Ecosystem metrics

New Repos
26
New
Commits
800
up 19.8%
Releases
5
up 150.0%
Contributors
52
up 13.0%
Merges
27
up 0.0%

Repository Explorer

8307 commits in all time Jul 09, 2026 15:44 – Oct 07, 2026 15:44 UTC
LoafPickleWW wen-tools
feat: add WenPad sale smart contract and frontend components
Git Commit dbfd4cf8 Branch main Document 20/5,695 ++ 4,585 --
iglosiggio puya
WIP: Implement "normal" opts
Git Commit 841985b0 Branch remote-box Document 300/611,700 ++ 21,392 --
Comment out npm test in new-release.yml
Comment out the npm test step in the release workflow.
Git Commit 2af0e1c7 Branch main Document 1/1 ++ 1 --
Merge a121f5beabc5cbb5fc16c8dcabf228cf86a3ddd6 into 361d3066ffaca4241991cc6563403417bf562ecf
Git Commit b145554f Branch pull/17/merge Document 4/3,364 ++ 1,958 --
fix(deps): update all non-major dependencies
Git Commit a121f5be Branch renovate/all-minor-patch Document 4/3,364 ++ 1,958 --
nullun specs
Merge 21a7f33f6b43907aec420bdfe40396fc1b866162 into 77002d1e2d50d7d769cacbc9fa54caeec652001c
Git Commit 3cadf9e5 Branch pull/314/merge Document 10/89 ++ 74 --
Disable innerTxnAssetData retrieval temporarily
Comment out the inner transaction asset data retrieval due to issues with Pera modifying the txgroup during signing.
Git Commit 702aeefd Branch main Document 1/8 ++ 5 --
ChrisWozniak specs
Merge b77e6904964c1e84a7112ee2bd82af5c6b31c1ca into 77002d1e2d50d7d769cacbc9fa54caeec652001c
Git Commit 5e02793c Branch pull/318/merge Document 4/152 ++ 18 --
ipaleka frontend
Added claim link for the accepted NFT offers
Git Commit 616c8460 Branch main Document 5/67 ++ 0 --
cicd deploy stable 1.2026.10.07-stable [skip ci]
Git Commit 4218b997 Branch master Document 2/2 ++ 2 --
ipaleka frontend
Added claim link for the accepted NFT offers
Git Commit 753926de Branch main Document 5/66 ++ 0 --
scholtz-aures wallet
Deploying to gh-pages from @ scholtz/wallet@1add2170066329d1fbc6c62332fe7c266fc9b1d1 🚀
Git Commit 6c66b102 Branch gh-pages Document 9/16 ++ 16 --
scholtz-aures wallet
Add security audit report for AWallet (commit 381ae2b) - October 2026
- Executive summary of findings including 1 High, 4 Medium, 3 Low, and 1 Informational issues.
- Detailed descriptions and recommendations for each finding, including critical issues related to multi-tab wallet persistence, password management, and WalletConnect vulnerabilities.
- Re-verification of prior findings with updated statuses and evidence.
- Dependency review highlighting new advisories and potential security impacts.
- Appendix listing files reviewed during the audit process.
Git Commit 1add2170 Branch master Document 2/210 ++ 34 --
scholtz wallet
Deploying to gh-pages from @ scholtz/wallet@b1540ea755fbdb4634de1ebf10e898af7629c803 🚀
Git Commit 71197c12 Branch gh-pages Document 15/6,762 ++ 6,761 --
scholtz wallet
Biatec Direct: relay-free popup + postMessage dApp transport (#193)
* Add Biatec Direct: relay-free popup + postMessage dApp transport (#192)

A third dApp transport next to WalletConnect and Liquid Auth. The dApp opens
/direct in a popup and exchanges ARC-0027 messages over window.postMessage;
nothing passes through a relay or the internet, so it works for localhost dApps
and offline installs.

Security: the dApp identity is the browser-verified event.origin (https or
loopback only), every message must come from both the hinted origin and
window.opener, replies use that origin as targetOrigin (never "*"), exactly one
request per popup within 30 s of ready, refuses to run framed or without an
opener, network-binds every request and transaction to the active genesis hash,
and reuses the shared sender/signer admission guards. Site grants live in the
encrypted wallet blob and are written with a read-modify-write against the
persisted record so a stale tab cannot overwrite another tab's data.

