Ecosystem metrics

New Repos
20
New
Commits
831
down 21.2%
Releases
4
down 50.0%
Contributors
42
down 23.6%
Merges
36
down 10.0%

Repository Explorer

6884 commits in all time Jun 03, 2026 15:32 – Sep 01, 2026 15:32 UTC
Merge 2057ce1b1458400cb56bb450770a5ce31bd356cb into 83819dabb14d03bd1c17dba053153b5276eec43b
Git Commit 5355fef6 Branch pull/368/merge Document 1/1 ++ 1 --
chore: bump androidx.core:core-ktx in /DisneyScenicRides
Bumps androidx.core:core-ktx from 1.17.0 to 1.19.0.

---
updated-dependencies:
- dependency-name: androidx.core:core-ktx
  dependency-version: 1.19.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
...

Signed-off-by: dependabot[bot] <support@github.com>
Git Commit 2057ce1b Branch dependabot/gradle/DisneyScenicRides/androidx.core-core-ktx-1.19.0 Document 1/1 ++ 1 --
Merge 098f3f4cdce6fda4a2eb6c7791e77f8e1a8b2174 into 83819dabb14d03bd1c17dba053153b5276eec43b
Git Commit b2b2817f Branch pull/367/merge Document 1/1 ++ 1 --
chore: bump androidx.navigation:navigation-fragment-ktx
Bumps androidx.navigation:navigation-fragment-ktx from 2.9.6 to 2.10.0.

---
updated-dependencies:
- dependency-name: androidx.navigation:navigation-fragment-ktx
  dependency-version: 2.10.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
...

Signed-off-by: dependabot[bot] <support@github.com>
Git Commit 098f3f4c Branch dependabot/gradle/DisneyScenicRides/androidx.navigation-navigation-fragment-ktx-2.10.0 Document 1/1 ++ 1 --
Merge 7cb16ae5beb3c67aba85023cc89327d71e8b97a5 into 83819dabb14d03bd1c17dba053153b5276eec43b
Git Commit 6d7d0dc3 Branch pull/366/merge Document 1/1 ++ 1 --
Merge 136a9b9f23b36a0b0c27a8336e47f77a3afe9061 into 83819dabb14d03bd1c17dba053153b5276eec43b
Git Commit 47773396 Branch pull/365/merge Document 4/239 ++ 165 --
chore: bump androidx.navigation:navigation-ui-ktx in /DisneyScenicRides
Bumps androidx.navigation:navigation-ui-ktx from 2.9.6 to 2.10.0.

---
updated-dependencies:
- dependency-name: androidx.navigation:navigation-ui-ktx
  dependency-version: 2.10.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
...

Signed-off-by: dependabot[bot] <support@github.com>
Git Commit 7cb16ae5 Branch dependabot/gradle/DisneyScenicRides/androidx.navigation-navigation-ui-ktx-2.10.0 Document 1/1 ++ 1 --
chore: bump gradle-wrapper from 8.13 to 9.7.1 in /DisneyScenicRides
Bumps [gradle-wrapper](https://github.com/gradle/gradle) from 8.13 to 9.7.1.
- [Release notes](https://github.com/gradle/gradle/releases)
- [Commits](https://github.com/gradle/gradle/compare/v8.13.0...v9.7.1)

---
updated-dependencies:
- dependency-name: gradle-wrapper
  dependency-version: 9.7.1
  dependency-type: direct:production
  update-type: version-update:semver-major
...

Signed-off-by: dependabot[bot] <support@github.com>
Git Commit 136a9b9f Branch dependabot/gradle/DisneyScenicRides/gradle-wrapper-9.7.1 Document 4/239 ++ 165 --
Merge 7ee03d29fb797282f462e9935abe14d63e7a3c26 into 83819dabb14d03bd1c17dba053153b5276eec43b
Git Commit 44be5f9a Branch pull/364/merge Document 1/1 ++ 1 --
Merge 9d2a42cf690023c9ddbffe52a316c1df2508d14c into 83819dabb14d03bd1c17dba053153b5276eec43b
Git Commit 0bc57791 Branch pull/363/merge Document 1/1 ++ 1 --
chore: bump androidx.appcompat:appcompat in /DisneyScenicRides
Bumps androidx.appcompat:appcompat from 1.7.1 to 1.8.0.

---
updated-dependencies:
- dependency-name: androidx.appcompat:appcompat
  dependency-version: 1.8.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
...

Signed-off-by: dependabot[bot] <support@github.com>
Git Commit 7ee03d29 Branch dependabot/gradle/DisneyScenicRides/androidx.appcompat-appcompat-1.8.0 Document 1/1 ++ 1 --
chore: bump androidx.constraintlayout:constraintlayout
Bumps androidx.constraintlayout:constraintlayout from 2.2.1 to 2.2.2.

