Ecosystem metrics
- New Repos
- 12
- New
- Commits
- 610
- down 6.7%
- Releases
- 4
- up 100.0%
- Contributors
- 44
- down 8.3%
- Merges
- 23
- up 228.6%
Activity Overview
Commits and releases over time
- Commits
- Releases
- Authors
Repository Explorer
No repositories match that filter.
7636 commits in all time
Jul 01, 2026 14:21 – Sep 29, 2026 14:21 UTC
Merge 0318429fd70fb211f6ae16aaa133c6f481e28403 into 881e85a365a61bfb69602b552554ebf33d152487
e32483e7
pull/671/merge
3/443 ++ 0 --
docs: correct AlgoKit endpoint overrides and expand Nodely reference
0318429f
docs/nodely-deployment-guide
2/203 ++ 119 --
Merge 92c3e50330cd6fe0ae5a4cea949487c865bf787e into 8258f5cd88a4e9e67e19ba8d9172a53668dd15c8
7a9fbe62
pull/41/merge
15/663 ++ 114 --
refactor(oid4vc): simplify did:key / uri+idx revocation addressing
The integration branch has not shipped, so drop compatibility paths that only protected data which cannot exist: - Remove the legacy fallback that inferred a configuration id from offeredCredentialConfigurationIds (and its 409). A narrowed holder revocation now filters entries by their recorded configuration id. - Make statusChange.entries required and drop the whole-session fallbacks. Enforce the exactly-one-addressing-form rule in one place, Oid4vcStatusService.resolveTargets, instead of splitting it between DTO @ValidateIf guards and the service. The DTO now validates field formats only. Also collapse the revokedAt stamping branch, trim comments that narrated the PR's own history, drop tests made redundant by the above, and tighten the README and revocation plan.
92c3e503
feat/revoke-by-did-key
12/91 ++ 272 --
fix(oid4vc): flip only the status entries a request addresses
Revocation resolved an addressing form to an issuance session and then flipped every entry that session held. One session can yield several credentials — multiple credential_configuration_ids in an offer, or a repeated credential request — so both narrowing forms revoked credentials the caller never named: uri + idx took out its siblings, and a credentialConfigurationId filter matched at session level took out the other configurations in the same offer. Each status entry now records the credentialConfigurationId it was issued under, and a request resolves to the entries it names rather than to a session: - uri + idx flips that one entry. - credentialConfigurationId is matched per entry, leaving the rest of the offer valid. - The selection is written into the durable statusChange intent, so a resumed operation replays it instead of widening, and a pending operation covering a different set returns 409. - revokedAt / revokedReason stay session-level and are only set by an operation covering the whole session. The status list bit is the per-credential answer. Entries allocated before the configuration id was recorded carry none. A single-configuration offer is still unambiguous; a narrowed request against an older session that offered several returns 409 rather than guessing which siblings to revoke with it. Validation is tightened alongside, since each gap silently widened a destructive operation: - An empty credentialConfigurationId is rejected rather than read as "no filter", which revoked every credential the holder held. - Half of uri + idx is rejected rather than falling through to the holder form, which turned a malformed single-credential request into a holder-wide one. - An explicitly empty ?holderDidKey= reaches findByHolder's did:key check instead of being treated as an absent filter and listing every session.
30e8853d
feat/revoke-by-did-key
12/323 ++ 56 --
feat(oid4vc): address credential status by holder did:key or status entry
Revoke/reactivate previously required the local issuance session id. Losing that id left a credential permanently unrevokable, so it is no longer accepted. Requests now carry exactly one addressing form: - holderDidKey, optionally narrowed by credentialConfigurationId, acting on every credential issued to that wallet-local DID. - uri + idx, the pair already embedded in the credential status.status_list claim, resolved back to its issuance session. Both are backed by new Vault KV indexes written at offer creation and at allocation: sessions/issuance/by-holder/<multibase>/<sessionId> and status-lists/entries/<listId>/<idx>. One key per record, so concurrent writers append without contending. Existing sessions are not backfilled; the indexes populate for new offers and issuances only. GET credential/issuer/sessions gains an index-backed ?holderDidKey= filter. holderKey() revalidates the did:key before building a Vault path. The query parameter reaches the repository unvalidated, since ValidationPipe only covers typed DTOs, and the value becomes a path segment where .. would otherwise escape the index folder. Revocation remains session-scoped once resolved, and a holder matching several sessions is not atomic across them: a partial failure leaves earlier sessions revoked and re-sending the same request finishes the rest.
b3520fd1
feat/revoke-by-did-key
13/551 ++ 88 --
fix: pass the http client to the genesis downloads
Both genesis downloads reached for a package-level client, so a test had no way to point them at a mock server. Take an api.HttpPkgInterface like the release checks, the catchpoint lookup and the short links already do. GetGenesis has no callers; handleDataDirMac gets the client from algod.Install, which the install and bootstrap commands now supply. Drop main_test.go with it. A test binary is not linked as package main, so the linker never stamps main.version there and both sides of the comparison were the same "dev" default: the test passed whether or not init handed the version over. api/useragent_test.go covers SetVersion.
16c8fc2a
feat/user-agent
6/12 ++ 27 --
feat: identify nodekit via user-agent
Every outbound request went out as Go's default "Go-http-client/1.1", which tells a node operator reading their algod access log, or the GitHub release API, nothing about what is calling them. Send "Nodekit v<version>" instead, built from the version the linker stamps into main so that releases can be told apart. The shared HttpPkg wrapper covers the release checks, the catchpoint lookup, the short links and the upgrade download; the generated algod client gets the header through a request editor, since api/lf.go is overwritten by `make generate`.
6a73a179
feat/user-agent
8/179 ++ 7 --
fix: give --lines one meaning with and without --follow
--follow substituted a backlog of 10 when --lines was not given, so -n meant one thing alone and another beside -f: `-n 0 -f` replayed the whole history, where `tail -n 0 -f` shows none of it. --follow now replays the same set the command shows without it, --lines N shortens that backlog, and a stream that starts at now is --since 0s. The cost is that a bare -f reads the whole history before the first new entry arrives, as the command without -f already does.
e80f8602
fix/logs-follow-lines
4/97 ++ 20 --
Merge 378dcd6c279f060eadd4fc2e082997c38c19a0f1 into b090a483dcc3a6a69b22e603fc36392ac9e63ecc
06c2dc5b
pull/464/merge
1/717 ++ 946 --
chore(deps): lock file maintenance
378dcd6c
renovate/lock-file-maintenance
1/717 ++ 946 --
Merge 9b7290db9c7c24b07be04ef9bfa40bbf5e4cc5ac into 361d3066ffaca4241991cc6563403417bf562ecf
434656aa
pull/17/merge
4/3,363 ++ 1,957 --
fix(deps): update all non-major dependencies
9b7290db
renovate/all-minor-patch
4/3,363 ++ 1,957 --