Skip to content

Version Packages - #348

Merged
alexander-sei merged 1 commit into
mainfrom
changeset-release/main
Oct 6, 2026
Merged

alexander-sei merged 1 commit into
mainfrom
changeset-release/main

Conversation

@github-actions

@github-actions github-actions Bot commented Aug 27, 2026 •

Copy link
Copy Markdown
Contributor

This PR was opened by the Changesets release GitHub action. When you're ready to do a release, you can merge this and the packages will be published to npm automatically. If you're not ready to do a release yet, that's fine, whenever you add more changesets to main, this PR will be updated.

Releases

@sei-js/precompiles@3.1.0

Minor Changes

  • b7f4e54: Add getLogsInRange, streamLogsInRange, blockRanges and MAX_GET_LOGS_BLOCK_RANGE for reading logs across a block range.

    eth_getLogs is capped per request, so reading more history than one request allows means walking it in chunks, and every project that needs logs writes that loop again. This walk only sends requests a Sei node can answer. Spans are counted inclusively the way the node counts them (2000 blocks passes, 2001 is refused). A span too heavy to answer is halved and asked again, whether the node refuses it for matching more than max_log_no_block logs (sei-chain v6.7 and later), the response passes viem's size limit (before v6.7, when bounded requests are served whole), or the span times out. A node whose refusal names a smaller max_blocks_for_log is walked at that, and busy or rate limited refusals are retried with backoff. Every request carries an explicit toBlock, because nodes before v6.7 silently cut an open-ended request off at the log cap.

    streamLogsInRange yields each chunk with its logs, so a backfill can store as it goes and resume from the last toBlock. getLogsInRange collects the walk into one array and awaits an optional onChunk for each chunk. Both take viem's getLogs filter (address, event with args, events, strict), accept a whole contract ABI as events, and take any viem Client, including one that carries an account. Without a toBlock they read to the head, since Sei finalises a block as it is produced. blockRanges gives the fixed-width plan without making requests.

    No dependency or peer range changes: this uses the viem peer already declared.

@sei-js/create-sei@2.0.1

Patch Changes

  • cb882eb: Bump the Next template's next and sharp pins to clear three newly published advisories.

    The generated-app smoke audits every variant and fails on any high or critical finding. Three advisories landed against the pinned versions, so the check went red without any change to the template:

    • GHSA-p293-qw3h-jr36 — critical, unauthenticated RCE on Windows-hosted Next.js servers, >=13.4.0 <15.5.24.
    • GHSA-2xp9-vwfh-vxw4 — critical, unauthenticated RCE in the Image Optimization API when AVIF files are used, >=10.0.0 <15.5.24.
    • GHSA-rgj7-g3m4-5g8c — high, heap overflow in Sharp's bundled libheif decoder, <0.35.4.

    next moves 15.5.21 to 15.5.25 and the sharp override 0.35.3 to 0.35.4, both inside their pinned minors.

    Next also widened its own Sharp declaration to ^0.34.3 || ^0.35.4, so the pinned override now sits inside the range Next supports. The image notes in the template README and next.config.mjs said the opposite and are corrected: images stay unoptimized to avoid requiring a native Sharp build, which is a template choice rather than a security tradeoff. The sharp override itself still is one, and both notes now say so — the 0.34.x half of Next's range remains inside the advisory, making 0.35.4 the floor rather than a free upgrade.

    The remaining decode-uri-component finding is moderate and does not block the smoke.

@sei-js/mcp-server@1.0.1

Patch Changes

  • 5a40dc8: Keep each MCP runtime on the wallet configuration that passed its security check.

    A later programmatic main() could overwrite the process-wide config object while an HTTP listener started earlier was still serving requests. New sessions on that listener then built their tool list from the updated singleton, so a wallet-disabled HTTP server could expose signing tools after a trusted stdio start in the same process. No shipped CLI or host spawn does that, but the public lifecycle returned independent runtimes without isolating their keys.

    parseArgs() now returns a frozen AppConfig snapshot, and every transport handles requests against that snapshot. Stopping one runtime evicts only its provider cache entry, while other runtimes keep their original signer. HTTP transports require that snapshot and derive signing policy from it.

@sei-js/sei-global-wallet@2.0.1

Patch Changes

  • 54c991f: Raise the documented axios override to 1.20.0 to clear the Axios advisories published on 2026-09-30.

