scripts/security/license_compliance.js", + "security:cargo": "bash scripts/security/cargo_minimal_versions.sh --check-only", + "security:typosquat": "node scripts/detect-typosquatting.js", + "security:transitive-vuln": "node scripts/transitive-vulnerability-scanner.js", + "security:wasm-verify": "bash scripts/verify-wasm-build.sh", + "security:dep-health": "node scripts/monitor-dep-health.js --offline", + "security:commits": "node scripts/security/verify_commit_signatures.js --range origin/main..HEAD", + "security:license-gate": "node scripts/license-compliance.js --no-write", + "licenses:generate": "node scripts/license-compliance.js", + "build:release": "vite build && node scripts/license-compliance.js --out dist/licenses.json", + "security:cve-patch": "node scripts/auto-patch-cve.js", + "security:cve-patch:apply": "node scripts/auto-patch-cve.js --apply", + "security:maintainer-keys": "node scripts/security/verify_maintainer_keys.js", + "build:all": "npm run build && npm run build --workspace server --if-present", + "security:binaries": "node scripts/security/strip_executables.js", + "spike:webrtc": "vitest run test/webrtc-nat-spike.test.js", + "spike:crdt-storage": "vitest run test/crdt-storage-spike.test.js", + "spike:coep": "vitest run test/coep-headers-spike.test.js", + "security:strip": "node scripts/security/strip_executables.js --strip", + "test:coverage": "vitest run --coverage", + "test:a11y": "vitest run test/a11y-components.test.jsx", + "test:e2e": "playwright test", + "test:e2e:a11y": "playwright test tests/e2e/a11y.spec.ts", + "spike:crdt": "node --expose-gc --max-old-space-size=3072 scripts/spikes/crdt_memory_profile.js --heap-snapshots --out docs/spikes/results/crdt-memory-profile.json", + "spike:zk:build": "bash circuits/recursive_verifier/build.sh 1 && bash circuits/recursive_verifier/build.sh 2 && bash circuits/recursive_verifier/build.sh 5", + "spike:zk": "node scripts/spikes/zk_aggregation_benchmark.js --out docs/spikes/results/zk-aggregation.json", + "spike:routing": "node --expose-gc --max-old-space-size=3072 scripts/spikes/routing_benchmark.js --out docs/spikes/results/routing-benchmark.json", + "spike:storage": "node scripts/spikes/storage_contention_benchmark.js --out docs/spikes/results/storage-contention.json" }, "keywords": [], "author": "", @@ -58,8 +89,8 @@ "@playwright/test": "^1.62.1", "@testing-library/jest-dom": "^7.0.0", "@testing-library/react": "^16.3.2", - "@types/cors": "^2.8.17", - "@types/express": "^4.17.21", + "@types/cors": "^2.8.19", + "@types/express": "^5.0.6", "@types/node": "^22.0.0", "@types/pg": "^8.23.1", "@types/react": "^19.0.0", @@ -72,13 +103,24 @@ "jsdom": "^29.1.1", "lint-staged": "^15.0.0", "msw": "^2.15.0", - "rollup-plugin-visualizer": "^7.1.1", - "supertest": "^7.3.0", + "rollup-plugin-visualizer": "^5.14.0", + "supertest": "^7.0.0", "tsx": "^4.19.0", - "typescript": "^5.6.0", + "typescript": "^7.0.2", "vite": "^8.0.16", - "vite-plugin-pwa": "^1.3.0", - "vitest": "^4.1.10" + "vite-plugin-pwa": "^0.21.2", + "vitest": "^4.1.10", + "@axe-core/playwright": "^4.13.0", + "@sqlite.org/sqlite-wasm": "^3.53.4-build1", + "@testing-library/dom": "^10.4.1", + "@types/morgan": "^1.9.10", + "@vitest/coverage-v8": "^4.1.10", + "compression": "~1.8.1", + "globals": "^17.11.0", + "jest-axe": "^11.0.0", + "jest-canvas-mock": "^2.5.8", + "prettier": "^3.0.0", + "yjs": "^13.6.33" }, "dependencies": { "@apollo/server": "^5.5.1", @@ -106,12 +148,16 @@ "pg": "^8.23.0", "react": "^19.2.7", "react-dom": "^19.2.7", - "react-i18next": "^16.5.4", + "react-i18next": "^15.5.3", "react-map-gl": "^8.1.1", "react-router-dom": "^7.18.0", "workbox-range-requests": "^7.4.1", "ws": "^8.18.3", - "zod": "^3.25.76" + "zod": "^3.25.76", + "@types/supercluster": "~7.1.3", + "i18next": "^25.3.2", + "morgan": "^1.12.0", + "supercluster": "~9.0.0" }, "apiDrift": { "packages": [ @@ -2504,5 +2550,26 @@ } } } + }, + "workspaces": [ + "server" + ], + "lint-staged": { + "*.{js,jsx}": [ + "eslint --fix", + "prettier --write" + ], + "*.{css,md,json}": "prettier --write" + }, + "overrides": { + "axios": "^1.18.0", + "js-yaml": "^4.3.2", + "nanoid": "^3.3.18", + "postcss": "^8.5.23", + "react-router": "^7.18.2", + "smol-toml": "^1.7.1", + "ws@8.20.1": "8.21.0", + "qs": "^6.16.0", + "body-parser": "^1.20.6" } } diff --git a/scripts/auto-patch-cve.js b/scripts/auto-patch-cve.js new file mode 100644 index 00000000..f35a3101 --- /dev/null +++ b/scripts/auto-patch-cve.js @@ -0,0 +1,585 @@ +#!/usr/bin/env node +// #599 — Automated CVE patch bot. +// +// 1. Parse GitHub Security Advisories affecting the installed npm tree: +// --source npm-audit (default) `npm audit --json` (GitHub Advisory DB) +// --source github GitHub REST /advisories?affects=... (GITHUB_TOKEN +// recommended; gives first_patched_version directly) +// --advisories offline fixture: GitHub REST array or npm audit JSON +// 2. Plan the MINIMUM patched version for every vulnerable name@version in +// package-lock.json: the lowest published, non-prerelease, non-deprecated +// version above the installed one that no known advisory matches +// (same major preferred; a major bump is flagged as breaking). +// direct deps (package.json / server/package.json) -> bump the range +// transitive deps -> root `overrides`: +// `"name": "^patched"` floor when every installed copy shares the +// patched major, else `"name@": "patched"` (other majors +// untouched) +// 3. --apply: write manifests, `npm install`, re-audit, then run the full +// regression suite (`--verify `, repeatable; default `npm test`). +// Any failure restores package.json / server/package.json / lockfile. +// 4. --open-pr: commit on a `security/cve-patch-*` branch, push and open a PR +// (via `gh`) listing every advisory, the version moves and verification. +// +// Usage: +// node scripts/auto-patch-cve.js [--source npm-audit|github] [--advisories ] +// [--min-severity low|moderate|high|critical] [--fail-on ] +// [--apply] [--verify ""]... [--open-pr] [--base main] +// [--allow-major] [--offline] [--json] +// Without --apply it only prints the plan (dry run). +// +// Zero runtime dependencies (node built-ins + npm/git/gh CLIs). + +import fs from "node:fs"; +import path from "node:path"; +import { spawnSync } from "node:child_process"; +import { fileURLToPath } from "node:url"; + +const REPO_ROOT = path.resolve( + path.dirname(fileURLToPath(import.meta.url)), + "..", +); +const MANIFESTS = ["package.json", "server/package.json"]; +const DEP_FIELDS = ["dependencies", "devDependencies", "optionalDependencies"]; +const SEVERITIES = ["low", "moderate", "high", "critical"]; + +export const severityRank = (s) => { + const norm = String(s || "").toLowerCase() === "medium" ? "moderate" : String(s || "").toLowerCase(); + return SEVERITIES.indexOf(norm); +}; + +// ── Minimal semver (enough for advisory ranges) ────────────────────────── + +export function parseVersion(v) { + const m = /^v?(\d+)(?:\.(\d+))?(?:\.(\d+))?(?:-([0-9A-Za-z.-]+))?(?:\+.*)?$/.exec(String(v).trim()); + if (!m) return null; + return { major: +m[1], minor: +(m[2] || 0), patch: +(m[3] || 0), pre: m[4] || "" }; +} + +export function compareVersions(a, b) { + const x = parseVersion(a); + const y = parseVersion(b); + if (!x || !y) return String(a).localeCompare(String(b)); + for (const k of ["major", "minor", "patch"]) if (x[k] !== y[k]) return x[k] - y[k]; + if (x.pre === y.pre) return 0; + if (!x.pre) return 1; // release > prerelease + if (!y.pre) return -1; + return x.pre.localeCompare(y.pre, undefined, { numeric: true }); +} + +function expandComparator(tok) { + const m = /^(<=|>=|<|>|=|\^|~)?\s*v?(.+)$/.exec(tok); + const [, op = "=", ver] = m; + const p = parseVersion(ver); + if (!p) return []; + if (op === "^") { + const upper = p.major > 0 ? `${p.major + 1}.0.0` : p.minor > 0 ? `0.${p.minor + 1}.0` : `0.0.${p.patch + 1}`; + return [[">=", ver], ["<", `${upper}-0`]]; + } + if (op === "~") return [[">=", ver], ["<", `${p.major}.${p.minor + 1}.0-0`]]; + return [[op, ver]]; +} + +/** Parse an advisory range (GitHub ">= 1.0.0, < 1.2.3" or npm ">=1.0.0 <1.2.3", + * "1.0.0 - 1.2.2", "a || b", "*") into OR-ed sets of [op, version]. */ +export function parseRange(range) { + const r = String(range ?? "*").trim(); + return r.split("||").map((set) => { + const s = set.replace(/,/g, " ").trim(); + if (!s || s === "*" || s.toLowerCase() === "x") return []; + const hyphen = /^(\S+)\s+-\s+(\S+)$/.exec(s); + if (hyphen) return [[">=", hyphen[1]], ["<=", hyphen[2]]]; + const toks = s.replace(/(<=|>=|<|>|=|\^|~)\s+/g, "$1").split(/\s+/); + return toks.flatMap(expandComparator); + }); +} + +export function satisfies(version, range) { + return parseRange(range).some((set) => + set.every(([op, v]) => { + const c = compareVersions(version, v); + return op === "<" ? c < 0 : op === "<=" ? c <= 0 : op === ">" ? c > 0 : op === ">=" ? c >= 0 : c === 0; + }), + ); +} + +/** Exclusive upper bound (`< X`) of the range set that matches `version`. */ +export function upperBound(version, range) { + for (const set of parseRange(range)) { + if (!satisfies(version, set.map(([op, v]) => `${op}${v}`).join(" "))) continue; + const lt = set.find(([op]) => op === "<"); + if (lt) return lt[1]; + } + return null; +} + +// ── Advisory normalization ─────────────────────────────────────────────── + +/** GitHub REST `/advisories` (global advisories) response -> advisories. */ +export function normalizeGithubAdvisories(list) { + const out = []; + for (const adv of list || []) { + for (const v of adv.vulnerabilities || []) { + if (v.package?.ecosystem && v.package.ecosystem.toLowerCase() !== "npm") continue; + const patched = typeof v.first_patched_version === "string" + ? v.first_patched_version + : v.first_patched_version?.identifier; + out.push({ + id: adv.ghsa_id, + cve: adv.cve_id || null, + package: v.package?.name, + severity: (adv.severity || "unknown").toLowerCase(), + range: v.vulnerable_version_range, + firstPatched: patched || null, + url: adv.html_url || `https://github.com/advisories/${adv.ghsa_id}`, + title: adv.summary || "", + }); + } + } + return dedupeAdvisories(out); +} + +/** `npm audit --json` (v7+) -> advisories. Only concrete `via` objects carry + * advisory data; string `via` entries just point at another package. */ +export function normalizeNpmAudit(report) { + const out = []; + for (const vuln of Object.values(report?.vulnerabilities || {})) { + for (const via of vuln.via || []) { + if (typeof via !== "object") continue; + const ghsa = /GHSA-[\w-]+/.exec(via.url || "")?.[0]; + out.push({ + id: ghsa || String(via.source), + cve: null, + package: via.name, + severity: (via.severity || "unknown").toLowerCase(), + range: via.range, + firstPatched: null, + url: via.url, + title: via.title || "", + }); + } + } + return dedupeAdvisories(out); +} + +function dedupeAdvisories(list) { + const seen = new Map(); + for (const a of list) if (a.package && a.range) seen.set(`${a.id}:${a.package}:${a.range}`, a); + return [...seen.values()]; +} + +// ── Planning ───────────────────────────────────────────────────────────── + +/** name -> manifest files declaring it directly. */ +export function directDeps(manifests) { + const map = new Map(); + for (const [file, pkg] of Object.entries(manifests)) { + for (const field of DEP_FIELDS) { + for (const name of Object.keys(pkg?.[field] || {})) { + if (!map.has(name)) map.set(name, []); + map.get(name).push(file); + } + } + } + return map; +} + +/** Installed name@version occurrences from package-lock.json. */ +export function collectInstalled(lock) { + const out = []; + for (const [p, meta] of Object.entries(lock.packages || {})) { + const idx = p.lastIndexOf("node_modules/"); + if (idx === -1 || meta.link || !meta.version) continue; + const name = p.slice(idx + "node_modules/".length); + // Hoisted into a top-level node_modules (root or workspace) => may be direct. + const hoisted = idx === 0 || !p.slice(0, idx).includes("node_modules/"); + out.push({ name, version: meta.version, path: p, hoisted }); + } + return out; +} + +/** Pick the minimum safe version above `version`. */ +export function pickPatchedVersion(version, matching, allForPkg, published) { + const isVulnerable = (v) => allForPkg.some((a) => satisfies(v, a.range)); + if (published && published.length) { + const ok = published + .filter((v) => { + const p = parseVersion(v); + return p && !p.pre && compareVersions(v, version) > 0 && !isVulnerable(v); + }) + .sort(compareVersions); + const major = parseVersion(version)?.major; + const sameMajor = ok.find((v) => parseVersion(v).major === major); + const to = sameMajor || ok[0]; + return to ? { to, breaking: !sameMajor } : null; + } + const bounds = matching.map((a) => a.firstPatched || upperBound(version, a.range)); + if (bounds.some((b) => !b)) return null; // e.g. "<= X": needs the published list + const to = bounds.sort(compareVersions).at(-1); + if (isVulnerable(to)) return null; + return { to, breaking: parseVersion(to).major !== parseVersion(version).major }; +} + +/** + * Build the patch plan. + * @param versionsOf async (name) => string[] | null published versions + */ +export async function planPatches({ lock, manifests, advisories, versionsOf = async () => null, allowMajor = false }) { + const direct = directDeps(manifests); + const byPkg = new Map(); + for (const a of advisories) { + if (!byPkg.has(a.package)) byPkg.set(a.package, []); + byPkg.get(a.package).push(a); + } + + // Majors of every installed copy, to decide whether a name-level override + // floor is safe (it would otherwise drag other majors along). + const majors = new Map(); + for (const occ of collectInstalled(lock)) { + if (!majors.has(occ.name)) majors.set(occ.name, new Set()); + majors.get(occ.name).add(parseVersion(occ.version)?.major); + } + + const seen = new Set(); + const patches = []; + const unresolved = []; + for (const occ of collectInstalled(lock)) { + const allForPkg = byPkg.get(occ.name); + if (!allForPkg) continue; + const matching = allForPkg.filter((a) => satisfies(occ.version, a.range)); + if (!matching.length) continue; + const isDirect = occ.hoisted && direct.has(occ.name); + const key = `${occ.name}@${occ.version}:${isDirect}`; + if (seen.has(key)) continue; + seen.add(key); + + const sortedAdvs = [...new Map(matching.map((a) => [a.id, a])).values()].sort((a, b) => a.id.localeCompare(b.id)); + const base = { + name: occ.name, + from: occ.version, + advisories: sortedAdvs.map((a) => a.id), + severity: matching.map((a) => a.severity).sort((x, y) => severityRank(y) - severityRank(x))[0], + urls: sortedAdvs.map((a) => a.url || ""), + }; + const needsRegistry = matching.some((a) => !a.firstPatched && !upperBound(occ.version, a.range)); + const published = needsRegistry || !matching.every((a) => a.firstPatched) + ? await versionsOf(occ.name) + : null; + const pick = pickPatchedVersion(occ.version, matching, allForPkg, published); + if (!pick) { + unresolved.push({ ...base, reason: "no published non-vulnerable version found" }); + continue; + } + if (pick.breaking && !allowMajor) { + unresolved.push({ ...base, to: pick.to, reason: `fix requires a major bump to ${pick.to} (re-run with --allow-major)` }); + continue; + } + patches.push({ + ...base, + to: pick.to, + breaking: pick.breaking, + strategy: isDirect ? "manifest" : "override", + manifests: isDirect ? direct.get(occ.name) : ["package.json"], + singleMajor: [...majors.get(occ.name)].every((m) => m === parseVersion(pick.to).major), + }); + } + const order = (p) => [-severityRank(p.severity), p.name, p.from]; + const cmp = (a, b) => { + const [x, y] = [order(a), order(b)]; + return x[0] - y[0] || x[1].localeCompare(y[1]) || compareVersions(x[2], y[2]); + }; + return { patches: patches.sort(cmp), unresolved: unresolved.sort(cmp) }; +} + +/** Apply a plan to manifest objects (returns new objects + skipped patches). */ +export function applyPlan(manifests, plan) { + const next = structuredClone(manifests); + const applied = []; + const skipped = []; + for (const patch of plan.patches) { + if (patch.strategy === "manifest") { + let ok = false; + for (const file of patch.manifests) { + for (const field of DEP_FIELDS) { + const spec = next[file]?.