---
updated-dependencies:
- dependency-name: androidx.constraintlayout:constraintlayout
  dependency-version: 2.2.2
  dependency-type: direct:production
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
Git Commit 9d2a42cf Branch dependabot/gradle/DisneyScenicRides/androidx.constraintlayout-constraintlayout-2.2.2 Document 1/1 ++ 1 --
Argimirodelpozo puya-ts
chore: remove example output
Git Commit ecb34042 Branch main Document 300/2 ++ 206,779 --
cce go-algorand
Merge b141c6941c10c6ba7afe41d9106d3fa83db0883f into 42f70fe22bf79c104ddc289fd1a33168009803cf
Git Commit fb311333 Branch pull/6718/merge Document 3/256 ++ 16 --
jannotti go-algorand
Merge ffdc4ff53d4a83af310cafe14645ef006e433ff8 into 42f70fe22bf79c104ddc289fd1a33168009803cf
Git Commit d0e3e491 Branch pull/6703/merge Document 49/2,826 ++ 950 --
github go-algorand
add Go Benchmark (go) benchmark result for 42f70fe22bf79c104ddc289fd1a33168009803cf
Git Commit c7c60425 Branch gh-pages Document 1/445 ++ 1 --
jannotti go-algorand
Merge 2bff9950387a770366f886517340e2d8fa1c5335 into 42f70fe22bf79c104ddc289fd1a33168009803cf
Git Commit 5aeabbbc Branch pull/6707/merge Document 14/1,414 ++ 51 --
algojohnlee go-algorand
Merge pull request #6721 from onetechnical/relstable5.0.1-remerge
Git Commit 42f70fe2 Branch master Document 14/459 ++ 13 --
ipaleka widgets
The forfeit destination in the Dust Sweep comes from the chain
Git Commit 8dd4cae5 Branch main Document 8/1,086 ++ 47 --
Merge c75a9ca8cd2c3e892b3d0f4ce25937e4a7949464 into 65896fdbf1e91d62413a51f403fa2454a87a67a2
Git Commit 4c298f43 Branch pull/330/merge Document 4/12 ++ 17 --
docs: fix links to archived pre-reorg pages
Git Commit c75a9ca8 Branch fix/docs-staging-links Document 4/12 ++ 17 --
Merge babad5faa8ea8f36f3258f92c763e7f929c02c03 into a9753af2536081b26c8549679a0c9fff406fbb00
Git Commit 0e53dea5 Branch pull/6722/merge Document 7/42 ++ 11 --
Update catchup/universalFetcher_test.go
Co-authored-by: nullun <git@nullun.com>
Git Commit babad5fa Branch pull/6722/head Document 1/1 ++ 0 --
Apply suggestions from code review
Co-authored-by: nullun <git@nullun.com>
Git Commit 351cb6c2 Branch pull/6722/head Document 2/3 ++ 2 --
ipaleka widgets
Require the router to be in the group, and show where a forfeit goes (S7, S2)
**S7.** The S6 fix mirrored `_assert_group_is_clean` into the browser, and the
mirror was faithful and insufficient. That guard checks hygiene - rekey, close,
group fee - and hygiene is not what a hostile conversion violates. A plain
asset transfer of the whole balance to a stranger carries no close, no rekey
and an ordinary fee, and passed the mirror completely.

The contract does not check `aamt` or `arcv` either, and does not need to: on a
routed group the rest of it checks - the input proven spent, the co-signed
floor, the pinned pools - and none of that runs unless the router is called. So
the mirror had copied the cheap outer shell and left out the part doing the
work. The two exempt entry points say the same thing from the other side:
`pool_budget` and `verify_discount` skip the hygiene guard precisely because
they ride alongside a route, so hygiene alone was never the safety argument.

`routedGroupProblems` now also requires a call to the router whose ARC-4
selector is not one of those two - "calls the router" would have passed
`[pool_budget, transfer-to-attacker]`, which calls the router and is checked by
nothing. The app id comes from `data-router-app`, handed down by the view and
overridable by a setting, with the same number in the widget as a fallback so a
missing attribute cannot switch the rule off. Not from the plan response: an id
the engine supplied would make the check agree with whatever the engine wanted,
which is S2 for the third time. The two excluded selectors are recomputed from
the method signatures by verify-sweep.sh rather than trusted as constants.

All four router groups in the audit's evidence carry non-exempt selectors, so
the rule accepts every conversion that has actually executed.

It also caught a test that had gone quiet. "Accepting implies no transaction
closes or rekeys" became vacuous the moment this landed - no corpus transaction
is an application call, so every generated group was refused for that reason
and the implication was never exercised. It now prefixes a real route call and
asserts that something really was accepted.

**S2 recommendation 2.** The row showed unit, id, badge, value and reason and
never the address the tokens went to, so on the one disposition that gives
something away the destination was the single fact the reader was not shown.
`destinationLabel` is the pure half, tested; `renderLine` only appends it. A
close says plainly that nothing leaves, because a blank cell there reads as a
missing fact rather than as reassurance. The audit is explicit that this
complements the chain lookup rather than replacing it.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01XqeQenXa9oWnLCWEvuiy8B
Git Commit 4fe081b9 Branch review/S2-hardening Document 6/331 ++ 5 --