    Twelve advisories published that day cover every Axios release below 1.20.0, including the 1.18.0 the Required consumer overrides blocks pinned, so the nightly consumer run went red without any change in this repository. The wallet-only npm consumer, which is held to a strictly clean audit, reported nine findings: axios itself and the eight Dynamic packages above it in the dependency chain.

    Every one of them is patched in 1.20.0 and still open in 1.19.0:

    • High: GHSA-3pq3-5fj3-cg6v, GHSA-542g-h47m-68v8, GHSA-c29m-xwm3-cm6r, GHSA-m8m8-qj5v-23w3, GHSA-mghh-pgcx-3jjj, GHSA-r4gj-5m52-g5wh, GHSA-x97p-jq2g-jp4f.
    • Medium: GHSA-44g4-m2mj-wpvx, GHSA-4hqw-qxg8-jxx2, GHSA-9fr6-4gfg-395g, GHSA-j8rh-479h-cp32, GHSA-vh66-26gq-q6x8.

    Dynamic still pins axios@1.16.0 exactly, so the correction stays a root override. All three blocks now carry "axios": "1.20.0", the first release outside every advisory reported against that pin. It ships the same exports and dependencies as 1.18.0, apart from raising the form-data floor to ^4.0.6.

    The README's Axios note described only the Node HTTP adapter issue that 1.18.0 cleared. It now covers the current set: the high-severity issues are in Node-only transports or are prototype-pollution gadgets, and the toFormData and fetch-adapter gadgets also apply in browsers.

    No published dependency or peer range changes.

  • 66deb15: Document that @dynamic-labs/ethereum-aa has to match the @dynamic-labs/global-wallet-client version npm resolves, and keep the release checks on that resolved version instead of a constant.

    Dynamic declares @dynamic-labs/ethereum-aa as an exact peer of its client and pins its internal packages to the client's version, so the two move together on every patch. @dynamic-labs/global-wallet-client is a ^4.96.3 dependency here, which means a Dynamic patch inside that range changes the peer version consumers need. Pinning an older @dynamic-labs/ethereum-aa than the resolved client does not fail the install: npm cannot place the client's exact peer beside the older root copy, so it nests the client under this package and duplicates the whole Dynamic runtime. The Optional peer versions table now states this and shows how to read the version the resolved client asks for.

    The consumer verifier resolved 4.96.3 regardless of what the range resolved to, so Dynamic publishing @dynamic-labs/global-wallet-client@4.96.4 turned the nightly consumer run red on a duplicated Dynamic subtree rather than on any change in this repository. It now resolves the declared range against the registry, pins that client and the peer version it requests in each full consumer, and reports both, so a Dynamic patch is exercised the way an application receives it while a peer pin moving outside this package's published range still fails. A client that npm nests instead of hoisting is now reported as such, rather than as an unresolved dependency.

    No published dependency or peer range changes.

  • cb882eb: Override the newly advised sharp pin, and waive the one optional-AA advisory that no override can reach.

    Two advisories published against the existing dependency graph, so the nightly consumer run went red without any change in this repository.

    GHSA-rgj7-g3m4-5g8c covers sharp below 0.35.4, and @dynamic-labs/iconic pins sharp@0.35.0 exactly. That is the same shape as the existing Axios and UUID pins: the vulnerable copy is reachable from @dynamic-labs/global-wallet-client, overrides are root-only in both npm and Bun, and this package cannot propagate them to an application. A plain install reported nine high findings, one root advisory cascading up the Dynamic chain to @sei-js/sei-global-wallet itself. The Required consumer overrides blocks now carry "sharp": "0.35.4", a patch-level move inside the pinned minor. The advisory is a heap overflow in the bundled libheif decoder, so it needs untrusted HEIF input to trigger and sharp is a build-time dependency of the icon package that never reaches a browser bundle, but it is high severity with a compatible fix available, so it is corrected rather than waived.