[field]?.[patch.name]; + if (spec === undefined) continue; + const bare = spec.replace(/^[\^~]/, ""); + if (!parseVersion(bare) && !/^[<>=\s\d.x*|^~-]+$/.test(spec)) continue; // git/file/workspace specs + const prefix = /^[\^~]/.exec(spec)?.[0] ?? (parseVersion(spec) ? "" : "^"); + next[file][field][patch.name] = `${prefix}${patch.to}`; + ok = true; + } + } + (ok ? applied : skipped).push(ok ? patch : { ...patch, reason: "non-semver dependency spec" }); + } else { + const root = next["package.json"]; + root.overrides ||= {}; + const existing = root.overrides[patch.name]; + const ours = typeof existing === "string" && existing.startsWith("^") && parseVersion(existing.slice(1)); + if (existing !== undefined && !ours) { + skipped.push({ ...patch, reason: `existing override for ${patch.name}` }); + continue; + } + if (patch.singleMajor) { + // Name-level floor: npm reliably re-resolves every copy below it. + // (A version-keyed override leaves hoisted copies that still satisfy + // their dependents' ranges untouched.) Keep the highest floor when + // several vulnerable versions of one package are patched. + const floor = ours && compareVersions(existing.slice(1), patch.to) > 0 ? existing : `^${patch.to}`; + root.overrides[patch.name] = floor; + } else { + root.overrides[`${patch.name}@${patch.from}`] = patch.to; + } + applied.push(patch); + } + } + return { manifests: next, applied, skipped }; +} + +/** Lockfile occurrences of patched packages that still match an advisory. */ +export function residualVulnerable(lock, advisories, applied) { + const names = new Set(applied.map((p) => p.name)); + return collectInstalled(lock).filter( + (o) => names.has(o.name) && advisories.some((a) => a.package === o.name && satisfies(o.version, a.range)), + ); +} + +export function renderPrBody({ applied, skipped = [], unresolved = [], verification = [] }) { + const row = (p) => + `| \`${p.name}\` | ${p.from} → **${p.to}**${p.breaking ? " ⚠️ major" : ""} | ${p.severity} | ${p.strategy} | ${p.advisories + .map((id, i) => (p.urls[i] ? `[${id}](${p.urls[i]})` : id)) + .join(", ")} |`; + const lines = [ + "## Automated security patch (CVE patch bot, #599)", + "", + `Patches **${applied.length}** vulnerable dependency version(s) to the minimum non-vulnerable release.`, + "", + "| Package | Version | Severity | Strategy | Advisories |", + "| --- | --- | --- | --- | --- |", + ...applied.map(row), + "", + "### Regression verification", + "", + ...(verification.length + ? verification.map((v) => `- ${v.ok ? "✅" : "❌"} \`${v.cmd}\``) + : ["- not run"]), + ]; + if (skipped.length || unresolved.length) { + lines.push("", "### Needs manual follow-up", ""); + for (const p of [...skipped, ...unresolved]) + lines.push(`- \`${p.name}@${p.from}\` (${p.advisories.join(", ")}): ${p.reason}`); + } + lines.push( + "", + "Strategy `manifest` bumps a direct dependency range; `override` raises a transitive dependency via root `overrides` (a `^patched` floor when every installed copy shares that major, otherwise keyed by the exact vulnerable version). See `docs/security-runbook.md`.", + ); + return lines.join("\n") + "\n"; +} + +// ── I/O ────────────────────────────────────────────────────────────────── + +const readJson = (rel) => JSON.parse(fs.readFileSync(path.join(REPO_ROOT, rel), "utf8")); + +function npmAudit() { + // npm audit exits 1 when vulnerabilities exist; the JSON is still on stdout. + const res = spawnSync("npm", ["audit", "--json", "--package-lock-only"], { + cwd: REPO_ROOT, + encoding: "utf8", + maxBuffer: 64 * 1024 * 1024, + }); + if (!res.stdout) throw new Error(`npm audit produced no output: ${res.stderr?.slice(0, 300)}`); + const report = JSON.parse(res.stdout); + if (report.error) throw new Error(`npm audit: ${report.error.summary || report.error.code}`); + return normalizeNpmAudit(report); +} + +async function githubAdvisories(lock) { + const token = process.env.GITHUB_TOKEN || process.env.GH_TOKEN; + const pkgs = [...new Set(collectInstalled(lock).map((o) => `${o.name}@${o.version}`))]; + const out = []; + for (let i = 0; i < pkgs.length; i += 100) { + const affects = pkgs.slice(i, i + 100).join(","); + let url = `https://api.github.com/advisories?ecosystem=npm&per_page=100&affects=${encodeURIComponent(affects)}`; + while (url) { + const res = await fetch(url, { + headers: { + Accept: "application/vnd.github+json", + "X-GitHub-Api-Version": "2022-11-28", + ...(token ? { Authorization: `Bearer ${token}` } : {}), + }, + signal: AbortSignal.timeout(20_000), + }); + if (!res.ok) throw new Error(`GitHub advisories API ${res.status}`); + out.push(...(await res.json())); + url = /<([^>]+)>;\s*rel="next"/.exec(res.headers.get("link") || "")?.[1]; + } + } + return normalizeGithubAdvisories(out); +} + +function loadAdvisoryFile(file) { + const data = JSON.parse(fs.readFileSync(path.resolve(file), "utf8")); + return Array.isArray(data) ? normalizeGithubAdvisories(data) : normalizeNpmAudit(data); +} + +function registryVersions(offline) { + const cache = new Map(); + return async (name) => { + if (offline) return null; + if (!cache.has(name)) { + cache.set(name, (async () => { + try { + const res = await fetch(`https://registry.npmjs.org/${name.replace("/", "%2F")}`, { + headers: { Accept: "application/vnd.npm.install-v1+json" }, + signal: AbortSignal.timeout(15_000), + }); + if (!res.ok) return null; + const doc = await res.json(); + return Object.entries(doc.versions || {}).filter(([, m]) => !m.deprecated).map(([v]) => v); + } catch { + return null; + } + })()); + } + return cache.get(name); + }; +} + +function run(cmd, args, opts = {}) { + console.log(`$ ${[cmd, ...args].join(" ")}`); + const res = spawnSync(cmd, args, { cwd: REPO_ROOT, stdio: "inherit", ...opts }); + return res.status === 0; +} + +function printPlan(plan) { + console.log(`cve-patch: ${plan.patches.length} patch(es), ${plan.unresolved.length} unresolved`); + for (const p of plan.patches) + console.log( + ` [${p.severity}] ${p.name} ${p.from} -> ${p.to}${p.breaking ? " (MAJOR)" : ""} via ${p.strategy} (${p.advisories.join(", ")})`, + ); + for (const p of plan.unresolved) + console.log(` [${p.severity}] ${p.name}@${p.from}: UNRESOLVED — ${p.reason} (${p.advisories.join(", ")})`); +} + +async function main() { + const args = process.argv.slice(2); + const getArg = (flag, def) => { + const i = args.indexOf(flag); + return i !== -1 ? args[i + 1] : def; + }; + const getAll = (flag) => args.flatMap((a, i) => (a === flag ? [args[i + 1]] : [])); + const source = getArg("--source", "npm-audit"); + const minSeverity = getArg("--min-severity", "low"); + const failOn = getArg("--fail-on"); + const openPr = args.includes("--open-pr"); + const apply = args.includes("--apply") || openPr; + const offline = args.includes("--offline"); + const verifyCmds = getAll("--verify"); + if (!verifyCmds.length) verifyCmds.push("npm test"); + + const lock = readJson("package-lock.json"); + const manifests = Object.fromEntries( + MANIFESTS.filter((f) => fs.existsSync(path.join(REPO_ROOT, f))).map((f) => [f, readJson(f)]), + ); + + let advisories; + try { + const file = getArg("--advisories"); + advisories = file ? loadAdvisoryFile(file) : source === "github" ? await githubAdvisories(lock) : npmAudit(); + } catch (e) { + console.error(`cve-patch: advisory lookup failed: ${e.message}`); + process.exit(2); + } + advisories = advisories.filter((a) => severityRank(a.severity) >= severityRank(minSeverity)); + + const plan = await planPatches({ + lock, + manifests, + advisories, + versionsOf: registryVersions(offline), + allowMajor: args.includes("--allow-major"), + }); + if (args.includes("--json")) console.log(JSON.stringify(plan, null, 2)); + else printPlan(plan); + + const failing = failOn + ? [...plan.patches, ...plan.unresolved].filter((p) => severityRank(p.severity) >= severityRank(failOn)) + : []; + + if (!apply || plan.patches.length === 0) { + if (failing.length) { + console.error(`cve-patch: FAIL — ${failing.length} vulnerable package(s) at or above '${failOn}'`); + process.exit(1); + } + return; + } + + // ── Apply + regression verification ── + const tracked = [...Object.keys(manifests), "package-lock.json"]; + const backup = Object.fromEntries(tracked.map((f) => [f, fs.readFileSync(path.join(REPO_ROOT, f), "utf8")])); + const restore = () => { + for (const [f, body] of Object.entries(backup)) fs.writeFileSync(path.join(REPO_ROOT, f), body); + console.error("cve-patch: restored package.json / server/package.json / package-lock.json"); + }; + + const result = applyPlan(manifests, plan); + for (const [f, pkg] of Object.entries(result.manifests)) + fs.writeFileSync(path.join(REPO_ROOT, f), JSON.stringify(pkg, null, 2) + "\n"); + + if (!run("npm", ["install", "--ignore-scripts", "--no-audit", "--no-fund"])) { + restore(); + process.exit(1); + } + + const verification = []; + const residual = residualVulnerable(readJson("package-lock.json"), advisories, result.applied); + for (const r of residual) console.warn(`cve-patch: WARN ${r.name}@${r.version} still vulnerable in lockfile (${r.path})`); + verification.push({ cmd: "package-lock.json re-resolved to patched versions", ok: residual.length === 0 }); + if (source === "npm-audit" && !getArg("--advisories")) { + const remaining = new Set(npmAudit().map((a) => `${a.package}:${a.id}`)); + const still = result.applied.filter((p) => p.advisories.some((id) => remaining.has(`${p.name}:${id}`))); + for (const p of still) console.warn(`cve-patch: WARN ${p.name} still reported after patch (another copy?)`); + verification.push({ cmd: "npm audit (patched advisories cleared)", ok: still.length === 0 }); + } + for (const cmd of verifyCmds) { + const ok = run("sh", ["-c", cmd]); + verification.push({ cmd, ok }); + if (!ok) { + console.error(`cve-patch: regression verification failed: ${cmd}`); + restore(); + run("npm", ["install", "--ignore-scripts", "--no-audit", "--no-fund"]); + process.exit(1); + } + } + + const body = renderPrBody({ ...result, unresolved: plan.unresolved, verification }); + const bodyFile = path.join(REPO_ROOT, ".cve-patch-pr.md"); + fs.writeFileSync(bodyFile, body); + console.log(`cve-patch: applied ${result.applied.length} patch(es); PR body -> .cve-patch-pr.md`); + + if (openPr) { + const base = getArg("--base", "main"); + const stamp = new Date().toISOString().slice(0, 10); + const branch = `security/cve-patch-${stamp}-${process.env.GITHUB_RUN_ID || process.pid}`; + const title = `fix(security): patch ${result.applied.length} vulnerable dependenc${result.applied.length === 1 ? "y" : "ies"}`; + const ok = + run("git", ["checkout", "-b", branch]) && + run("git", ["add", ...tracked]) && + run("git", ["commit", "-m", title, "-m", "Automated by scripts/auto-patch-cve.js (#599)."]) && + run("git", ["push", "-u", "origin", branch]) && + run("gh", ["pr", "create", "--base", base, "--head", branch, "--title", title, "--body-file", bodyFile]); + fs.rmSync(bodyFile, { force: true }); + if (!ok) { + console.error("cve-patch: failed to open the security PR"); + process.exit(1); + } + } +} + +const isMain = process.argv[1] === fileURLToPath(import.meta.url); +if (isMain) { + main().catch((e) => { + console.error(`cve-patch: ${e.stack || e.message}`); + process.exit(2); + }); +} diff --git a/scripts/license-compliance.js b/scripts/license-compliance.js new file mode 100644 index 00000000..7aa6eb54 --- /dev/null +++ b/scripts/license-compliance.js @@ -0,0 +1,387 @@ +#!/usr/bin/env node +// #586 — Dependency license compliance & copyleft legal gate (npm + Cargo). +// +// Extracts license metadata for every direct and transitive dependency: +// - npm: package-lock.json (`license` field; falls back to the installed +// node_modules//package.json, the same source license-checker +// reads). +// - Cargo: `cargo metadata` for each Cargo workspace (root + contract/). +// Each license is evaluated as a full SPDX expression (`OR` picks the most +// permissive branch, `AND` the most restrictive), then: +// - approved permissive licenses compatible with the MIT/Apache-2.0 codebase +// - review weak copyleft / unknown / non-SPDX: warns (fails with --strict) +// - denied strong or network copyleft (GPL, AGPL, SSPL, EUPL, ...): FAILS +// unless the package is listed in LICENSE_EXCEPTIONS. +// Writes `licenses.json`, the attribution manifest shipped with release builds. +// +// Usage: +// node scripts/license-compliance.js [--out ] [--no-write] [--check] +// [--strict] [--skip-cargo] [--json] +// --check fail if the committed licenses.json is stale (CI freshness gate) +// +// Zero runtime dependencies (node built-ins only). + +import fs from "node:fs"; +import path from "node:path"; +import { execFileSync } from "node:child_process"; +import { fileURLToPath } from "node:url"; + +const REPO_ROOT = path.resolve( + path.dirname(fileURLToPath(import.meta.url)), + "..", +); + +// Cargo workspaces to scan, relative to the repo root. +const CARGO_WORKSPACES = ["Cargo.toml", "contract/Cargo.toml"]; + +export const APPROVED = new Set([ + "MIT", + "MIT-0", + "ISC", + "Apache-2.0", + "BSD-2-Clause", + "BSD-3-Clause", + "0BSD", + "BlueOak-1.0.0", + "CC0-1.0", + "CC-BY-3.0", + "CC-BY-4.0", + "Unlicense", + "Zlib", + "BSL-1.0", + "Python-2.0", + "Unicode-3.0", + "Unicode-DFS-2016", + "WTFPL", +]); + +// Strong / network copyleft — incompatible with shipping a permissive codebase. +export const DENIED_RE = + /^(A?GPL|SSPL|EUPL|OSL|RPL|CPAL|Sleepycat|CC-BY-(NC|SA|ND)|CC-BY-NC-SA|CC-BY-NC-ND)(-|$)/i; + +// Pre-existing, legally reviewed exceptions: name -> justification. The gate +// passes on the current tree but still fails on any NEW denied license. +// Do not extend without legal review (docs/legal-compliance.md). +export const LICENSE_EXCEPTIONS = { + "npm:@lobstrco/signer-extension-api": + "GPL-3.0 via @creit-tech/stellar-wallets-kit; browser-extension messaging shim, tracked for replacement (#625)", +}; + +const RANK = { approved: 0, review: 1, denied: 2 }; +const worst = (a, b) => (RANK[a] >= RANK[b] ? a : b); +const best = (a, b) => (RANK[a] <= RANK[b] ? a : b); + +// Common non-SPDX spellings seen in package metadata. +const ALIASES = { + "APACHE 2.0": "Apache-2.0", + "APACHE2": "Apache-2.0", + "APACHE-2": "Apache-2.0", + "APACHE LICENSE 2.0": "Apache-2.0", + "APACHE LICENSE, VERSION 2.0": "Apache-2.0", + "MIT/X11": "MIT", + "X11": "MIT", + "BSD-3": "BSD-3-Clause", + "NEW BSD": "BSD-3-Clause", + "SIMPLIFIED BSD": "BSD-2-Clause", + "PUBLIC DOMAIN": "Unlicense", +}; + +/** Normalize a single license id (strip license-checker's `*` guess marker). */ +export function normalizeId(id) { + const trimmed = String(id).trim().replace(/\*$/, ""); + return ALIASES[trimmed.toUpperCase()] || trimmed; +} + +/** Classify one SPDX license id (optionally carrying a `WITH` exception). */ +export function classifyId(id, exception) { + const norm = normalizeId(id).replace(/\+$/, ""); + if (DENIED_RE.test(norm)) return exception ? "review" : "denied"; + if (APPROVED.has(norm)) return "approved"; + return "review"; // LGPL, MPL, EPL, CDDL, unknown, ... +} + +function tokenize(expr) { + return ( + expr + .replace(/[()]/g, " $& ") + // license-checker/old npm style "MIT/Apache-2.0" means OR + .replace(/\s*\/\s*/g, " OR ") + .split(/\s+/) + .filter(Boolean) + ); +} + +/** Evaluate an SPDX expression to approved | review | denied. + * OR binds looser than AND; `WITH` attaches an exception to the id. */ +export function classifyExpression(expr) { + if (!expr || typeof expr !== "string") return "review"; + const raw = expr.trim(); + if (!raw || /^(UNKNOWN|UNLICENSED|NONE)$/i.test(raw) || /^SEE LICENSE/i.test(raw)) { + return "review"; + } + if (ALIASES[raw.toUpperCase()]) return classifyId(raw); + const tokens = tokenize(raw); + let i = 0; + const parseOr = () => { + let res = parseAnd(); + while (tokens[i] && tokens[i].toUpperCase() === "OR") { + i++; + res = best(res, parseAnd()); + } + return res; + }; + const parseAnd = () => { + let res = parseAtom(); + while (tokens[i] && tokens[i].toUpperCase() === "AND") { + i++; + res = worst(res, parseAtom()); + } + return res; + }; + const parseAtom = () => { + const tok = tokens[i++]; + if (tok === undefined) return "review"; + if (tok === "(") { + const res = parseOr(); + if (tokens[i] === ")") i++; + return res; + } + if (tokens[i] && tokens[i].toUpperCase() === "WITH") { + i++; + return classifyId(tok, tokens[i++]); + } + return classifyId(tok); + }; + const result = parseOr(); + return i < tokens.length ? "review" : result; // trailing junk -> review +} + +function licenseFromPkgJson(pkg) { + if (typeof pkg.license === "string") return pkg.license; + if (pkg.license?.type) return pkg.license.type; + if (Array.isArray(pkg.licenses)) { + const ids = pkg.licenses.map((l) => (typeof l === "string" ? l : l?.type)).filter(Boolean); + if (ids.length) return ids.length > 1 ? `(${ids.join(" OR ")})` : ids[0]; + } + return undefined; +} + +function repoUrl(repository) { + const url = typeof repository === "string" ? repository : repository?.url; + return url ? url.replace(/^git\+/, "").replace(/\.git$/, "") : undefined; +} + +/** Collect npm dependencies from a lockfile (v2/v3). Workspace links and the + * root project are skipped — they are our own code. */ +export function collectNpm(lock, readInstalled = () => null) { + const out = []; + for (const [p, meta] of Object.entries(lock.packages || {})) { + if (!p.startsWith("node_modules/") || meta.link) continue; + const name = p.slice(p.lastIndexOf("node_modules/") + "node_modules/".length); + const installed = readInstalled(p); + const license = meta.license || (installed && licenseFromPkgJson(installed)) || "UNKNOWN"; + out.push({ + ecosystem: "npm", + name, + version: meta.version || installed?.version || "?", + license, + dev: Boolean(meta.dev), + repository: repoUrl(installed?.repository), + }); + } + return dedupe(out); +} + +/** Collect third-party crates from `cargo metadata --format-version 1`. */ +export function collectCargo(metadata) { + return dedupe( + (metadata.packages || []) + .filter((p) => p.source) // path/workspace crates have no source + .map((p) => ({ + ecosystem: "cargo", + name: p.name, + version: p.version, + license: p.license || (p.license_file ? `SEE LICENSE IN ${p.license_file}` : "UNKNOWN"), + dev: false, + repository: p.repository || undefined, + })), + ); +} + +function dedupe(list) { + const seen = new Map(); + for (const d of list) { + const key = `${d.ecosystem}:${d.name}@${d.version}`; + const prev = seen.get(key); + // A package is only dev-only if every occurrence is dev-only. + if (prev) prev.dev = prev.dev && d.dev; + else seen.set(key, { ...d }); + } + return [...seen.values()]; +} + +/** Classify every dependency and split out the violations. */ +export function evaluate(deps, exceptions = LICENSE_EXCEPTIONS) { + const packages = deps + .map((d) => { + let category = classifyExpression(d.license); + const exception = exceptions[`${d.ecosystem}:${d.name}`]; + if (category === "denied" && exception) category = "excepted"; + return { ...d, category, ...(category === "excepted" ? { exception } : {}) }; + }) + .sort((a, b) => + a.ecosystem.localeCompare(b.ecosystem) || + a.name.localeCompare(b.name) || + a.version.localeCompare(b.version), + ); + return { + packages, + denied: packages.filter((p) => p.category === "denied"), + review: packages.filter((p) => p.category === "review"), + excepted: packages.filter((p) => p.category === "excepted"), + }; +} + +/** Build the licenses.json attribution manifest (deterministic: no + * timestamps, so CI can diff it for freshness). */ +export function buildManifest(result) { + const count = (eco, cat) => + result.packages.filter((p) => (!eco || p.ecosystem === eco) && (!cat || p.category === cat)).length; + const byLicense = {}; + for (const p of result.packages) byLicense[p.license] = (byLicense[p.license] || 0) + 1; + return { + $comment: + "Auto-generated by scripts/license-compliance.js (#586). Do not edit by hand; run `npm run licenses:generate`.", + policy: { + projectLicenses: ["MIT", "Apache-2.0"], + approved: [...APPROVED].sort(), + denied: "strong/network copyleft: GPL, AGPL, SSPL, EUPL, OSL, RPL, CPAL, Sleepycat, CC-BY-NC/SA/ND", + review: "weak copyleft (LGPL, MPL, EPL, CDDL) and unrecognised licenses", + exceptions: LICENSE_EXCEPTIONS, + }, + summary: { + total: result.packages.length, + npm: count("npm"), + cargo: count("cargo"), + approved: count(null, "approved"), + review: count(null, "review"), + excepted: count(null, "excepted"), + denied: count(null, "denied"), + byLicense: Object.fromEntries(Object.entries(byLicense).sort(([a], [b]) => a.localeCompare(b))), + }, + packages: result.packages.map((p) => { + const entry = { + ecosystem: p.ecosystem, + name: p.name, + version: p.version, + license: p.license, + category: p.category, + }; + if (p.dev) entry.dev = true; + if (p.repository) entry.repository = p.repository; + if (p.exception) entry.exception = p.exception; + return entry; + }), + }; +} + +function readInstalledPkg(lockPath) { + try { + return JSON.parse(fs.readFileSync(path.join(REPO_ROOT, lockPath, "package.json"), "utf8")); + } catch { + return null; + } +} + +function cargoMetadata(manifest) { + const run = (extra) => + execFileSync( + "cargo", + ["metadata", "--format-version", "1", "--locked", "--manifest-path", manifest, ...extra], + { encoding: "utf8", maxBuffer: 256 * 1024 * 1024, stdio: ["ignore", "pipe", "pipe"] }, + ); + try { + return JSON.parse(run(["--offline"])); + } catch { + return JSON.parse(run([])); // registry index not cached yet + } +} + +function main() { + const args = process.argv.slice(2); + const getArg = (flag) => { + const i = args.indexOf(flag); + return i !== -1 ? args[i + 1] : undefined; + }; + const outPath = path.resolve(REPO_ROOT, getArg("--out") || "licenses.json"); + const strict = args.includes("--strict"); + const check = args.includes("--check"); + const noWrite = args.includes("--no-write") || check; + const skipCargo = args.includes("--skip-cargo"); + const asJson = args.includes("--json"); + + const lock = JSON.parse(fs.readFileSync(path.join(REPO_ROOT, "package-lock.json"), "utf8")); + const deps = collectNpm(lock, readInstalledPkg); + + if (!skipCargo) { + for (const rel of CARGO_WORKSPACES) { + const manifest = path.join(REPO_ROOT, rel); + if (!fs.existsSync(manifest)) continue; + try { + deps.push(...collectCargo(cargoMetadata(manifest))); + } catch (e) { + console.error(`license-compliance: cargo metadata failed for ${rel}: ${e.message.split("\n")[0]}`); + console.error("license-compliance: install Rust or pass --skip-cargo (npm-only scan)"); + process.exit(2); + } + } + } + + const result = evaluate(dedupe(deps)); + const manifest = buildManifest(result); + const serialized = JSON.stringify(manifest, null, 2) + "\n"; + + if (check) { + const current = fs.existsSync(outPath) ? fs.readFileSync(outPath, "utf8") : ""; + if (current !== serialized) { + console.error( + `license-compliance: ${path.relative(REPO_ROOT, outPath)} is stale — run \`npm run licenses:generate\` and commit it`, + ); + process.exitCode = 1; + } + } + if (!noWrite) fs.writeFileSync(outPath, serialized); + + if (asJson) { + console.log(JSON.stringify(manifest.summary, null, 2)); + } else { + const s = manifest.summary; + console.log( + `license-compliance: ${s.total} packages (npm ${s.npm}, cargo ${s.cargo}) — ` + + `${s.approved} approved, ${s.review} review, ${s.excepted} excepted, ${s.denied} denied`, + ); + if (!noWrite) console.log(`license-compliance: attribution manifest -> ${path.relative(REPO_ROOT, outPath)}`); + for (const p of result.review.slice(0, 15)) + console.log(`REVIEW: ${p.ecosystem}:${p.name}@${p.version} (${p.license})`); + if (result.review.length > 15) console.log(`... and ${result.review.length - 15} more (see licenses.json)`); + for (const p of result.excepted) + console.log(`EXCEPTED: ${p.ecosystem}:${p.name}@${p.version} (${p.license}) — ${p.exception}`); + for (const p of result.denied) + console.error(`DENIED: ${p.ecosystem}:${p.name}@${p.version} (${p.license})${p.dev ? " [dev]" : ""}`); + } + + if (result.denied.length > 0) { + console.error( + `license-compliance: FAIL — ${result.denied.length} copyleft license(s) not approved for this permissive codebase (see docs/legal-compliance.md)`, + ); + process.exit(1); + } + if (strict && result.review.length > 0) { + console.error("license-compliance: FAIL (--strict: licenses pending review)"); + process.exit(1); + } + if (!process.exitCode) console.log("license-compliance: OK"); +} + +const isMain = process.argv[1] === fileURLToPath(import.meta.url); +if (isMain) main(); diff --git a/scripts/security/verify_maintainer_keys.js b/scripts/security/verify_maintainer_keys.js new file mode 100644 index 00000000..a8711b69 --- /dev/null +++ b/scripts/security/verify_maintainer_keys.js @@ -0,0 +1,652 @@ +#!/usr/bin/env node +// #619 — Maintainer key revocation & web-of-trust verification engine. +// +// Validates OpenPGP signatures on git commits, tags and release artifacts +// against LIVE key revocation data pulled from OpenPGP keyservers, so a +// release signed with a key that was later found to be compromised is caught +// even though the signature predates the revocation. +// +// Revocation semantics (RFC 4880 §5.2.3.23): +// - reason 0x00 (none) / 0x02 (key compromised): EVERY signature by the key +// is invalid, whenever it was made. +// - reason 0x01 (superseded) / 0x03 (retired): signatures made before the +// revocation time stay valid; later ones are invalid. +// Web of trust: a signer is trusted when its primary key is a trusted root in +// config/maintainer-keys.json or carries >= `minCertifications` valid, +// unrevoked third-party certifications from trusted roots. +// +// Everything is verified in-process (RFC 4880 packet parser + node:crypto for +// RSA, EdDSA/Ed25519 and ECDSA): no local gpg needed. Public keys are cached +// under .cache/maintainer-keys/ and refreshed after `cacheTtlHours`. +// +// Usage: +// node scripts/security/verify_maintainer_keys.js +// [--range ] [--tags []] [--pinned] +// [--artifact --signature ]... +// [--config ] [--max ] [--strict] [--offline] [--refresh] [--json] +// Defaults to `--pinned --range HEAD --max 50` when no target is given. +// Exit 1 on any FAIL (bad signature, compromised key, fingerprint mismatch); +// unsigned / untrusted / unknown-key findings WARN, and FAIL under --strict. + +import fs from "node:fs"; +import path from "node:path"; +import crypto from "node:crypto"; +import { execFileSync } from "node:child_process"; +import { fileURLToPath } from "node:url"; + +const REPO_ROOT = path.resolve(path.dirname(fileURLToPath(import.meta.url)), "..", ".."); + +// ── Armor / packets (RFC 4880 §4, §6) ──────────────────────────────────── + +/** Decode every ASCII-armored block in `text` (or pass binary through). */ +export function dearmor(input) { + if (Buffer.isBuffer(input) && input[0] & 0x80) return input; + const text = input.toString(); + const blocks = []; + const re = /-----BEGIN PGP [A-Z ]+-----\r?\n([\s\S]*?)-----END PGP [A-Z ]+-----/g; + let m; + while ((m = re.exec(text))) { + const lines = m[1].split(/\r?\n/); + const blank = lines.findIndex((l) => l.trim() === ""); + const body = lines + .slice(blank + 1) + .filter((l) => l && !l.startsWith("=")) + .join(""); + blocks.push(Buffer.from(body, "base64")); + } + return Buffer.concat(blocks); +} + +export function* readPackets(buf) { + let i = 0; + while (i < buf.length) { + const ctb = buf[i++]; + if (!(ctb & 0x80)) throw new Error(`invalid packet header at ${i - 1}`); + let tag; + let len; + if (ctb & 0x40) { + tag = ctb & 0x3f; + const o = buf[i++]; + if (o < 192) len = o; + else if (o < 224) len = ((o - 192) << 8) + buf[i++] + 192; + else if (o === 255) { + len = buf.readUInt32BE(i); + i += 4; + } else throw new Error("partial-length packets are not used in keys/signatures"); + } else { + tag = (ctb >> 2) & 0x0f; + const lt = ctb & 3; + if (lt === 0) len = buf[i++]; + else if (lt === 1) { + len = buf.readUInt16BE(i); + i += 2; + } else if (lt === 2) { + len = buf.readUInt32BE(i); + i += 4; + } else len = buf.length - i; + } + yield { tag, body: buf.subarray(i, i + len) }; + i += len; + } +} + +function readMpi(buf, off) { + const bits = buf.readUInt16BE(off); + const bytes = (bits + 7) >> 3; + return { value: buf.subarray(off + 2, off + 2 + bytes), next: off + 2 + bytes }; +} + +const b64url = (b) => Buffer.from(b).toString("base64url"); +const leftPad = (b, n) => (b.length >= n ? b.subarray(b.length - n) : Buffer.concat([Buffer.alloc(n - b.length), b])); +const hex = (b) => Buffer.from(b).toString("hex").toUpperCase(); + +const HASHES = { 1: "md5", 2: "sha1", 3: "ripemd160", 8: "sha256", 9: "sha384", 10: "sha512", 11: "sha224" }; +const OID = { + "2B06010401DA470F01": "Ed25519", + "2A8648CE3D030107": "P-256", + "2B81040022": "P-384", + "2B81040023": "P-521", +}; +const EC_SIZE = { "P-256": 32, "P-384": 48, "P-521": 66 }; + +/** Parse a v4 public (sub)key packet body. */ +export function parsePublicKey(body) { + const version = body[0]; + if (version !== 4) return { version, unsupported: `v${version} keys` }; + const created = body.readUInt32BE(1); + const algo = body[5]; + const fpr = hex(crypto.createHash("sha1").update(keyPrefix(body)).digest()); + const key = { version, created, algo, fingerprint: fpr, keyId: fpr.slice(-16), body }; + try { + if (algo === 1 || algo === 3) { + const n = readMpi(body, 6); + const e = readMpi(body, n.next); + key.publicKey = crypto.createPublicKey({ key: { kty: "RSA", n: b64url(n.value), e: b64url(e.value) }, format: "jwk" }); + } else if (algo === 22 || algo === 19) { + const oidLen = body[6]; + const curve = OID[hex(body.subarray(7, 7 + oidLen))]; + const point = readMpi(body, 7 + oidLen).value; + if (algo === 22 && curve === "Ed25519") { + key.publicKey = crypto.createPublicKey({ key: { kty: "OKP", crv: "Ed25519", x: b64url(point.subarray(1)) }, format: "jwk" }); + } else if (algo === 19 && EC_SIZE[curve]) { + const n = EC_SIZE[curve]; + key.publicKey = crypto.createPublicKey({ + key: { kty: "EC", crv: curve, x: b64url(point.subarray(1, 1 + n)), y: b64url(point.subarray(1 + n)) }, + format: "jwk", + }); + } + key.curve = curve; + } else if (algo === 27) { + key.publicKey = crypto.createPublicKey({ key: { kty: "OKP", crv: "Ed25519", x: b64url(body.subarray(6, 38)) }, format: "jwk" }); + } + } catch { + key.publicKey = undefined; + } + return key; +} + +function keyPrefix(body) { + const h = Buffer.alloc(3); + h[0] = 0x99; + h.writeUInt16BE(body.length, 1); + return Buffer.concat([h, body]); +} + +function readSubpackets(buf) { + const out = []; + let i = 0; + while (i < buf.length) { + let len = buf[i++]; + if (len >= 192 && len < 255) len = ((len - 192) << 8) + buf[i++] + 192; + else if (len === 255) { + len = buf.readUInt32BE(i); + i += 4; + } + out.push({ type: buf[i] & 0x7f, data: buf.subarray(i + 1, i + len) }); + i += len; + } + return out; +} + +/** Parse a v4 signature packet body. */ +export function parseSignature(body) { + const version = body[0]; + if (version !== 4) return { version, unsupported: `v${version} signatures` }; + const type = body[1]; + const pubAlgo = body[2]; + const hashAlgo = body[3]; + const hashedLen = body.readUInt16BE(4); + const hashedEnd = 6 + hashedLen; + const hashed = readSubpackets(body.subarray(6, hashedEnd)); + const unhashedLen = body.readUInt16BE(hashedEnd); + const unhashed = readSubpackets(body.subarray(hashedEnd + 2, hashedEnd + 2 + unhashedLen)); + let off = hashedEnd + 2 + unhashedLen; + const left16 = body.subarray(off, off + 2); + off += 2; + const sig = { version, type, pubAlgo, hashAlgo, hashedPart: body.subarray(0, hashedEnd), left16, body }; + if (pubAlgo === 27) sig.raw = body.subarray(off, off + 64); + else { + sig.mpis = []; + while (off < body.length) { + const m = readMpi(body, off); + sig.mpis.push(m.value); + off = m.next; + } + } + for (const sp of [...hashed, ...unhashed]) { + if (sp.type === 2 && sig.created === undefined) sig.created = sp.data.readUInt32BE(0); + if (sp.type === 3 && hashed.includes(sp)) sig.expiresIn = sp.data.readUInt32BE(0); + if (sp.type === 9 && hashed.includes(sp)) sig.keyExpiresIn = sp.data.readUInt32BE(0); + if (sp.type === 16 && !sig.issuerKeyId) sig.issuerKeyId = hex(sp.data); + if (sp.type === 33 && !sig.issuerFpr) sig.issuerFpr = hex(sp.data.subarray(1)); + if (sp.type === 29 && hashed.includes(sp)) { + sig.reasonCode = sp.data[0]; + sig.reasonText = sp.data.subarray(1).toString("utf8"); + } + } + if (!sig.issuerKeyId && sig.issuerFpr) sig.issuerKeyId = sig.issuerFpr.slice(-16); + return sig; +} + +/** Verify `sig` over `prefix` (the signed data) with `key`. true/false, or + * null when the algorithm is not supported. */ +export function verifySignature(sig, key, prefix) { + if (!key?.publicKey || sig.unsupported) return null; + const hashName = HASHES[sig.hashAlgo]; + if (!hashName || hashName === "md5") return null; + const trailer = Buffer.alloc(6); + trailer[0] = 0x04; + trailer[1] = 0xff; + trailer.writeUInt32BE(sig.hashedPart.length, 2); + const data = Buffer.concat([prefix, sig.hashedPart, trailer]); + const digest = crypto.createHash(hashName).update(data).digest(); + if (!digest.subarray(0, 2).equals(sig.left16)) return false; + try { + if (key.algo === 1 || key.algo === 3) { + const modLen = (key.publicKey.asymmetricKeyDetails.modulusLength + 7) >> 3; + return crypto.verify(hashName, data, key.publicKey, leftPad(sig.mpis[0], modLen)); + } + if (key.algo === 22 || key.algo === 27) { + const raw = sig.raw || Buffer.concat([leftPad(sig.mpis[0], 32), leftPad(sig.mpis[1], 32)]); + return crypto.verify(null, digest, key.publicKey, raw); + } + if (key.algo === 19) { + const n = EC_SIZE[key.curve]; + const rs = Buffer.concat([leftPad(sig.mpis[0], n), leftPad(sig.mpis[1], n)]); + return crypto.verify(hashName, data, { key: key.publicKey, dsaEncoding: "ieee-p1363" }, rs); + } + } catch { + return false; + } + return null; +} + +function uidPrefix(tag, body) { + const h = Buffer.alloc(5); + h[0] = tag === 17 ? 0xd1 : 0xb4; + h.writeUInt32BE(body.length, 1); + return Buffer.concat([h, body]); +} + +/** Parse transferable public keys (primary + UIDs + subkeys + signatures). + * Duplicate copies of one key (several keyservers) are merged. */ +export function parseKeys(input) { + const keys = new Map(); + let key = null; + let uid = null; + let sub = null; + for (const { tag, body } of readPackets(dearmor(input))) { + if (tag === 6) { + const k = parsePublicKey(body); + key = keys.get(k.fingerprint) || { ...k, uids: [], subkeys: [], revocations: [] }; + keys.set(k.fingerprint, key); + uid = sub = null; + } else if (!key) { + continue; + } else if (tag === 13 || tag === 17) { + const text = tag === 13 ? body.toString("utf8") : "[user attribute]"; + uid = key.uids.find((u) => u.body.equals(body)) || { tag, body, text, sigs: [] }; + if (!key.uids.includes(uid)) key.uids.push(uid); + sub = null; + } else if (tag === 14) { + const s = parsePublicKey(body); + sub = key.subkeys.find((x) => x.fingerprint === s.fingerprint) || { ...s, revocations: [] }; + if (!key.subkeys.includes(sub)) key.subkeys.push(sub); + uid = null; + } else if (tag === 2) { + const sig = parseSignature(body); + const primary = keyPrefix(key.body); + if (sig.type === 0x20) { + sig.verified = verifySignature(sig, key, primary); + key.revocations.push(sig); + } else if (sig.type === 0x28 && sub) { + sig.verified = verifySignature(sig, key, Buffer.concat([primary, keyPrefix(sub.body)])); + sub.revocations.push(sig); + } else if (uid && ((sig.type >= 0x10 && sig.type <= 0x13) || sig.type === 0x30)) { + sig.prefix = Buffer.concat([primary, uidPrefix(uid.tag, uid.body)]); + uid.sigs.push(sig); + } + } + } + return [...keys.values()]; +} + +// ── Policy ─────────────────────────────────────────────────────────────── + +export const REVOCATION_REASONS = { + 0: "no reason specified", + 1: "key superseded", + 2: "key compromised", + 3: "key retired", +}; + +const isSelfIssued = (sig, key) => + sig.issuerFpr ? sig.issuerFpr === key.fingerprint : sig.issuerKeyId === key.keyId; + +/** Effective revocation for a key (or the subkey `signingFpr`): the most + * severe self-issued revocation that verifies (or cannot be checked — a + * revocation is never ignored just because the algorithm is unsupported). */ +export function revocationOf(key, signingFpr) { + const candidates = [...key.revocations]; + const sub = key.subkeys.find((s) => s.fingerprint === signingFpr); + if (sub) candidates.push(...sub.revocations); + const valid = candidates.filter((r) => isSelfIssued(r, key) && r.verified !== false); + if (!valid.length) return null; + const severity = (r) => ([1, 3].includes(r.reasonCode) ? 0 : 1); + valid.sort((a, b) => severity(b) - severity(a) || a.created - b.created); + const r = valid[0]; + return { + time: r.created, + code: r.reasonCode ?? 0, + reason: REVOCATION_REASONS[r.reasonCode ?? 0] || `reason 0x${(r.reasonCode ?? 0).toString(16)}`, + text: r.reasonText || "", + subkey: sub && sub.revocations.includes(r) ? sub.fingerprint : null, + verified: r.verified, + }; +} + +/** Is a signature made at `sigTime` still valid given the key's revocation? */ +export function evaluateSignatureTime(revocation, sigTime) { + if (!revocation) return { valid: true }; + const soft = revocation.code === 1 || revocation.code === 3; + if (soft && sigTime < revocation.time) { + return { valid: true, note: `signed before the key was revoked (${revocation.reason})` }; + } + return { + valid: false, + reason: soft + ? `signed after the key was revoked (${revocation.reason})` + : `key revoked: ${revocation.reason}${revocation.text ? ` — "${revocation.text}"` : ""}; every signature by it is invalid`, + }; +} + +/** Web-of-trust decision for `key` against trusted root keys. */ +export function webOfTrust(key, trustedKeys, minCertifications = 1) { + const roots = new Map(trustedKeys.map((k) => [k.fingerprint, k])); + if (roots.has(key.fingerprint)) return { trusted: true, root: true, certifiers: [] }; + const certifiers = new Set(); + for (const uid of key.uids) { + for (const cert of uid.sigs) { + if (cert.type < 0x10 || cert.type > 0x13) continue; + const issuer = [...roots.values()].find((r) => (cert.issuerFpr ? r.fingerprint === cert.issuerFpr : r.keyId === cert.issuerKeyId)); + if (!issuer) continue; + const rootRev = revocationOf(issuer); + if (rootRev && !evaluateSignatureTime(rootRev, cert.created).valid) continue; + if (verifySignature(cert, issuer, cert.prefix) !== true) continue; + const revoked = uid.sigs.some( + (r) => + r.type === 0x30 && + (r.issuerFpr || r.issuerKeyId) && + (r.issuerFpr ? r.issuerFpr === issuer.fingerprint : r.issuerKeyId === issuer.keyId) && + r.created >= cert.created && + verifySignature(r, issuer, r.prefix) === true, + ); + if (!revoked) certifiers.add(issuer.fingerprint); + } + } + return { trusted: certifiers.size >= minCertifications, root: false, certifiers: [...certifiers] }; +} + +/** Find the key (primary or subkey) that issued `sig`. */ +export function findSigner(sig, keys) { + for (const key of keys) { + for (const k of [key, ...key.subkeys]) { + if (sig.issuerFpr ? k.fingerprint === sig.issuerFpr : k.keyId === sig.issuerKeyId) return { key, signing: k }; + } + } + return null; +} + +/** Verify a detached signature (git commit/tag payloads, release artifacts) + * and apply the revocation + web-of-trust policy. */ +export function verifyDetached({ data, signature, keys, trustedKeys = [], minCertifications = 1, label }) { + const pkt = [...readPackets(dearmor(signature))].find((p) => p.tag === 2); + if (!pkt) return finding(label, "fail", "no OpenPGP signature packet"); + const sig = parseSignature(pkt.body); + if (sig.unsupported) return finding(label, "warn", `unsupported signature (${sig.unsupported})`); + const signer = findSigner(sig, keys); + const id = sig.issuerFpr || sig.issuerKeyId; + if (!signer) return finding(label, "unknown", `signing key ${id} not found on keyservers`, { issuer: id }); + let payload = Buffer.from(data); + if (sig.type === 0x01) payload = Buffer.from(payload.toString("utf8").replace(/\r?\n/g, "\r\n")); + const ok = verifySignature(sig, signer.signing, payload); + const meta = { signer: signer.key.fingerprint, signedAt: sig.created }; + if (ok === null) return finding(label, "unknown", `cannot verify algorithm ${sig.pubAlgo} for ${id}`, meta); + if (!ok) return finding(label, "fail", `BAD signature by ${signer.key.fingerprint}`, meta); + const verdict = evaluateSignatureTime(revocationOf(signer.key, signer.signing.fingerprint), sig.created); + if (!verdict.valid) return finding(label, "fail", verdict.reason, meta); + const wot = webOfTrust(signer.key, trustedKeys, minCertifications); + const who = signer.key.uids.find((u) => u.tag === 13)?.text || signer.key.fingerprint; + if (!wot.trusted) return finding(label, "untrusted", `good signature by ${who}, but key is not certified by a trusted root`, meta); + return finding( + label, + "ok", + `good signature by ${who}${wot.root ? " (trusted root)" : ` (certified by ${wot.certifiers.length} trusted key(s))`}${verdict.note ? `; ${verdict.note}` : ""}`, + meta, + ); +} + +function finding(target, status, detail, extra = {}) { + return { target, status, detail, ...extra }; +} + +/** Check a pinned maintainer key against live revocation data. */ +export function checkPinnedKey(dep, fingerprint, keys) { + const label = `${dep.name} key ${fingerprint}`; + const key = keys.find((k) => k.fingerprint === fingerprint.toUpperCase().replace(/\s+/g, "")); + if (!key) return finding(label, "unknown", "not found on any keyserver (cannot check revocation)"); + const rev = revocationOf(key); + if (!rev) return finding(label, "ok", "not revoked"); + if (rev.code === 1 || rev.code === 3) { + return finding(label, "warn", `${rev.reason} on ${new Date(rev.time * 1000).toISOString().slice(0, 10)}; releases signed before then remain valid — pin the successor key`); + } + return finding( + label, + "fail", + `REVOKED (${rev.reason}${rev.text ? `: "${rev.text}"` : ""}) on ${new Date(rev.time * 1000).toISOString().slice(0, 10)} — every ${dep.name} release signed by this key must be re-verified`, + ); +} + +// ── Git objects ────────────────────────────────────────────────────────── + +/** Split a raw commit object into signed payload + signature. */ +export function splitCommit(raw) { + const text = raw.toString("utf8"); + const headerEnd = text.indexOf("\n\n"); + const headers = text.slice(0, headerEnd).split("\n"); + const kept = []; + const sigLines = []; + let inSig = false; + for (const line of headers) { + if (/^gpgsig(-sha256)? /.test(line)) { + inSig = true; + sigLines.push(line.replace(/^gpgsig(-sha256)? /, "")); + } else if (inSig && line.startsWith(" ")) { + sigLines.push(line.slice(1)); + } else { + inSig = false; + kept.push(line); + } + } + const payload = kept.join("\n") + text.slice(headerEnd); + return { payload: Buffer.from(payload, "utf8"), signature: sigLines.length ? sigLines.join("\n") + "\n" : null }; +} + +/** Split a raw annotated tag object into signed payload + signature. */ +export function splitTag(raw) { + const text = raw.toString("utf8"); + const i = text.search(/-----BEGIN (PGP|SSH) SIGNATURE-----/); + if (i === -1) return { payload: raw, signature: null }; + return { payload: Buffer.from(text.slice(0, i), "utf8"), signature: text.slice(i) }; +} + +function git(args, opts = {}) { + return execFileSync("git", args, { cwd: REPO_ROOT, maxBuffer: 64 * 1024 * 1024, ...opts }); +} + +// ── Key cache + keyservers ─────────────────────────────────────────────── + +function keyserverUrls(server, id) { + const clean = id.toUpperCase(); + if (/keys\.openpgp\.org/.test(server)) { + return [`${server}/vks/v1/${clean.length === 40 ? "by-fingerprint" : "by-keyid"}/${clean}`]; + } + return [`${server}/pks/lookup?op=get&options=mr&search=0x${clean}`]; +} + +export class KeyStore { + constructor({ cacheDir, ttlHours = 6, keyservers = [], offline = false, refresh = false, fetchImpl = fetch }) { + Object.assign(this, { cacheDir, ttlMs: ttlHours * 3600_000, keyservers, offline, refresh, fetchImpl }); + } + + cachePath(id) { + return path.join(this.cacheDir, `${id.toUpperCase()}.asc`); + } + + /** Armored key material for a fingerprint or key id (cache, then network). */ + async armored(id) { + const file = this.cachePath(id); + const fresh = fs.existsSync(file) && Date.now() - fs.statSync(file).mtimeMs < this.ttlMs; + if (fs.existsSync(file) && (this.offline || (fresh && !this.refresh))) return fs.readFileSync(file, "utf8"); + if (this.offline) return null; + const parts = []; + for (const server of this.keyservers) { + for (const url of keyserverUrls(server, id)) { + try { + const res = await this.fetchImpl(url, { signal: AbortSignal.timeout(15_000) }); + if (res.ok) parts.push(await res.text()); + } catch { + // keyserver unreachable: fall through to the next one / the cache + } + } + } + if (!parts.length) return fs.existsSync(file) ? fs.readFileSync(file, "utf8") : null; + const text = parts.join("\n"); + fs.mkdirSync(this.cacheDir, { recursive: true }); + fs.writeFileSync(file, text); + return text; + } + + async keys(ids) { + const all = []; + for (const id of new Set(ids.filter(Boolean))) { + const text = await this.armored(id); + if (!text) continue; + try { + all.push(...parseKeys(text)); + } catch (e) { + console.warn(`maintainer-keys: WARN cannot parse key ${id}: ${e.message}`); + } + } + return mergeKeys(all); + } +} + +function mergeKeys(list) { + const byFpr = new Map(); + for (const k of list) { + const prev = byFpr.get(k.fingerprint); + if (!prev) byFpr.set(k.fingerprint, k); + else { + prev.revocations.push(...k.revocations); + prev.uids.push(...k.uids); + prev.subkeys.push(...k.subkeys); + } + } + return [...byFpr.values()]; +} + +// ── CLI ────────────────────────────────────────────────────────────────── + +function issuerOf(signature) { + try { + const pkt = [...readPackets(dearmor(signature))].find((p) => p.tag === 2); + const sig = pkt && parseSignature(pkt.body); + return sig?.issuerFpr || sig?.issuerKeyId || null; + } catch { + return null; + } +} + +async function main() { + const args = process.argv.slice(2); + const getArg = (flag, def) => { + const i = args.indexOf(flag); + return i !== -1 && args[i + 1] && !args[i + 1].startsWith("--") ? args[i + 1] : def; + }; + const getAll = (flag) => args.flatMap((a, i) => (a === flag ? [args[i + 1]] : [])); + const strict = args.includes("--strict"); + const configPath = path.resolve(REPO_ROOT, getArg("--config", "config/maintainer-keys.json")); + const config = JSON.parse(fs.readFileSync(configPath, "utf8")); + const max = Number(getArg("--max", "50")); + const artifacts = getAll("--artifact").map((a, i) => ({ file: a, sig: getAll("--signature")[i] })); + const explicit = args.includes("--range") || args.includes("--tags") || args.includes("--pinned") || artifacts.length; + const range = getArg("--range", explicit ? null : "HEAD"); + const pinned = args.includes("--pinned") || !explicit; + + const store = new KeyStore({ + cacheDir: path.resolve(REPO_ROOT, config.cacheDir || ".cache/maintainer-keys"), + ttlHours: config.cacheTtlHours ?? 6, + keyservers: config.keyservers || [], + offline: args.includes("--offline"), + refresh: args.includes("--refresh"), + }); + const trustedKeys = await store.keys((config.trustedKeys || []).map((k) => k.fingerprint)); + const minCerts = config.minCertifications ?? 1; + const findings = []; + + // 1. Pinned dependency maintainer keys vs live revocation lists. + if (pinned) { + for (const dep of config.dependencies || []) { + const keys = await store.keys(dep.fingerprints || []); + for (const fpr of dep.fingerprints || []) findings.push(checkPinnedKey(dep, fpr, keys)); + } + for (const root of config.trustedKeys || []) { + const key = trustedKeys.find((k) => k.fingerprint === root.fingerprint); + const rev = key && revocationOf(key); + if (rev && !(rev.code === 1 || rev.code === 3)) + findings.push(finding(`trusted root ${root.owner}`, "fail", `trusted root key revoked (${rev.reason}) — remove it from ${path.relative(REPO_ROOT, configPath)}`)); + } + } + + // 2. Git objects: commits in range + tags. + const objects = []; + if (range) { + const shas = git(["rev-list", `--max-count=${max}`, range], { encoding: "utf8" }).split("\n").filter(Boolean); + for (const sha of shas) objects.push({ label: `commit ${sha.slice(0, 10)}`, ...splitCommit(git(["cat-file", "commit", sha])) }); + } + if (args.includes("--tags")) { + const glob = getArg("--tags", "*"); + const tags = git(["for-each-ref", "--format=%(refname:short) %(objecttype)", `refs/tags/${glob}`], { encoding: "utf8" }) + .split("\n") + .filter(Boolean) + .map((l) => l.split(" ")); + for (const [tag, type] of tags) { + if (type !== "tag") objects.push({ label: `tag ${tag}`, signature: null, lightweight: true }); + else objects.push({ label: `tag ${tag}`, ...splitTag(git(["cat-file", "tag", tag])) }); + } + } + for (const { file, sig } of artifacts) { + if (!sig) { + findings.push(finding(`artifact ${file}`, "fail", "missing --signature for artifact")); + continue; + } + objects.push({ label: `artifact ${file}`, payload: fs.readFileSync(file), signature: fs.readFileSync(sig, "utf8") }); + } + + const signerKeys = await store.keys(objects.filter((o) => o.signature?.includes("PGP SIGNATURE")).map((o) => issuerOf(o.signature))); + for (const o of objects) { + if (!o.signature) findings.push(finding(o.label, "unsigned", o.lightweight ? "lightweight tag (cannot carry a signature)" : "not signed")); + else if (o.signature.includes("SSH SIGNATURE")) + findings.push(finding(o.label, "warn", "SSH signature — outside OpenPGP revocation lists; verify with `git verify-commit` + allowed_signers")); + else + findings.push( + verifyDetached({ data: o.payload, signature: o.signature, keys: [...signerKeys, ...trustedKeys], trustedKeys, minCertifications: minCerts, label: o.label }), + ); + } + + // Soft findings become failures at the --strict (release) boundary. + const soft = new Set(["unsigned", "unknown", "untrusted", "warn"]); + for (const f of findings) f.level = f.status === "ok" ? "ok" : f.status === "fail" || (strict && soft.has(f.status)) ? "FAIL" : "WARN"; + + if (args.includes("--json")) console.log(JSON.stringify(findings, null, 2)); + else { + for (const f of findings) { + const line = `${f.level.padEnd(4)} ${f.target}: [${f.status}] ${f.detail}`; + if (f.level === "FAIL") console.error(line); + else if (f.level === "WARN" || !args.includes("--quiet")) console.log(line); + } + } + const fails = findings.filter((f) => f.level === "FAIL").length; + const warns = findings.filter((f) => f.level === "WARN").length; + console.log(`verify-maintainer-keys: ${findings.length} checked, ${fails} fail, ${warns} warn${fails ? " — FAIL" : " — OK"}`); + process.exit(fails ? 1 : 0); +} + +const isMain = process.argv[1] === fileURLToPath(import.meta.url); +if (isMain) { + main().catch((e) => { + console.error(`verify-maintainer-keys: ${e.stack || e.message}`); + process.exit(2); + }); +} diff --git a/soroban-contract.md b/soroban-contract.md index cc91c403..8c4b34c2 100644 --- a/soroban-contract.md +++ b/soroban-contract.md @@ -1,3 +1,366 @@ +# Soroban Contract — HelPhone + +## Stack + +- **Network:** Stellar Testnet +- **Language:** Rust (Soroban SDK) +- **Tools:** `soroban-cli`, `stellar-rpc-client` (frontend) + +--- + +## Data Structures +Memory bounds and pagination are documented in +[`docs/memory-architecture.md`](docs/memory-architecture.md). Collections are +capped at 500, page reads at 100, and verifier proof payloads at 1 MiB. + + +```rust +#[derive(Clone, Debug, Eq, PartialEq)] +#[contracttype] +pub enum DataKey { + Request(u64), // request_id → Request + Responder(u64, u32), // (request_id, responder_index) → Responder + RequestCount, // u64 — autoincrement counter + ResponderCount(u64), // (request_id) → u32 — responder count per request +} + +#[derive(Clone, Debug, Eq, PartialEq)] +#[contracttype] +pub struct Request { + pub requester: Address, // wallet requesting help + pub lat: i64, // latitude * 1_000_000 (example: -3432 -> -34.32) + pub lng: i64, // longitude * 1_000_000 + pub emergency_type: String, // 'lost'|'fallen'|'medical'|'car'|'danger'|'other' + pub nickname: String, // optional alias (max 32 chars) + pub contact: String, // contact method (phone, Telegram, etc.) + pub status: Status, + pub created_at: u64, // Unix timestamp (seconds) + pub resolved_at: Option, // when it was resolved/closed +} + +#[derive(Clone, Debug, Eq, PartialEq)] +#[contracttype] +pub enum Status { + Pending, // open, waiting for responders + Enroute, // someone is already on the way + Resolved, // the situation was resolved + Cancelled, // the requester cancelled +} + +#[derive(Clone, Debug, Eq, PartialEq)] +#[contracttype] +pub struct Responder { + pub responder: Address, // wallet helping + pub lat: i64, // position when accepted + pub lng: i64, + pub eta_seconds: u32, // estimated ETA in seconds + pub arrived: bool, // whether the responder actually arrived + pub responded_at: u64, // timestamp +} +``` + +--- + +## Functions + +### `create_request` + +```rust +fn create_request( + env: Env, + requester: Address, + lat: i64, + lng: i64, + nickname: String, + contact: String, +) -> u64 +``` + +- Emits `RequestCreated { id, requester, lat, lng }` +- Requires `requester.require_auth()` +- Increments `RequestCount` and stores the `Request` with `status: Pending` + +### `accept_request` + +```rust +fn accept_request( + env: Env, + responder: Address, + request_id: u64, + lat: i64, + lng: i64, + eta_seconds: u32, +) -> u32 // returns the responder index +``` + +- Requires `responder.require_auth()` +- Requires `request.status == Pending` +- Sets `request.status = Enroute` +- Stores `Responder` and increments `ResponderCount` +- Emits `RequestAccepted { request_id, responder, eta_seconds }` + +### `update_location` + +```rust +fn update_location( + env: Env, + responder: Address, + request_id: u64, + lat: i32, + lng: i32, +) +``` + +- **No `require_auth`** — the position is public because it is already visible on the map. The frontend signs it with an ephemeral keypair (`getTrackingSigner`) to avoid asking for a wallet signature every few seconds. +- Looks for the `Responder` matching `responder` within the request and updates `lat`/`lng`. +- Panics with `NotFound` if the responder does not exist in that request. +- Emits `LocUpd { request_id, responder, lat, lng }`. +- Trade-off: without auth, anyone can spoof a responder's position. This is acceptable for demo tracking; gate it with `responder.require_auth()` to harden it. + +### `mark_arrived` + +```rust +fn mark_arrived( + env: Env, + responder: Address, + request_id: u64, +) +``` + +- Marks `responder.arrived = true` +- Emits `ResponderArrived { request_id, responder }` + +### `resolve_request` + +```rust +fn resolve_request( + env: Env, + requester: Address, + request_id: u64, +) +``` + +- Requires `requester.require_auth()` +- Only the original requester can resolve it +- Sets `status: Resolved` and stores `resolved_at` +- Emits `RequestResolved { request_id }` + +### `cancel_request` + +```rust +fn cancel_request( + env: Env, + requester: Address, + request_id: u64, +) +``` + +- Requires `requester.require_auth()` +- Only works if `status == Pending` +- Sets `status: Cancelled` +- Emits `RequestCancelled { request_id }` + +### `get_request` + +```rust +fn get_request(env: Env, request_id: u64) -> Option +``` + +- Read-only. Returns the request or `None`. + +### `get_responder` + +```rust +fn get_responder(env: Env, request_id: u64, index: u32) -> Option +``` + +- Read-only. Returns a specific responder. + +### `get_request_count` + +```rust +fn get_request_count(env: Env) -> u64 +``` + +### `get_active_requests` + +```rust +fn get_active_requests(env: Env, max: u32) -> Vec +``` + +- Iterates request IDs backward from `RequestCount`, returning those that are `Pending` or `Enroute`. +- Maximum `max` results. + +### `get_responder_count` + +```rust +fn get_responder_count(env: Env, request_id: u64) -> u32 +``` + +### `get_ranking` + +```rust +fn get_ranking(env: Env, limit: u32) -> Vec +``` + +- Returns responders with the most arrivals, sorted descending. + +```rust +#[contracttype] +pub struct RankingEntry { + pub responder: Address, + pub total_arrivals: u32, +} +``` + +--- + +## Events + +```rust +#[contractevent] +pub enum HelPhoneEvent { + RequestCreated { id: u64, requester: Address, lat: i64, lng: i64, created_at: u64 }, + RequestAccepted { request_id: u64, responder: Address, eta_seconds: u32 }, + ResponderArrived { request_id: u64, responder: Address }, + RequestResolved { request_id: u64, resolved_at: u64 }, + RequestCancelled { request_id: u64 }, + LocationUpdated { request_id: u64, responder: Address, lat: i32, lng: i32 }, +} +``` + +The frontend subscribes to these events through Stellar RPC `getEvents()` to update the map in real time, replacing the `supabase.channel` subscriptions. + +--- + +## Deploy (Testnet) + +```bash +# 1. Build (uses Stellar CLI) +stellar contract build + +# 2. Deploy a testnet +stellar contract deploy \ + --wasm target/wasm32v1-none/release/helphone_contract.wasm \ + --network testnet \ + --source helphone-deployer +``` + +### Deployed + +| Campo | Valor | +|---|---| +| **Contract ID** | `CBO66W2GEGZZNGKLYU2R7QNUA7FKBHMDATNTJXRJS3R6GP7PVXI244YU` | +| **Network** | Stellar Testnet | +| **Tx (upload)** | `abdd1f6280305b4b544df5616cb8331b3f86024b8b16f274508b14a43d749536` | +| **Tx (deploy)** | `c713d22d379eaf7cc6983948e25e6e531483243d1223d7c9e378e7726d44b0ee` | +| **Wasm size** | 11,966 bytes | +| **Functions** | 11 exported | +| **Wallet source** | `helphone-deployer` (`GAEFEAC7...`) | +| **Source code** | `contract/contracts/helphone-contract/src/lib.rs` | + +Verified: `get_request_count` -> 0, `create_request` -> returns id 1 with the `RqCreated` event emitted. + +### Identity + +```bash +stellar keys generate helphone-deployer --network testnet +stellar keys fund helphone-deployer --network testnet +``` + +--- + +## Frontend Migration + +| Today (Supabase) | Tomorrow (Soroban) | Status | +|---|---|---| +| `supabase.from('requests').insert(...)` | `contract.create_request(...)` via `stellar-wallet-kit` | ✅ | +| `supabase.from('responders').insert(...)` | `contract.accept_request(...)` | ✅ | +| `supabase.channel(...).on('postgres_changes', ...)` | Poll every 5s with `get_active_requests` / every 3s with `get_responder_count` | ✅ | +| `supabase.from('responders').select(...).eq('status','arrived')` | `contract.get_ranking(...)` | Pending in Ranking.jsx | +| No fees | Writes pay a minimal XLM fee (~0.00001 XLM) | ✅ | +| Photos (base64 in DB) | Removed — not on-chain | ✅ | +| `gender` field | Replaced by `contact` (phone/Telegram) | ✅ | +| No emergency type | `emergency_type: String` added in contract v2 | ✅ | +| No wallet required | Connected Stellar wallet (Testnet) | ✅ | + +### Modified Files + +| File | Change | +|---|---| +| `src/lib/contract.js` | Helper with all Soroban contract functions | +| `src/pages/Help.jsx` | Removed Supabase, connected the contract, polling, emergency type, ZK proofs | +| `src/pages/Ranking.jsx` | Migrated to contract `get_ranking()` | +| `src/main.jsx` | WalletProvider `PUBLIC → TESTNET` | +| `src/lib/supabase.js` | **Removed** | +| `@supabase/supabase-js` | **Removed** from package.json | + +### Contract v2 (deprecated — do not use) + +- **Contract ID**: `CDKOCBOBOBZOE3WRIQSHRU6Q75VX5UNP7BRBEXCI4QCC5QXQIGUSJZZU` +- `Request` struct now includes `emergency_type: String` +- `create_request` receives 6 args (`emergency_type` was added between `lng` and `nickname`) + +### Contract v3 (deployed — current) + +- **Contract ID**: `CDP5XZ7UYCGSQBYRDYM2OEAUQJULBZPULSQXK7LGNAJTRXRG3VHZLSHY` +- **Network**: Stellar Testnet +- Added `update_location` for live responder tracking, plus the `LocUpd` event. +- **Privacy**: the frontend sends empty `nickname` and `contact` values on-chain (`createRequest(..., '', '', ...)`). Real name/contact values stay only in browser `localStorage`. +- **Location**: only a coarse location goes on-chain (`anonymizeLocation` rounds to 2 decimals, about 1 km). The exact coordinate is used only as the private witness for the ZK proof (Noir), proving "I am inside the zone" without revealing where. +- This is the default ID used by `src/lib/contract.js`; production can override it with `VITE_HELPHONE_CONTRACT_ID`. + +--- + +## Next Steps + +1. ✅ Create the Rust project with `stellar contract init` +2. ✅ Implement the contract +3. ✅ Build + Deploy a testnet +4. ✅ Migrate `Help.jsx` — remove Supabase, connect the contract +5. ✅ Migrate `Ranking.jsx` — read ranking from the contract +6. ✅ Remove `src/lib/supabase.js` and `@supabase/supabase-js` +7. ✅ ZK proof badges — dynamic instead of "SOON" +8. ⬜ Test end-to-end + +--- + +## Open Source Sustainability Reserve (`contracts/helphone_dao`, #587) + +The DAO contract holds a reserve that funds maintainers of the open source +dependencies HelPhone ships. The reserve logic is in +`contracts/helphone_dao/src/sustainability.rs`, and its entry points are on `HelPhoneDao`. + +- **1% protocol fee.** `collect_sustainability_fee(payer, gross_amount)` pulls + `gross_amount * 100 / 10_000` (`SUSTAINABILITY_FEE_BPS = 100`) of the + configured SAC token from `payer` into the reserve. Amounts are rounded down, + so a dust payment pays nothing. +- **DAO-voted grants.** `propose_maintainer_grant(proposer, maintainer, package, + amount, title, description)` opens a `FundAllocation` proposal and attaches a + `MaintainerGrant`. When the proposal passes and `execute_proposal` runs after + the timelock, the grant is paid automatically if the reserve covers it. If the + reserve is short, the grant stays `Pending`. Anyone can then call + `disburse_grant(proposal_id)` once the reserve has grown. Grants attached to + failed or cancelled proposals can never be paid. +- **Reads:** `get_sustainability_stats()` returns reserve, collected, + disbursed, grants proposed/paid and maintainers funded (used by + `/vault` via `getSustainabilityStats()` in `src/lib/contract.ts`). + `get_maintainer_grant(proposal_id)` and `get_maintainer_funding(maintainer)` + are the other two reads. +- **Admin:** `configure_sustainability(admin, reserve_token)` picks the SAC + token. `set_voting_supply(admin, supply)` sets the quorum denominator, because + SEP-41 tokens expose no `total_supply()`. + +```bash +cd contracts/helphone_dao && cargo test # grant lifecycle tests +stellar contract build # wasm32v1-none artifact +stellar contract deploy --wasm ../../target/wasm32v1-none/release/helphone_dao.wasm \ + --source helphone-deployer --network testnet -- \ + --admin --governance_token +``` + +Set `VITE_HELPHONE_DAO_CONTRACT_ID` to show the dependency funding stats on the +Vault dashboard. // Implementation added ## M-of-N admin governance diff --git a/src/lib/contract.ts b/src/lib/contract.ts index f87c3e7b..d13f60d5 100644 --- a/src/lib/contract.ts +++ b/src/lib/contract.ts @@ -584,6 +584,137 @@ export async function getMaintainerFunding() { }); } +// ── HelPhone DAO — open source sustainability reserve (#587) ── +// contracts/helphone_dao routes 1% of protocol transactions (SAC token) into +// a reserve and pays DAO-approved grants to dependency maintainers. + +/** Basis-point cut of each gross protocol amount routed to the reserve. */ +export const SUSTAINABILITY_FEE_BPS = 100; + +/** Fee the DAO collects on `grossAmount` (integer stroops), rounded down to + * match the contract's i128 arithmetic. Returns a BigInt. */ +export function computeSustainabilityFee(grossAmount) { + const gross = BigInt(grossAmount); + if (gross <= 0n) return 0n; + return (gross * BigInt(SUSTAINABILITY_FEE_BPS)) / 10_000n; +} + +/** Decode `get_sustainability_stats` into plain numbers for the UI. */ +export function normalizeSustainabilityStats(raw) { + if (!raw) return null; + const toNum = (v) => { + const n = safeToNumber(v ?? 0); + return Number.isFinite(n) ? n : 0; + }; + return { + token: raw.token || null, + feeBps: toNum(raw.fee_bps), + reserve: toNum(raw.reserve), + totalCollected: toNum(raw.total_collected), + totalDisbursed: toNum(raw.total_disbursed), + grantsProposed: toNum(raw.grants_proposed), + grantsDisbursed: toNum(raw.grants_disbursed), + maintainersFunded: toNum(raw.maintainers_funded), + }; +} + +/** Decode a `MaintainerGrant` (status is a unit enum → `[name]` or `name`). */ +export function normalizeMaintainerGrant(raw) { + if (!raw) return null; + const status = Array.isArray(raw.status) ? raw.status[0] : raw.status; + return { + proposalId: safeToNumber(raw.proposal_id), + maintainer: raw.maintainer, + package: raw.package, + amount: safeToNumber(raw.amount), + status: status === "Disbursed" ? "Disbursed" : "Pending", + disbursedAt: safeToNumber(raw.disbursed_at) || null, + }; +} + +function _daoContractId() { + const id = import.meta.env?.VITE_HELPHONE_DAO_CONTRACT_ID; + return id ? assertValidContractId(id, "VITE_HELPHONE_DAO_CONTRACT_ID") : null; +} + +/** Reserve + grant statistics. Returns null when the DAO is not deployed + * (VITE_HELPHONE_DAO_CONTRACT_ID unset). */ +export async function getSustainabilityStats() { + const id = _daoContractId(); + if (!id) return null; + return _withCache("getSustainabilityStats", [id], CACHE_TTL.short, async () => { + const sim = await simulateRead(new Contract(id).call("get_sustainability_stats")); + if (!sim.result) return null; + return normalizeSustainabilityStats(scValToNative(sim.result.retval)); + }); +} + +export async function getMaintainerGrant(proposalId) { + const id = _daoContractId(); + if (!id) return null; + const sim = await simulateRead( + new Contract(id).call("get_maintainer_grant", scv(BigInt(proposalId), { type: "u64" })), + ); + if (!sim.result) return null; + return normalizeMaintainerGrant(scValToNative(sim.result.retval)); +} + +async function _daoWrite(fn, args, wallet) { + const id = _daoContractId(); + if (!id) throw new Error("VITE_HELPHONE_DAO_CONTRACT_ID not configured"); + const signerAddress = await resolveWalletAddress(wallet); + if (!signerAddress) throw new Error("Wallet address is not available yet"); + await ensureAccountFunded(signerAddress); + const account = await server.getAccount(signerAddress); + const tx = new TransactionBuilder(account, { + fee: BASE_FEE, + networkPassphrase: NETWORK, + }) + .addOperation( + Operation.invokeContractFunction({ + contract: id, + function: fn, + args: args(signerAddress), + }), + ) + .setTimeout(30) + .build(); + return await sendWrite(tx, wallet, fn); +} + +/** Open a DAO FundAllocation proposal granting `amount` stroops of the + * reserve token to `maintainer` for `pkg` (e.g. "npm:@stellar/stellar-sdk"). */ +export async function proposeMaintainerGrant( + maintainer, + pkg, + amount, + title, + description, + wallet, +) { + return _daoWrite( + "propose_maintainer_grant", + (signer) => [ + scv(signer, { type: "address" }), + scv(maintainer, { type: "address" }), + scv(pkg, { type: "string" }), + scv(BigInt(amount), { type: "i128" }), + scv(title, { type: "string" }), + scv(description, { type: "string" }), + ], + wallet, + ); +} + +/** Retry a grant left Pending because the reserve was short at execution. */ +export async function disburseMaintainerGrant(proposalId, wallet) { + return _daoWrite( + "disburse_grant", + () => [scv(BigInt(proposalId), { type: "u64" })], + wallet, + ); +} + export async function getExpertVerifications(walletAddress, limit = 10) { if (!walletAddress) return []; return _withCache( diff --git a/src/pages/VaultDashboard.jsx b/src/pages/VaultDashboard.jsx index 2a599c0f..58db720a 100644 --- a/src/pages/VaultDashboard.jsx +++ b/src/pages/VaultDashboard.jsx @@ -14,6 +14,7 @@ import { getOracleQuote, sanitizeWalletAddress, buildLocationProofZone, + getSustainabilityStats, } from "../lib/contract"; import { generateLocationProof, @@ -27,6 +28,89 @@ function sanitizeAddress(raw) { return addr; } +const STROOPS = 10_000_000; + +function formatTokens(stroops) { + return stroops != null ? (stroops / STROOPS).toFixed(2) : "—"; +} + +/** #587 — open source dependency funding from the DAO sustainability reserve. */ +export function SustainabilityPanel({ stats }) { + const label = { + fontSize: "9px", + letterSpacing: "1px", + color: "rgba(242,236,220,0.72)", + marginBottom: "4px", + }; + const tile = { + padding: "12px", + borderRadius: "10px", + background: "rgba(255,255,255,0.04)", + border: "1px solid rgba(255,255,255,0.06)", + }; + const tiles = stats + ? [ + ["RESERVE BALANCE", formatTokens(stats.reserve), "#3F8487"], + ["TOTAL COLLECTED", formatTokens(stats.totalCollected), "#F4ECDC"], + ["GRANTED TO MAINTAINERS", formatTokens(stats.totalDisbursed), "#FF7A6B"], + ["MAINTAINERS FUNDED", String(stats.maintainersFunded), "#7357FF"], + [ + "GRANTS PAID / VOTED", + `${stats.grantsDisbursed} / ${stats.grantsProposed}`, + "#F4ECDC", + ], + ["PROTOCOL FEE SHARE", `${(stats.feeBps / 100).toFixed(2)}%`, "#a2a586"], + ] + : []; + + return ( +
+
+ OPEN SOURCE SUSTAINABILITY +
+ {stats ? ( +
+ {tiles.map(([name, value, color]) => ( +
+
{name}
+
+ {value} +
+
+ ))} +
+ ) : ( +

+ Sustainability reserve not deployed. Set + VITE_HELPHONE_DAO_CONTRACT_ID to show dependency funding stats. +

+ )} +
+ ); +} + function CampaignCard({ campaignId, balance, @@ -268,6 +352,7 @@ export default function VaultDashboard() { const [contributing, setContributing] = useState(false); const [message, setMessage] = useState(""); const [messageType, setMessageType] = useState("info"); + const [sustainability, setSustainability] = useState(null); const [treasury, setTreasury] = useState([]); const [treasuryLoading, setTreasuryLoading] = useState(true); @@ -326,6 +411,23 @@ export default function VaultDashboard() { setLoading(false); }, [loadPayout]); + // Real-time reserve stats: refresh every 15s while the page is open. + useEffect(() => { + let cancelled = false; + async function loadSustainability() { + try { + const stats = await getSustainabilityStats(); + if (!cancelled) setSustainability(stats); + } catch {} + } + loadSustainability(); + const timer = setInterval(loadSustainability, 15_000); + return () => { + cancelled = true; + clearInterval(timer); + }; + }, []); + async function handleConnectWallet() { try { const { address } = await StellarWalletsKit.authModal(); @@ -611,6 +713,11 @@ export default function VaultDashboard() { + {/* Open source sustainability reserve (#587) */} +
+ +
+ {/* Campaign Lookup */}
+} +// ── Domain interfaces for HelPhone ─────────────────────────────────────────── + +/** On-chain request status values returned by the Soroban contract. */ +export type RequestStatus = 'Pending' | 'Enroute' | 'Resolved' | 'Cancelled' + +/** Priority level for a help request. */ +export type PriorityLevel = 'Low' | 'Medium' | 'High' | 'Critical' + +/** A help request as decoded from the Soroban contract. */ +export interface HelpRequest { + id: number + requester: string + lat: number | null + lng: number | null + emergency_type: string + nickname: string + contact: string + status: RequestStatus + priority: PriorityLevel + created_at: number + resolved_at: number | null +} + +/** A responder entry attached to a request. */ +export interface Responder { + /** Composite id: `${requestId}-${index}` */ + id: string + responder: string + lat: number | null + lng: number | null + eta_seconds: number | null + arrived: boolean + responded_at: number +} + +/** Ranking entry returned by `get_ranking`. */ +export interface RankingEntry { + responder: string + total_arrivals: number +} + +// ── ZK Proof interfaces ─────────────────────────────────────────────────────── + +/** A bounding box used in the ZK location proof. */ +export interface ProofZone { + boxXMin: string + boxXMax: string + boxYMin: string + boxYMax: string + radiusMeters: number | null + center: { lat: number; lng: number } | null +} + +/** Result returned by generateLocationProof / _requestServerProof. */ +export interface LocationProof { + proof: Uint8Array + publicInputsBytes: Uint8Array + publicInputsPrefix: Uint8Array + nullifier: string + zone: ProofZone + publicInputs?: unknown +} + +/** + * Persisted ZK checkpoint stored in component state after a successful proof. + * Includes the original proof plus on-chain transaction hashes recorded + * after Stellar confirmation. + */ +export interface ZkCheckpoint { + scope: string + campaignId: string + nullifier: string + proof: LocationProof + zone: ProofZone + createdAt: string + /** Transaction hash of the primary on-chain action (create/accept request). */ + txHash?: string + /** Request id linked to this checkpoint once created. */ + requestId?: number + /** Transaction hash of the proof fingerprint record on Stellar. */ + recordTxHash?: string +} + +/** All possible status values for the ZK proof pipeline. */ +export type ZkStatus = 'idle' | 'proving' | 'proved' | 'recording' | 'recorded' | 'error' + +/** Shape of the zkReducer state. */ +export interface ZkState { + status: ZkStatus + logs: string[] + proof: ZkCheckpoint | null + error: string +} + +// ── Application state interfaces ───────────────────────────────────────────── + +/** User profile stored in localStorage. */ +export interface UserProfile { + nickname: string + contact: string +} + +/** A fully accepted offer receipt held in component state. */ +export interface OfferReceipt { + requestId: number + label: string + emergencyType: string + txHash: string + proofId: string + at: string + arrivalTxHash?: string +} + +// ── Wallet interfaces ───────────────────────────────────────────────────────── + +/** Minimal shape of the StellarWalletsKit instance used across the app. */ +export interface WalletKit { + authModal(): Promise<{ address: string }> + getAddress(): Promise<{ address: string }> + disconnect(): Promise + signTransaction(xdr: string, opts: { networkPassphrase: string }): Promise + on(event: string, handler: (event?: unknown) => void): () => void +} + +// ── Open source sustainability reserve (#587) ─────────────────────────────── + +/** `get_sustainability_stats` from contracts/helphone_dao, normalized. */ +export interface SustainabilityStats { + /** SAC token the reserve is held in; null until the admin configures it. */ + token: string | null + /** Basis points of each protocol transaction routed to the reserve (100 = 1%). */ + feeBps: number + reserve: number + totalCollected: number + totalDisbursed: number + grantsProposed: number + grantsDisbursed: number + maintainersFunded: number +} + +export type GrantStatus = 'Pending' | 'Disbursed' + +/** A DAO-voted grant to an open source dependency maintainer. */ +export interface MaintainerGrant { + proposalId: number + maintainer: string + /** Dependency identifier, e.g. "npm:@stellar/stellar-sdk". */ + package: string + amount: number + status: GrantStatus + disbursedAt: number | null +} + /** * HelPhone System-Wide TypeScript Definitions */ diff --git a/test/cve-patch.test.js b/test/cve-patch.test.js new file mode 100644 index 00000000..a7b1e533 --- /dev/null +++ b/test/cve-patch.test.js @@ -0,0 +1,239 @@ +import { describe, it, expect } from "vitest"; +import { + compareVersions, + satisfies, + upperBound, + severityRank, + normalizeGithubAdvisories, + normalizeNpmAudit, + collectInstalled, + pickPatchedVersion, + planPatches, + applyPlan, + residualVulnerable, + renderPrBody, +} from "../scripts/auto-patch-cve.js"; + +// #599 — CVE patch bot. Fixture-only: no npm, registry or GitHub calls. + +describe("semver helpers", () => { + it("orders versions, releases above prereleases", () => { + expect(compareVersions("1.2.3", "1.10.0")).toBeLessThan(0); + expect(compareVersions("2.0.0", "2.0.0-rc.1")).toBeGreaterThan(0); + expect(compareVersions("1.0.0", "1.0.0")).toBe(0); + }); + + it("matches GitHub and npm advisory range syntaxes", () => { + expect(satisfies("1.16.0", ">= 1.0.0, < 1.18.0")).toBe(true); // GitHub + expect(satisfies("1.18.0", ">=1.0.0 <1.18.0")).toBe(false); // npm audit + expect(satisfies("8.5.22", "<=8.5.22")).toBe(true); + expect(satisfies("1.1.0", "1.0.0 - 1.2.2")).toBe(true); + expect(satisfies("3.0.0", "<2.0.0 || >=3.0.0 <3.0.5")).toBe(true); + expect(satisfies("2.5.0", "<2.0.0 || >=3.0.0 <3.0.5")).toBe(false); + expect(satisfies("1.9.9", "^1.2.0")).toBe(true); + expect(satisfies("2.0.0", "^1.2.0")).toBe(false); + }); + + it("finds the exclusive upper bound of the matching set", () => { + expect(upperBound("1.16.0", ">=1.15.2 <1.18.0")).toBe("1.18.0"); + expect(upperBound("0.5.0", "<0.6.0 || >=1.0.0 <1.2.0")).toBe("0.6.0"); + expect(upperBound("8.5.15", "<=8.5.22")).toBeNull(); + }); + + it("ranks severities (GitHub 'medium' == npm 'moderate')", () => { + expect(severityRank("critical")).toBeGreaterThan(severityRank("high")); + expect(severityRank("medium")).toBe(severityRank("moderate")); + }); +}); + +describe("advisory normalization", () => { + it("parses GitHub REST global advisories", () => { + const advs = normalizeGithubAdvisories([ + { + ghsa_id: "GHSA-aaaa-bbbb-cccc", + cve_id: "CVE-2026-0001", + severity: "high", + html_url: "https://github.com/advisories/GHSA-aaaa-bbbb-cccc", + summary: "Prototype