Also: Connect page "Direct" tab (list/revoke sites), frame-ancestors CSP in the
nginx config, connect.direct.* strings in all 10 locales, docs/DIRECT.md,
changelog, unit tests and a Playwright E2E spec using a cross-origin fixture dApp.

Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com>

* Address review findings on Biatec Direct (wallet side)

- Stale tab: saveWallet now takes the persisted value of shared wc items
  (direct:sessions) and wallet-record writes are serialized across tabs with a
  Web Lock, so a stale main tab can neither restore a revoked grant nor drop a
  new one.
- Single-use channel: a reload or lock/unlock cycle never announces ready again.
- handleRequest answers 4000 and ends the request on unexpected failure; the
  popup shows a "refused" state; approve/send/cancel responses are idempotent.
- The built-in table of well-known networks wins over the remote genesis list;
  grants are bound to the network they were made on; sign_data validates an
  optional genesisHash.
- Reject trailing-dot origins; /payWC inside a popup uses the minimal layout.
- Document the wire contract (wallet providerId, normalized genesisHash).
- Tests: wire-shape contract, stale-tab regression, disable, reload replay,
  ARC-60 unapproved signer / domain mismatch / approved signer, poisoned list.

Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com>

* Address second-round review findings on Biatec Direct (wallet side)

- approveEnable restores the pending request when persisting the grant fails,
  so the popup can retry or reject instead of going blank.
- Connect page: a Direct-tab load failure no longer aborts the page init.
- startPopup load failure shows the "start over" state rather than "refused".
- changePassword takes the cross-tab wallet write lock and keeps shared items
  persisted by other tabs (shared serializer with saveWallet).
- Document the dApp-implementer rules (unique window name, accepted origins).

Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com>

* Address third-round review findings on Biatec Direct (wallet side)

- Grant updates are now one atomic critical section: wallet/wcUpdateItemFresh
  runs read, update and write inside the cross-tab Web Lock, so concurrent
  updates (popup approve vs main-tab revoke) can neither restore a revoked
  grant nor drop a new one. The shared-item merge is a pure, unit-tested module.
- direct/reset runs first and in its own try/catch on logout and wallet
  destruction, so a pending request is always answered 4001 even if another
  transport's teardown throws.
- Only the four known peer fields are persisted (no dApp-controlled extra keys).
- A refused second channel start no longer tears down the live channel.
- Tests: merge unit spec, concurrent-update atomicity and lock-mid-request E2E.

Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com>

* Address fourth-round review findings on Biatec Direct (wallet side)

- Never wait on the remote genesis list for well-known networks or custom nodes
  (a stalled connection to the list host could leave the popup waiting).
- Docs name the right shared-item action (wcUpdateItemFresh).

Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com>

* Cap account names sent in the Direct enable response

The dApp library rejects names longer than 128 characters, which would make a
valid grant fail on the dApp side while the wallet kept it. Bound the name at
the source and omit it when empty.

Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com>

* Accept the verified origin's host (with port) as the ARC-0060 domain

use-wallet sends location.host as the ARC-0060 domain, which includes a
non-default port ("localhost:5173"); the wallet compared only the hostname, so
sign_data was refused for any dApp on a non-default port, including the
documented localhost development case. Accept the origin's host or hostname
(another host or port is still refused). The check moves to an import-free
module with a unit spec; an E2E test signs a port-bearing domain.

Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com>

* Direct popup: privacy and UX pass

Security/privacy: the enable response carries addresses only. Account names
are the user's private labels and were sent to the site without saying so.