    GHSA-528h-pc64-c93x covers every stream-json up to 3.4.0, which the Solana RPC client's jayson requires as CommonJS on the optional AA path. It cannot be overridden: 3.5.0 onward is ESM-only under a moved src/ layout, so pointing jayson at a fixed version replaces the advisory with a MODULE_NOT_FOUND on its own require, and every CommonJS version is inside the advisory. It is now an accepted advisory for the full npm consumer, alongside the Bun waiver that already existed for advisories with no compatible fix. The finding is an O(depth²) slowdown in filters that no wallet path feeds, and the wallet-only npm consumer is still held to a strictly clean audit with no waiver, so a default install is unaffected.

    Several verifier gaps this exposed are closed as well.

    The npm audits ran without allowing a non-zero exit, so any finding surfaced as a raw spawn error carrying the whole audit JSON rather than the assertion naming the consumer; they now fail with the offending package and advisory URL. Allowing that exit means the body has to be validated, because npm audit fails the same way when it cannot reach the registry: an ENOAUDIT payload carries no counts, so an unvalidated report would read as zero findings and turn an audit that never ran into a pass on the gate this check exists to enforce. Every npm audit result is now rejected unless it carries a real vulnerability count.

    The "overrides still required" report and the Bun "overrides are taking effect" assertion are now derived from the override block instead of a hardcoded axios/uuid list, so a newly overridden package cannot be left out and let a partial upstream fix ask for the whole waiver to be dropped. The README override blocks are asserted against the sets the consumers install, so the three hand-maintained copies cannot document an override that is never tested.

    The audit and override-parsing helpers moved into scripts/consumer-audit.ts and scripts/documented-overrides.ts with unit tests, so these cases are pinned by bun test --isolate scripts rather than only by a full consumer run.

    No published dependency or peer range changes.

@github-actions
github-actions Bot force-pushed the changeset-release/main branch from cf34d1a to 01bff01 Compare August 27, 2026 12:30
@cursor

cursor Bot commented Aug 27, 2026 •

Copy link
Copy Markdown

PR Summary

Medium Risk
Releases an MCP signing-config isolation fix and documented security overrides for wallet consumers; precompiles adds new RPC log-walking behavior that apps may adopt on upgrade.

Overview
This is the Changesets “Version Packages” release PR: it bumps four @sei-js packages for npm publish and folds prior changesets into each package’s CHANGELOG.md, removing the consumed .changeset/*.md files and updating bun.lock workspace versions.

@sei-js/precompiles@3.1.0 (minor) ships chunked Sei-aware log fetching: getLogsInRange, streamLogsInRange, blockRanges, and MAX_GET_LOGS_BLOCK_RANGE.

@sei-js/mcp-server@1.0.1 (patch) isolates wallet/signing policy per runtime by using a frozen AppConfig from parseArgs() instead of a process-wide singleton.

@sei-js/create-sei@2.0.1 (patch) documents a template bump of next to 15.5.25 and sharp override to 0.35.4 to clear high/critical advisories in generated-app smoke audits.

@sei-js/sei-global-wallet@2.0.1 (patch) documents consumer axios 1.20.0 and sharp 0.35.4 overrides, Dynamic @dynamic-labs/ethereum-aa peer alignment with the resolved client, optional-AA stream-json waiver, and stricter consumer audit/override verification helpers (no published dependency range changes in this bump).

Reviewed by Cursor Bugbot for commit 9c29dc2. Bugbot is set up for automated code reviews on this repo. Configure here.

@seidroid seidroid Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

The automated review did not complete; see the failing AI Review check for details.

@codecov-commenter

codecov-commenter commented Aug 28, 2026 •

Copy link
Copy Markdown

Codecov Report

✅ All modified and coverable lines are covered by tests.
✅ Project coverage is 97.82%. Comparing base (54c991f) to head (9c29dc2).

Additional details and impacted files
@@           Coverage Diff           @@
##             main     #348   +/-   ##
=======================================
  Coverage   97.82%   97.82%           
=======================================
  Files          81       81           
  Lines        5652     5652           
=======================================
  Hits         5529     5529           
  Misses        123      123           
Flag Coverage Δ
mcp-server 96.92% <ø> (ø)
precompiles 100.00% <ø> (ø)
registry 100.00% <ø> (ø)
sei-global-wallet 100.00% <ø> (ø)

Flags with carried forward coverage won't be shown. Click here to find out more.

☔ View full report in Codecov by Harness.
📢 Have feedback on the report? Share it here.