pollution", + vulnerabilities: [ + { + package: { ecosystem: "npm", name: "left-pad" }, + vulnerable_version_range: "< 1.3.1", + first_patched_version: "1.3.1", + }, + { + package: { ecosystem: "pip", name: "left-pad" }, + vulnerable_version_range: "< 9", + first_patched_version: { identifier: "9.0.0" }, + }, + ], + }, + ]); + expect(advs).toEqual([ + { + id: "GHSA-aaaa-bbbb-cccc", + cve: "CVE-2026-0001", + package: "left-pad", + severity: "high", + range: "< 1.3.1", + firstPatched: "1.3.1", + url: "https://github.com/advisories/GHSA-aaaa-bbbb-cccc", + title: "Prototype pollution", + }, + ]); + }); + + it("parses npm audit JSON, ignoring string `via` links", () => { + const advs = normalizeNpmAudit({ + vulnerabilities: { + express: { via: ["qs"] }, + qs: { + via: [ + { + source: 1, + name: "qs", + title: "DoS", + url: "https://github.com/advisories/GHSA-x5fp-wj9c-mxmx", + severity: "moderate", + range: ">=6.14.2 <=6.15.3", + }, + ], + }, + }, + }); + expect(advs).toHaveLength(1); + expect(advs[0]).toMatchObject({ id: "GHSA-x5fp-wj9c-mxmx", package: "qs", firstPatched: null }); + }); +}); + +const lock = { + packages: { + "": { name: "helphone" }, + server: { name: "helphone-prover" }, + "node_modules/helphone-prover": { link: true, resolved: "server" }, + "node_modules/morgan": { version: "1.11.0" }, + "node_modules/axios": { version: "1.16.0" }, + "node_modules/sdk/node_modules/axios": { version: "1.16.1" }, + "node_modules/ws": { version: "8.20.1" }, + "node_modules/old/node_modules/ws": { version: "7.5.11" }, + "node_modules/uuid": { version: "8.3.2" }, + "node_modules/elliptic": { version: "6.6.1" }, + }, +}; +const manifests = { + "package.json": { dependencies: { morgan: "^1.11.0" }, devDependencies: {} }, + "server/package.json": { dependencies: { morgan: "~1.11.0" } }, +}; +const adv = (pkg, range, extra = {}) => ({ + id: `GHSA-${pkg}`, + package: pkg, + range, + severity: "high", + firstPatched: null, + url: `https://github.com/advisories/GHSA-${pkg}`, + ...extra, +}); +const advisories = [ + adv("morgan", "<1.12.0", { severity: "moderate" }), + adv("axios", ">=1.0.0 <1.18.0"), + adv("ws", ">=8.0.0 <8.21.0"), + adv("uuid", "<11.1.1", { severity: "moderate" }), + adv("elliptic", "<=6.6.1", { severity: "low" }), +]; +const published = { + elliptic: ["6.6.0", "6.6.1"], + uuid: ["8.3.2", "9.0.0", "11.1.1"], +}; + +describe("collectInstalled", () => { + it("skips root/workspace links and marks hoisted copies", () => { + const occ = collectInstalled(lock); + expect(occ.map((o) => o.name)).not.toContain("helphone-prover"); + expect(occ.find((o) => o.path === "node_modules/axios").hoisted).toBe(true); + expect(occ.find((o) => o.path === "node_modules/sdk/node_modules/axios").hoisted).toBe(false); + }); +}); + +describe("pickPatchedVersion", () => { + it("chooses the lowest published same-major version no advisory matches", () => { + const advs = [adv("p", "<=1.2.0"), adv("p", ">=1.2.5 <1.3.0")]; + const pick = pickPatchedVersion("1.1.0", [advs[0]], advs, ["1.1.0", "1.2.1", "1.2.5", "1.3.0", "2.0.0-rc.1"]); + expect(pick).toEqual({ to: "1.2.1", breaking: false }); + }); + + it("uses the advisory upper bound when no registry data is available", () => { + expect(pickPatchedVersion("1.16.0", [advisories[1]], [advisories[1]], null)).toEqual({ to: "1.18.0", breaking: false }); + expect(pickPatchedVersion("6.6.1", [advisories[4]], [advisories[4]], null)).toBeNull(); + }); +}); + +describe("planPatches", async () => { + const plan = await planPatches({ lock, manifests, advisories, versionsOf: async (n) => published[n] || null }); + + it("bumps direct deps in every manifest and overrides transitive ones", () => { + const morgan = plan.patches.find((p) => p.name === "morgan"); + expect(morgan).toMatchObject({ to: "1.12.0", strategy: "manifest" }); + expect(morgan.manifests).toEqual(["package.json", "server/package.json"]); + expect(plan.patches.filter((p) => p.name === "axios").map((p) => p.strategy)).toEqual(["override", "override"]); + }); + + it("orders by severity and leaves major bumps / unfixable versions for humans", () => { + expect(plan.patches[0].severity).toBe("high"); + const reasons = Object.fromEntries(plan.unresolved.map((u) => [u.name, u.reason])); + expect(reasons.uuid).toMatch(/major bump to 11\.1\.1/); + expect(reasons.elliptic).toMatch(/no published non-vulnerable/); + }); + + it("allows major bumps when asked", async () => { + const p = await planPatches({ + lock, + manifests, + advisories, + versionsOf: async (n) => published[n] || null, + allowMajor: true, + }); + expect(p.patches.find((x) => x.name === "uuid")).toMatchObject({ to: "11.1.1", breaking: true }); + }); + + it("applies range floors, exact-version keys for mixed majors, and keeps spec style", () => { + const { manifests: next, applied } = applyPlan(manifests, plan); + expect(next["package.json"].dependencies.morgan).toBe("^1.12.0"); + expect(next["server/package.json"].dependencies.morgan).toBe("~1.12.0"); + // every axios copy is 1.x -> one name-level floor + expect(next["package.json"].overrides.axios).toBe("^1.18.0"); + // ws has a 7.x copy that must not be dragged to 8.x + expect(next["package.json"].overrides["ws@8.20.1"]).toBe("8.21.0"); + expect(next["package.json"].overrides.ws).toBeUndefined(); + expect(applied).toHaveLength(4); + expect(manifests["package.json"].overrides).toBeUndefined(); // input untouched + }); + + it("never clobbers a hand-written override", () => { + const pinned = structuredClone(manifests); + pinned["package.json"].overrides = { axios: "1.17.0" }; + const { skipped } = applyPlan(pinned, plan); + expect(skipped.map((s) => s.name)).toEqual(["axios", "axios"]); + }); + + it("detects copies left vulnerable after install", () => { + const after = structuredClone(lock); + after.packages["node_modules/axios"].version = "1.18.0"; + after.packages["node_modules/morgan"].version = "1.12.0"; + after.packages["node_modules/ws"].version = "8.21.0"; + const residual = residualVulnerable(after, advisories, plan.patches); + expect(residual.map((r) => r.path)).toEqual(["node_modules/sdk/node_modules/axios"]); + }); + + it("renders a PR body with advisories, verification and follow-ups", () => { + const { applied, skipped } = applyPlan(manifests, plan); + const body = renderPrBody({ + applied, + skipped, + unresolved: plan.unresolved, + verification: [{ cmd: "npm test", ok: true }], + }); + expect(body).toContain("| `morgan` | 1.11.0 → **1.12.0** | moderate | manifest | [GHSA-morgan](https://github.com/advisories/GHSA-morgan) |"); + expect(body).toContain("✅ `npm test`"); + expect(body).toMatch(/`uuid@8\.3\.2` \(GHSA-uuid\): fix requires a major bump/); + }); +}); diff --git a/test/fixtures/pgp/alice.asc b/test/fixtures/pgp/alice.asc new file mode 100644 index 00000000..87bf8775 --- /dev/null +++ b/test/fixtures/pgp/alice.asc @@ -0,0 +1,9 @@ +-----BEGIN PGP PUBLIC KEY BLOCK----- + +mDMEarTuJhYJKwYBBAHaRw8BAQdAae3Bakj2YsGMQ9ppim2AnB/DdBaez1xvi0/z +Ps+HKyy0H0FsaWNlIFJvb3QgPGFsaWNlQGV4YW1wbGUudGVzdD6IkwQTFgoAOxYh +BJ1MWRk9J51YempM9RVcnnBeIFT0BQJqtO4mAhsDBQsJCAcCAiICBhUKCQgLAgQW +AgMBAh4HAheAAAoJEBVcnnBeIFT0dEwBAI2iQDne83I308G/w/TiYwe65NVDtTX7 +HyFGAdGveeOFAP9t/6xIlcfNLcW0+VQFISeyO5A/jA8RTutl3KBd/JrFBg== +=IGBs +-----END PGP PUBLIC KEY BLOCK----- diff --git a/test/fixtures/pgp/artifact.txt b/test/fixtures/pgp/artifact.txt new file mode 100644 index 00000000..c0f90b7c --- /dev/null +++ b/test/fixtures/pgp/artifact.txt @@ -0,0 +1 @@ +helphone release artifact diff --git a/test/fixtures/pgp/artifact.txt.asc b/test/fixtures/pgp/artifact.txt.asc new file mode 100644 index 00000000..8caaa33f --- /dev/null +++ b/test/fixtures/pgp/artifact.txt.asc @@ -0,0 +1,11 @@ +-----BEGIN PGP SIGNATURE----- + +iQEzBAABCgAdFiEEo6cCXm18CWmYCqoP6cXJYfJP6KkFAmq07iYACgkQ6cXJYfJP +6KkMiQf8CCHg7MyHALt7EjY7F7PP/BXopIEIssH7c1xmXeUKPcEDG70nTA3x64YT +dtOv6J0iPIXC/viC4sCj5UTQZjIrmYpPs+QJzfn42B98zRNWf9mYNtIiL5BEfkNg +Cn9i9gs8CU7rWgbFDrE/kCP2OfeTo24h8uD+sZuGoBOuLOYWCJjOA2xf4zj+tyPE +vnW9lL8JOvcZMopD6pzZurILVassT8b7dV+coFAcpVcRIkf+BgRa0FI0vV3+pWaa +3FerG3wK995Wm06sQG43IIVCOs1UANXN+EeJ74jecv2mUZ+sT9D1Q9CdpGWjm1Q8 +rxIoWX4S6aGBVEaQoYPJKkeUt3e49Q== +=8N+X +-----END PGP SIGNATURE----- diff --git a/test/fixtures/pgp/bob-revoked-compromised.asc b/test/fixtures/pgp/bob-revoked-compromised.asc new file mode 100644 index 00000000..bb6a7389 --- /dev/null +++ b/test/fixtures/pgp/bob-revoked-compromised.asc @@ -0,0 +1,25 @@ +-----BEGIN PGP PUBLIC KEY BLOCK----- + +mQENBGq07iYBCADHP1YPH059maUTFSQ6EZ8GpS7MKeLzebYJ335Pl5o+ilL4wKLm +QLab5eFJwVgp2hAJsA2hEwNshy+hkxcIToUh+F3EHk+T81ocUX+m8nw+CePFP9mB +n8vA3hmdyHhnoAUsyZnXwb0csmDcTOfwfpBB7WBQL5gB4EXbAFDkQYXcHR4DpZlF +hJGkXwaP6zywh3/xxizGnT1M2dly/1AaEzbutpHkm/VAb6A4grqvKrgno6nw6Drr +iRowSL7zZaigJzXNJzJPK8tCXvYrchFcpTPm77TE5yOcsRrED/4lluYY0vspSeDP +ggYtI5vheqdJL5R89bXcSadZrrRONL4t/yOLABEBAAGJAUgEIAEKADIWIQSjpwJe +bXwJaZgKqg/pxclh8k/oqQUCarTuVRQdAnByaXZhdGUga2V5IGxlYWtlZAAKCRDp +xclh8k/oqbWpB/9tsfTq3B6FRzf+XZ0ro2SQVtwDyOBJhxx35K38Ohp7CsdM4ksb +sW6ZKiU2cYKeI/ot5fK20yLSUGj6/Kv/ewJ9T+jSJSbh6OgXYaJMQS56JefMpV+o +0ZCHP7pUVT/C+tTbFUvxh/p/1f/vFSNh4s/wptLf9gY3GdD8UFNhfNvlNP3nt58g +YU6IHDXPH91xkUP5CpPhysfyx3c2iefzFYz9PNHVCqcg5rQApOF4cT6a1Tko/prJ +ocPFnk/Ui3daNfjHWegQUIMGnHoiPf0K/OUCQgu4h3WxLwAc70OtxjEkwuDXnr9v +D1IQcTMuyLVaBzGoVkZKZwqS5e+XgY8frCqEtCFCb2IgTWFpbnRhaW5lciA8Ym9i +QGV4YW1wbGUudGVzdD6JAVEEEwEKADsWIQSjpwJebXwJaZgKqg/pxclh8k/oqQUC +arTuJgIbAwULCQgHAgIiAgYVCgkICwIEFgIDAQIeBwIXgAAKCRDpxclh8k/oqXk8 +B/0V52A10kzh6Ik9uQeJst7nNQ01JhKsItn7DXBkKYnVgGv4BrH2kUFU4rwNUKrT +w+r1AWLZSBy9iCUeWM9bVwkQYGVHodvhyc403VGqsupBZ4fc5dM13h4Sp9W3/B8A +itrLiOIPEfNDlw4kItUa2h/WSCDNzGuPlCV+A2Klp/Udzjwc0URxc2xMNHxIW99n +slqeGCEVfzuyI+622gWlZcm11ev+fvbOQMtz5vAGGsuM2+7+BVz99DOhrgTsYU/2 +ESAabG7BY10H9OyyMBQEyTnXgVjVG924QlsPev6aKpdS/+yus1rUj6LlPozY/HcY +LaaIjsm52JYvLr+Lk9ZvaYlW +=Y/e7 +-----END PGP PUBLIC KEY BLOCK----- diff --git a/test/fixtures/pgp/bob.asc b/test/fixtures/pgp/bob.asc new file mode 100644 index 00000000..3bb640f3 --- /dev/null +++ b/test/fixtures/pgp/bob.asc @@ -0,0 +1,18 @@ +-----BEGIN PGP PUBLIC KEY BLOCK----- + +mQENBGq07iYBCADHP1YPH059maUTFSQ6EZ8GpS7MKeLzebYJ335Pl5o+ilL4wKLm +QLab5eFJwVgp2hAJsA2hEwNshy+hkxcIToUh+F3EHk+T81ocUX+m8nw+CePFP9mB +n8vA3hmdyHhnoAUsyZnXwb0csmDcTOfwfpBB7WBQL5gB4EXbAFDkQYXcHR4DpZlF +hJGkXwaP6zywh3/xxizGnT1M2dly/1AaEzbutpHkm/VAb6A4grqvKrgno6nw6Drr +iRowSL7zZaigJzXNJzJPK8tCXvYrchFcpTPm77TE5yOcsRrED/4lluYY0vspSeDP +ggYtI5vheqdJL5R89bXcSadZrrRONL4t/yOLABEBAAG0IUJvYiBNYWludGFpbmVy +IDxib2JAZXhhbXBsZS50ZXN0PokBUQQTAQoAOxYhBKOnAl5tfAlpmAqqD+nFyWHy +T+ipBQJqtO4mAhsDBQsJCAcCAiICBhUKCQgLAgQWAgMBAh4HAheAAAoJEOnFyWHy +T+ipeTwH/RXnYDXSTOHoiT25B4my3uc1DTUmEqwi2fsNcGQpidWAa/gGsfaRQVTi +vA1QqtPD6vUBYtlIHL2IJR5Yz1tXCRBgZUeh2+HJzjTdUaqy6kFnh9zl0zXeHhKn +1bf8HwCK2suI4g8R80OXDiQi1RraH9ZIIM3Ma4+UJX4DYqWn9R3OPBzRRHFzbEw0 +fEhb32eyWp4YIRV/O7Ij7rbaBaVlybXV6/5+9s5Ay3Pm8AYay4zb7v4FXP30M6Gu +BOxhT/YRIBpsbsFjXQf07LIwFATJOdeBWNUb3bhCWw96/poql1L/7K6zWtSPouU+ +jNj8dxgtpoiOybnYli8uv4uT1m9piVY= +=J2o6 +-----END PGP PUBLIC KEY BLOCK----- diff --git a/test/fixtures/pgp/carol-certified.asc b/test/fixtures/pgp/carol-certified.asc new file mode 100644 index 00000000..13cd2106 --- /dev/null +++ b/test/fixtures/pgp/carol-certified.asc @@ -0,0 +1,12 @@ +-----BEGIN PGP PUBLIC KEY BLOCK----- + +mDMEarTuJhYJKwYBBAHaRw8BAQdAAeNpqXcB8vzuJsNNxawmtbEitE1tTJezmTG1 +jsiJ9c+0JUNhcm9sIE1haW50YWluZXIgPGNhcm9sQGV4YW1wbGUudGVzdD6IkwQT +FgoAOxYhBEw1lYrzdgxhJ+07yJK9kWGuJDDJBQJqtO4mAhsDBQsJCAcCAiICBhUK +CQgLAgQWAgMBAh4HAheAAAoJEJK9kWGuJDDJWH4A/R8iW+rPDDq75zRp43GIpO4p +RYXVTmE/XSAIP5IOtRjYAP9O93YLLLfGguofIoS6QrZjUSbaXLikS4TUClim7DcK +Boh1BBAWCgAdFiEEnUxZGT0nnVh6akz1FVyecF4gVPQFAmq07iYACgkQFVyecF4g +VPSl9gEA62dcYjPwcat+3QGa9VpdOBuqRHEQStIf8AjyPRCwPBsA/iP88EvqzuPn +qvBRH6nL5OoZhr3dH+b47C23azzLtxQM +=9rGy +-----END PGP PUBLIC KEY BLOCK----- diff --git a/test/fixtures/pgp/dave-revoked-superseded.asc b/test/fixtures/pgp/dave-revoked-superseded.asc new file mode 100644 index 00000000..d797a798 --- /dev/null +++ b/test/fixtures/pgp/dave-revoked-superseded.asc @@ -0,0 +1,12 @@ +-----BEGIN PGP PUBLIC KEY BLOCK----- + +mDMEarTuJhYJKwYBBAHaRw8BAQdAixfOdIJy0pe8+3BTdJcemZdKKGz808wMgh9K +c6TmrRyIigQgFgoAMhYhBJ6zo3ruiAXQf81+FmiqcL5l57gxBQJqtO5YFB0Bcm90 +YXRlZCB0byBuZXcga2V5AAoJEGiqcL5l57gxBgMA+wc5ejRVmRERLTK0S+66PhxQ +NCjGdVuC+8sXJofCduveAQCQLGI1HtTHOKljoERWBzlnSbe0IhNAGHoDC8tN8rIo +DbQgRGF2ZSBSZXRpcmVkIDxkYXZlQGV4YW1wbGUudGVzdD6IkwQTFgoAOxYhBJ6z +o3ruiAXQf81+FmiqcL5l57gxBQJqtO4mAhsDBQsJCAcCAiICBhUKCQgLAgQWAgMB +Ah4HAheAAAoJEGiqcL5l57gxkUYA+gJVFy0lYzZHfH7EGwoGrrfYHzbOjQTT1Z6I +y+T3DQrnAP9aqYvGz18A50lZCy4l2nsFw86V0IVIxcsA4GgEPx1bAQ== +=dunf +-----END PGP PUBLIC KEY BLOCK----- diff --git a/test/license-compliance.test.js b/test/license-compliance.test.js new file mode 100644 index 00000000..8846ac71 --- /dev/null +++ b/test/license-compliance.test.js @@ -0,0 +1,161 @@ +import { describe, it, expect } from "vitest"; +import { + classifyExpression, + classifyId, + normalizeId, + collectNpm, + collectCargo, + evaluate, + buildManifest, +} from "../scripts/license-compliance.js"; + +// #586 — Dependency license compliance & copyleft gate. Fixture-only: no +// filesystem or cargo invocation. + +describe("classifyId", () => { + it("approves permissive licenses and denies strong copyleft", () => { + expect(classifyId("MIT")).toBe("approved"); + expect(classifyId("Apache-2.0")).toBe("approved"); + expect(classifyId("GPL-3.0-only")).toBe("denied"); + expect(classifyId("AGPL-3.0-or-later")).toBe("denied"); + expect(classifyId("SSPL-1.0")).toBe("denied"); + expect(classifyId("GPL-2.0+")).toBe("denied"); + }); + + it("routes weak copyleft and unknown ids to review", () => { + expect(classifyId("LGPL-3.0-only")).toBe("review"); + expect(classifyId("MPL-2.0")).toBe("review"); + expect(classifyId("Some-Custom-License")).toBe("review"); + }); + + it("normalizes aliases and license-checker guess markers", () => { + expect(normalizeId("Apache 2.0")).toBe("Apache-2.0"); + expect(normalizeId("MIT*")).toBe("MIT"); + expect(classifyId("BSD-3-Clause*")).toBe("approved"); + }); +}); + +describe("classifyExpression (SPDX)", () => { + it("OR picks the most permissive branch", () => { + expect(classifyExpression("MIT OR Apache-2.0")).toBe("approved"); + expect(classifyExpression("GPL-3.0 OR MIT")).toBe("approved"); + expect(classifyExpression("(GPL-2.0 OR LGPL-2.1)")).toBe("review"); + }); + + it("AND picks the most restrictive term", () => { + expect(classifyExpression("(MIT OR Apache-2.0) AND Unicode-3.0")).toBe("approved"); + expect(classifyExpression("MIT AND GPL-3.0")).toBe("denied"); + expect(classifyExpression("MIT AND (AGPL-3.0 OR SSPL-1.0)")).toBe("denied"); + }); + + it("honours WITH exceptions and slash-separated legacy forms", () => { + expect(classifyExpression("Apache-2.0 WITH LLVM-exception")).toBe("approved"); + expect(classifyExpression("GPL-2.0 WITH Classpath-exception-2.0")).toBe("review"); + expect(classifyExpression("MIT/Apache-2.0")).toBe("approved"); + }); + + it("treats missing or non-SPDX metadata as review", () => { + expect(classifyExpression(undefined)).toBe("review"); + expect(classifyExpression("UNKNOWN")).toBe("review"); + expect(classifyExpression("SEE LICENSE IN LICENSE.md")).toBe("review"); + expect(classifyExpression("UNLICENSED")).toBe("review"); + }); +}); + +const fixtureLock = { + lockfileVersion: 3, + packages: { + "": { name: "helphone", version: "1.0.0" }, + server: { name: "helphone-prover", version: "1.0.0" }, + "node_modules/helphone-prover": { resolved: "server", link: true }, + "node_modules/react": { version: "19.2.7", license: "MIT" }, + "node_modules/copyleft-lib": { version: "1.0.0", license: "AGPL-3.0" }, + "node_modules/a/node_modules/react": { version: "19.2.7", license: "MIT", dev: true }, + "node_modules/nolicense": { version: "0.1.0" }, + "node_modules/devtool": { version: "2.0.0", license: "GPL-2.0", dev: true }, + }, +}; + +describe("collectNpm", () => { + const installed = { + "node_modules/nolicense": { + version: "0.1.0", + licenses: [{ type: "MIT" }, { type: "Apache-2.0" }], + repository: { url: "git+https://github.com/x/nolicense.git" }, + }, + }; + const deps = collectNpm(fixtureLock, (p) => installed[p] || null); + + it("skips the root project and workspace links", () => { + expect(deps.map((d) => d.name)).not.toContain("helphone-prover"); + expect(deps.map((d) => d.name)).not.toContain("server"); + }); + + it("dedupes nested copies; dev only if every copy is dev", () => { + const react = deps.filter((d) => d.name === "react"); + expect(react).toHaveLength(1); + expect(react[0].dev).toBe(false); + }); + + it("falls back to the installed package.json licenses array", () => { + const pkg = deps.find((d) => d.name === "nolicense"); + expect(pkg.license).toBe("(MIT OR Apache-2.0)"); + expect(pkg.repository).toBe("https://github.com/x/nolicense"); + }); +}); + +describe("collectCargo", () => { + it("keeps registry crates and drops workspace path crates", () => { + const deps = collectCargo({ + packages: [ + { name: "helphone_dao", version: "0.1.0", source: null, license: null }, + { + name: "soroban-sdk", + version: "26.0.1", + source: "registry+https://github.com/rust-lang/crates.io-index", + license: "Apache-2.0", + repository: "https://github.com/stellar/rs-soroban-sdk", + }, + { + name: "ring", + version: "0.17.0", + source: "registry+https://github.com/rust-lang/crates.io-index", + license: null, + license_file: "LICENSE", + }, + ], + }); + expect(deps.map((d) => d.name)).toEqual(["soroban-sdk", "ring"]); + expect(deps[0]).toMatchObject({ ecosystem: "cargo", license: "Apache-2.0" }); + expect(deps[1].license).toBe("SEE LICENSE IN LICENSE"); + }); +}); + +describe("evaluate + buildManifest", () => { + const deps = [ + ...collectNpm(fixtureLock), + { ecosystem: "cargo", name: "gpl-crate", version: "1.0.0", license: "GPL-3.0-only", dev: false }, + ]; + + it("fails on new copyleft (dev deps included), passes excepted ones", () => { + const result = evaluate(deps, { "npm:copyleft-lib": "legal sign-off #1" }); + expect(result.denied.map((p) => `${p.ecosystem}:${p.name}`).sort()).toEqual([ + "cargo:gpl-crate", + "npm:devtool", + ]); + expect(result.excepted).toHaveLength(1); + expect(result.excepted[0]).toMatchObject({ name: "copyleft-lib", exception: "legal sign-off #1" }); + expect(result.review.map((p) => p.name)).toEqual(["nolicense"]); + }); + + it("produces a deterministic, sorted attribution manifest", () => { + const result = evaluate(deps, {}); + const a = buildManifest(result); + const b = buildManifest(evaluate([...deps].reverse(), {})); + expect(JSON.stringify(a)).toBe(JSON.stringify(b)); + expect(a.summary).toMatchObject({ total: 5, npm: 4, cargo: 1, denied: 3, review: 1, approved: 1 }); + expect(a.packages[0].ecosystem).toBe("cargo"); + expect(a.packages.find((p) => p.name === "devtool").dev).toBe(true); + expect(a).not.toHaveProperty("generatedAt"); + }); +}); diff --git a/test/maintainer-keys.test.js b/test/maintainer-keys.test.js new file mode 100644 index 00000000..908df1f1 --- /dev/null +++ b/test/maintainer-keys.test.js @@ -0,0 +1,194 @@ +import { describe, it, expect } from "vitest"; +import { readFileSync, mkdtempSync, existsSync } from "node:fs"; +import { tmpdir } from "node:os"; +import { join } from "node:path"; +import { + parseKeys, + revocationOf, + evaluateSignatureTime, + webOfTrust, + verifyDetached, + checkPinnedKey, + splitCommit, + splitTag, + KeyStore, +} from "../scripts/security/verify_maintainer_keys.js"; + +// #619 — Maintainer key revocation & web-of-trust engine. Fixtures in +// test/fixtures/pgp were generated with GnuPG 2.4 from throwaway keys +// (private halves discarded): +// alice Ed25519, trusted root; certifies carol +// bob RSA-2048; signed artifact.txt, then revoked as COMPROMISED +// carol Ed25519, certified by alice (web of trust) +// dave Ed25519, revoked as SUPERSEDED + +const fx = (f) => readFileSync(join(__dirname, "fixtures/pgp", f), "utf8"); +const FPR = { + alice: "9D4C59193D279D587A6A4CF5155C9E705E2054F4", + bob: "A3A7025E6D7C0969980AAA0FE9C5C961F24FE8A9", + carol: "4C35958AF3760C6127ED3BC892BD9161AE2430C9", + dave: "9EB3A37AEE8805D07FCD7E1668AA70BE65E7B831", +}; +const [alice] = parseKeys(fx("alice.asc")); +const [bob] = parseKeys(fx("bob.asc")); +const [bobRevoked] = parseKeys(fx("bob-revoked-compromised.asc")); +const [carol] = parseKeys(fx("carol-certified.asc")); +const [dave] = parseKeys(fx("dave-revoked-superseded.asc")); +const artifact = readFileSync(join(__dirname, "fixtures/pgp/artifact.txt")); + +describe("RFC 4880 key parsing", () => { + it("computes v4 fingerprints and key ids for RSA and Ed25519 keys", () => { + expect(alice.fingerprint).toBe(FPR.alice); + expect(bob.fingerprint).toBe(FPR.bob); + expect(bob.keyId).toBe(FPR.bob.slice(-16)); + expect(alice.algo).toBe(22); + expect(bob.algo).toBe(1); + expect(carol.uids[0].text).toBe("Carol Maintainer "); + }); + + it("merges copies of one key served by several keyservers", () => { + const merged = parseKeys(fx("bob.asc") + "\n" + fx("bob-revoked-compromised.asc")); + expect(merged).toHaveLength(1); + expect(revocationOf(merged[0])).not.toBeNull(); + }); +}); + +describe("revocation certificates (KRL)", () => { + it("reads a cryptographically verified 'key compromised' revocation", () => { + expect(revocationOf(bob)).toBeNull(); + const rev = revocationOf(bobRevoked); + expect(rev).toMatchObject({ code: 2, reason: "key compromised", text: "private key leaked", verified: true }); + }); + + it("reads a 'key superseded' revocation", () => { + expect(revocationOf(dave)).toMatchObject({ code: 1, reason: "key superseded", verified: true }); + }); + + it("ignores a forged revocation that does not verify", () => { + const forged = parseKeys(fx("bob-revoked-compromised.asc"))[0]; + forged.revocations.forEach((r) => (r.verified = false)); + expect(revocationOf(forged)).toBeNull(); + }); +}); + +describe("evaluateSignatureTime", () => { + const at = 1_000_000; + it("compromise invalidates signatures made BEFORE the revocation", () => { + const res = evaluateSignatureTime({ time: at, code: 2, reason: "key compromised", text: "" }, at - 86_400); + expect(res.valid).toBe(false); + expect(res.reason).toMatch(/every signature by it is invalid/); + }); + + it("'no reason' is treated like compromise", () => { + expect(evaluateSignatureTime({ time: at, code: 0, reason: "no reason specified" }, at - 1).valid).toBe(false); + }); + + it("superseded/retired keys keep earlier signatures valid", () => { + const rev = revocationOf(dave); + expect(evaluateSignatureTime(rev, rev.time - 60)).toMatchObject({ valid: true }); + expect(evaluateSignatureTime(rev, rev.time + 60).valid).toBe(false); + }); +}); + +describe("web of trust", () => { + it("trusts roots directly and keys certified by a root", () => { + expect(webOfTrust(alice, [alice])).toMatchObject({ trusted: true, root: true }); + expect(webOfTrust(carol, [alice])).toMatchObject({ trusted: true, certifiers: [FPR.alice] }); + }); + + it("does not trust uncertified keys or honour a raised threshold", () => { + expect(webOfTrust(bob, [alice]).trusted).toBe(false); + expect(webOfTrust(carol, [alice], 2).trusted).toBe(false); + }); + + it("drops certifications made by a compromised root", () => { + expect(webOfTrust(carol, [bobRevoked]).trusted).toBe(false); + }); +}); + +describe("verifyDetached (release artifacts, commits, tags)", () => { + const sig = fx("artifact.txt.asc"); + + it("accepts a good signature by a trusted, unrevoked key", () => { + const res = verifyDetached({ data: artifact, signature: sig, keys: [bob], trustedKeys: [bob], label: "a" }); + expect(res.status).toBe("ok"); + expect(res.signer).toBe(FPR.bob); + }); + + it("fails a release signed BEFORE its key was revoked as compromised", () => { + const res = verifyDetached({ data: artifact, signature: sig, keys: [bobRevoked], trustedKeys: [bobRevoked], label: "a" }); + expect(res.status).toBe("fail"); + expect(res.detail).toMatch(/key compromised/); + expect(res.signedAt).toBeLessThan(revocationOf(bobRevoked).time); + }); + + it("detects tampering", () => { + const res = verifyDetached({ data: Buffer.from("tampered"), signature: sig, keys: [bob], trustedKeys: [bob], label: "a" }); + expect(res.status).toBe("fail"); + expect(res.detail).toMatch(/BAD signature/); + }); + + it("reports unknown signers and good-but-untrusted signatures", () => { + expect(verifyDetached({ data: artifact, signature: sig, keys: [alice], label: "a" }).status).toBe("unknown"); + expect(verifyDetached({ data: artifact, signature: sig, keys: [bob], trustedKeys: [alice], label: "a" }).status).toBe("untrusted"); + }); +}); + +describe("checkPinnedKey", () => { + const dep = { name: "example-lib" }; + it("fails on compromise, warns on supersession, passes otherwise", () => { + expect(checkPinnedKey(dep, FPR.bob, [bobRevoked]).status).toBe("fail"); + expect(checkPinnedKey(dep, FPR.dave, [dave]).status).toBe("warn"); + expect(checkPinnedKey(dep, FPR.alice, [alice]).status).toBe("ok"); + expect(checkPinnedKey(dep, FPR.carol, []).status).toBe("unknown"); + }); +}); + +describe("git object splitting", () => { + it("strips the gpgsig header (and continuation lines) from the signed payload", () => { + const raw = Buffer.from( + "tree abc\nparent def\nauthor A 1 +0000\ncommitter A 1 +0000\n" + + "gpgsig -----BEGIN PGP SIGNATURE-----\n \n wsBc\n -----END PGP SIGNATURE-----\n\nmessage\n", + ); + const { payload, signature } = splitCommit(raw); + expect(payload.toString()).toBe("tree abc\nparent def\nauthor A 1 +0000\ncommitter A 1 +0000\n\nmessage\n"); + expect(signature).toBe("-----BEGIN PGP SIGNATURE-----\n\nwsBc\n-----END PGP SIGNATURE-----\n"); + expect(splitCommit(Buffer.from("tree abc\n\nmsg\n")).signature).toBeNull(); + }); + + it("splits a signed annotated tag at the signature", () => { + const { payload, signature } = splitTag(Buffer.from("object abc\ntag v1\n\nrelease\n-----BEGIN PGP SIGNATURE-----\nx\n")); + expect(payload.toString()).toBe("object abc\ntag v1\n\nrelease\n"); + expect(signature.startsWith("-----BEGIN PGP SIGNATURE-----")).toBe(true); + }); +}); + +describe("KeyStore cache", () => { + it("serves cached keys offline and refetches from keyservers when stale", async () => { + const cacheDir = mkdtempSync(join(tmpdir(), "keys-")); + const calls = []; + const fetchImpl = async (url) => { + calls.push(url); + return { ok: true, text: async () => fx("dave-revoked-superseded.asc") }; + }; + const store = new KeyStore({ cacheDir, keyservers: ["https://keys.openpgp.org", "https://keyserver.ubuntu.com"], fetchImpl }); + const [k] = await store.keys([FPR.dave]); + expect(k.fingerprint).toBe(FPR.dave); + expect(calls).toEqual([ + `https://keys.openpgp.org/vks/v1/by-fingerprint/${FPR.dave}`, + `https://keyserver.ubuntu.com/pks/lookup?op=get&options=mr&search=0x${FPR.dave}`, + ]); + expect(existsSync(join(cacheDir, `${FPR.dave}.asc`))).toBe(true); + + await store.keys([FPR.dave]); // fresh cache: no network + expect(calls).toHaveLength(2); + + const offline = new KeyStore({ cacheDir, offline: true, fetchImpl }); + expect((await offline.keys([FPR.dave]))[0].fingerprint).toBe(FPR.dave); + expect(calls).toHaveLength(2); + + const refresh = new KeyStore({ cacheDir, refresh: true, keyservers: ["https://keys.openpgp.org"], fetchImpl }); + await refresh.keys([FPR.dave]); + expect(calls).toHaveLength(3); + }); +}); diff --git a/test/sustainability-pool.test.js b/test/sustainability-pool.test.js new file mode 100644 index 00000000..e6bfaad8 --- /dev/null +++ b/test/sustainability-pool.test.js @@ -0,0 +1,121 @@ +import { describe, it, expect } from "vitest"; +import { createElement } from "react"; +import { render, screen } from "@testing-library/react"; +import { + SUSTAINABILITY_FEE_BPS, + computeSustainabilityFee, + normalizeSustainabilityStats, + normalizeMaintainerGrant, + getSustainabilityStats, +} from "../src/lib/contract"; +import { SustainabilityPanel } from "../src/pages/VaultDashboard.jsx"; + +// #587 — Open source sustainability reserve (contracts/helphone_dao). +// On-chain behaviour is covered by `cargo test` in contracts/helphone_dao; +// these tests pin the frontend decoding + fee math to the contract's. + +describe("computeSustainabilityFee", () => { + it("takes 1% and rounds down like the contract's i128 math", () => { + expect(SUSTAINABILITY_FEE_BPS).toBe(100); + expect(computeSustainabilityFee(250_000)).toBe(2_500n); + expect(computeSustainabilityFee(199n)).toBe(1n); + expect(computeSustainabilityFee(99)).toBe(0n); + }); + + it("returns 0 for non-positive amounts", () => { + expect(computeSustainabilityFee(0)).toBe(0n); + expect(computeSustainabilityFee(-500)).toBe(0n); + }); +}); + +describe("normalizeSustainabilityStats", () => { + it("maps scValToNative output (BigInt i128 / u32) to numbers", () => { + const stats = normalizeSustainabilityStats({ + token: "CTOKEN", + fee_bps: 100, + reserve: 60_000n, + total_collected: 100_000n, + total_disbursed: 40_000n, + grants_proposed: 3, + grants_disbursed: 1, + maintainers_funded: 1, + }); + expect(stats).toEqual({ + token: "CTOKEN", + feeBps: 100, + reserve: 60_000, + totalCollected: 100_000, + totalDisbursed: 40_000, + grantsProposed: 3, + grantsDisbursed: 1, + maintainersFunded: 1, + }); + }); + + it("returns null for a missing result and zero-fills absent fields", () => { + expect(normalizeSustainabilityStats(null)).toBeNull(); + expect(normalizeSustainabilityStats({ token: undefined }).reserve).toBe(0); + }); +}); + +describe("normalizeMaintainerGrant", () => { + it("decodes the unit-enum status and u64/i128 fields", () => { + const grant = normalizeMaintainerGrant({ + proposal_id: 7n, + maintainer: "GMAINTAINER", + package: "npm:@stellar/stellar-sdk", + amount: 40_000n, + status: ["Disbursed"], + disbursed_at: 1_700_000_000n, + }); + expect(grant).toEqual({ + proposalId: 7, + maintainer: "GMAINTAINER", + package: "npm:@stellar/stellar-sdk", + amount: 40_000, + status: "Disbursed", + disbursedAt: 1_700_000_000, + }); + expect( + normalizeMaintainerGrant({ status: ["Pending"], disbursed_at: 0n }) + .status, + ).toBe("Pending"); + }); +}); + +describe("getSustainabilityStats", () => { + it("returns null without a deployed DAO contract", async () => { + expect(await getSustainabilityStats()).toBeNull(); + }); +}); + +describe("SustainabilityPanel", () => { + it("renders reserve and grant statistics", () => { + render( + createElement(SustainabilityPanel, { + stats: { + token: "CTOKEN", + feeBps: 100, + reserve: 600_000_000, + totalCollected: 1_000_000_000, + totalDisbursed: 400_000_000, + grantsProposed: 3, + grantsDisbursed: 1, + maintainersFunded: 1, + }, + }), + ); + expect(screen.getByText("OPEN SOURCE SUSTAINABILITY")).toBeInTheDocument(); + expect(screen.getByText("60.00")).toBeInTheDocument(); + expect(screen.getByText("40.00")).toBeInTheDocument(); + expect(screen.getByText("1 / 3")).toBeInTheDocument(); + expect(screen.getByText("1.00%")).toBeInTheDocument(); + }); + + it("explains how to enable the panel when the DAO is not deployed", () => { + render(createElement(SustainabilityPanel, { stats: null })); + expect( + screen.getByText(/VITE_HELPHONE_DAO_CONTRACT_ID/), + ).toBeInTheDocument(); + }); +});