UX: the popup now leads with a request headline and a prominent, scheme-aware
origin card; the network is shown by its friendly name; the locked screen
already names the site asking for access (from the URL hint); the window title
names the site; the signing view is compact (no bookkeeping columns or paging,
transactions expanded) and the result returns to the site automatically once
everything in the request is signed, so a second click in a small window is
not needed; clearer waiting/empty states and button hierarchy.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>

* Direct popup: fit the signing view into the popup

The shared request table was designed for desktop and overflowed the 480px
window, clipping the primary button and the transaction columns. In the popup
it now hides the bookkeeping columns, the header rows and the developer copy
button, keeps the type and rekey/close-to warnings, labels the fee, shows
"Send back" only for a partially signed request, and wraps values without
breaking the detail labels.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>

* Direct popup: review fixes for sign-data review, origin wording, fee detail

- Sign-data in the popup: items are expanded and reviewed individually; the
  one-click "Sign all" is not offered there (a result now returns on its own
  once every item is signed, so nothing may be signed unseen).
- The site address is labelled "claimed, not confirmed" until a message from
  it has been accepted; the pre-unlock banner says "a page claiming to be ...".
- The per-transaction fee is a row in the detail view (all transports), so it
  is never hidden behind the request total.
- E2E: sign-data review/auto-return, rekey and fee visible in the compact view,
  a partly signed request is not returned automatically.

Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com>

* Direct popup: show clawback source and OnComplete; polish states and a11y

Security/trust: the request detail now lists the account an asset clawback
really takes funds from and an app call's OnComplete (destructive ones are
highlighted), for every transport, since the compact popup is the only review
surface. The pre-unlock banner and window title only use the unverified origin
hint in a genuine popup (opener present, not framed). A custom node shows that
the site chooses the network, with the start of the genesis hash.

UX: rejecting shows a neutral "Request declined" state instead of a green
"Done"; single-transaction requests show one Sign button; the hidden expander
column no longer wastes popup width; state changes move focus to the headline
and are announced; the kicker names the wallet brand; the sign hint is accurate
for multi-step requests; Hungarian copy grammar fixed.

Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com>

* Direct: sign only what the popup can show completely; verified-state fixes

Security: the compact popup is the user's only review surface, so Direct now
signs only payments, asset transfers and calls to existing apps. Asset
configuration, freeze, key registration, state proofs, heartbeats and app
creation/update (whose security-relevant fields it does not show) are refused
with 4200; dApps needing them use WalletConnect.

Trust display: a popup-level "verified" flag (set once a message from the hinted
origin passed the gate) drives the "verified/claimed" label, so it no longer
reverts to "claimed" after a declined or refused request, and the window title
names the site only once it is verified. Removed the noisy aria-live region;
focus moves to the headline on each state change.

Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com>

---------

Co-authored-by: Ludovit Scholtz <ludovit.scholtz@aaaauto.cz>
Co-authored-by: Claude Sonnet 5.5 <noreply@anthropic.com>
Git Commit b1540ea7 Branch master Document 37/4,357 ++ 89 --
ipaleka frontend
Filter hides the load-more controls and clears inline display on reset
Git Commit 60237318 Branch main Document 10/312 ++ 11 --
emg110 ARCs
Merge 8f056958b107eea9cf7c80665a2424aafd33a4a8 into 750f8a3065a96f9a6e27711d72c92c59255dda7f
Git Commit 9d27a639 Branch pull/265/merge Document 4/1,022 ++ 0 --
whawk46 ARCs
Merge b56cc5532185a5363a2fce328e75b7a4d5caf774 into 750f8a3065a96f9a6e27711d72c92c59255dda7f
Git Commit 6f86e867 Branch pull/489/merge Document 2/249 ++ 0 --
whawk46 ARCs
feat(arc-0402): add HTTP 402 Machine Payment & Execution Evidence Standard
Git Commit b56cc553 Branch pull/489/head Document 2/249 ++ 0 --
nullun go-algorand
Merge 86c77aa96b2e4f00c0fa86c637cf2206f55b55d0 into a57ad64788568d1f76f63f52af499e3e30fa9149
Git Commit dcf4f26c Branch pull/6750/merge Document 5/389 ++ 41 --
Merge 86035fab92e9254b36c1622a18a293022df7c63a into a57ad64788568d1f76f63f52af499e3e30fa9149
Git Commit 38fdc167 Branch pull/6746/merge Document 2/23 ++ 21 --
Merge d60b10a1aa2630d0309c9535356d797339289d4b into a57ad64788568d1f76f63f52af499e3e30fa9149
Git Commit f2cab315 Branch pull/6742/merge Document 2/23 ++ 21 --