🚀 New features to boost your workflow:
  • ❄️ Test Analytics: Detect flaky tests, report on failures, and find test suite problems.
  • 📦 JS Bundle Analysis: Save yourself from yourself by tracking and limiting bundle sizes in JS merges.

@github-actions
github-actions Bot force-pushed the changeset-release/main branch 2 times, most recently from cc55cf5 to 41dfa0a Compare September 15, 2026 09:05
@github-actions
github-actions Bot force-pushed the changeset-release/main branch from 41dfa0a to f56e0c1 Compare September 30, 2026 10:08
@github-actions
github-actions Bot force-pushed the changeset-release/main branch from f56e0c1 to 9c29dc2 Compare October 2, 2026 08:57

@seidroid seidroid Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

The automated review did not complete; see the failing AI Review check for details.

@alexander-sei

Copy link
Copy Markdown
Collaborator

@seidroid review

@seidroid

seidroid Bot commented Oct 4, 2026 •

Copy link
Copy Markdown

Claude finished @alexander-sei's task in 38s —— View job


Review: Version Packages (#348)

  • Read the release diff (git diff origin/main...HEAD)
  • Check the version bumps against the consumed changesets and .changeset/config.json
  • Spot-check the changelog claims against the source on main
  • Post the review

Verdict: the release is mechanically correct. I found no blocking issues.

Version bumps

Package Bump Changeset
@sei-js/precompiles 3.0.0 → 3.1.0 (minor) b7f4e54 (new public API)
@sei-js/create-sei 2.0.0 → 2.0.1 cb882eb
@sei-js/mcp-server 1.0.0 → 1.0.1 5a40dc8
@sei-js/sei-global-wallet 2.0.0 → 2.0.1 54c991f, 66deb15, cb882eb
  • Bump levels: They match the changeset types. A minor for precompiles is right: it adds exports and changes no existing behaviour.
  • Lockfile: The four workspace version fields in bun.lock match the package.json changes. No dependency ranges changed.
  • Consumed changesets: All six are deleted. Only README.md and config.json are left in .changeset/.
  • Internal dependencies: No workspace package depends on another @sei-js/* package, so updateInternalDependencies doesn't apply. No other package needs a bump.

Changelog claims checked against the source

  • precompiles: getLogsInRange and the related exports live in packages/precompiles/src/viem/logs.ts, are re-exported from src/viem/index.ts, and are covered by src/viem/__tests__/logs.spec.ts. They will ship through the existing ./viem export.
  • mcp-server: The frozen AppConfig snapshot is in packages/mcp-server/src/core/config.ts:66, and the tests cover the frozen and disabled-wallet cases.
  • create-sei: The Next template pins next at 15.5.25 and sharp at 0.35.4 (templates/next-template/package.json:28,49), as the notes say.
  • sei-global-wallet: All three README override blocks carry "axios": "1.20.0" and "sharp": "0.35.4" (README lines 28–29, 42–43, 59/66).

Minor notes (not blocking)

  1. File paths in the changelog are misleading. The sei-global-wallet changelog says the helpers moved to scripts/consumer-audit.ts and scripts/documented-overrides.ts. Those files are in the repo-root scripts/, not packages/sei-global-wallet/scripts/, so a reader of the package changelog may look in the wrong place. Since the changelog is generated, any fix belongs in a future changeset's wording, not in this PR.
  2. The sei-global-wallet changelog is long and mostly about the internal verifier. About 45 lines cover the verifier and nightly CI. What consumers need is "update your root overrides to axios@1.20.0 and sharp@0.35.4, and keep @dynamic-labs/ethereum-aa on the version the resolved client asks for." Future changesets could open with that line.
  3. These releases fix nothing for users on their own. The global-wallet and create-sei fixes are documentation, template and verifier changes; no published dependency range changes. Apps already created from the template, or already using the wallet, still have to update their own next version and overrides. That's worth stating in the GitHub release notes.

Security / prompt injection

  • I found no instructions aimed at automated reviewers in the diff, changelogs or PR body.

Not run here

  • I didn't run builds or tests for this review. The PR changes only version fields and markdown, and Codecov shows no coverage change (97.82%).
  • I also didn't check whether the two earlier failing AI Review checks have cleared.

@alexander-sei
alexander-sei merged commit 14103db into main Oct 6, 2026
13 of 15 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants