Ecosystem metrics
- New Repos
- 20
- New
- Commits
- 831
- down 21.2%
- Releases
- 4
- down 50.0%
- Contributors
- 42
- down 23.6%
- Merges
- 36
- down 10.0%
Activity Overview
Commits and releases over time
- Commits
- Releases
- Authors
Repository Explorer
No repositories match that filter.
6884 commits in all time
Jun 03, 2026 15:32 – Sep 01, 2026 15:32 UTC
Merge 2057ce1b1458400cb56bb450770a5ce31bd356cb into 83819dabb14d03bd1c17dba053153b5276eec43b
5355fef6
pull/368/merge
1/1 ++ 1 --
chore: bump androidx.core:core-ktx in /DisneyScenicRides
Bumps androidx.core:core-ktx from 1.17.0 to 1.19.0. --- updated-dependencies: - dependency-name: androidx.core:core-ktx dependency-version: 1.19.0 dependency-type: direct:production update-type: version-update:semver-minor ... Signed-off-by: dependabot[bot] <support@github.com>
2057ce1b
dependabot/gradle/DisneyScenicRides/androidx.core-core-ktx-1.19.0
1/1 ++ 1 --
Merge 098f3f4cdce6fda4a2eb6c7791e77f8e1a8b2174 into 83819dabb14d03bd1c17dba053153b5276eec43b
b2b2817f
pull/367/merge
1/1 ++ 1 --
chore: bump androidx.navigation:navigation-fragment-ktx
Bumps androidx.navigation:navigation-fragment-ktx from 2.9.6 to 2.10.0. --- updated-dependencies: - dependency-name: androidx.navigation:navigation-fragment-ktx dependency-version: 2.10.0 dependency-type: direct:production update-type: version-update:semver-minor ... Signed-off-by: dependabot[bot] <support@github.com>
098f3f4c
dependabot/gradle/DisneyScenicRides/androidx.navigation-navigation-fragment-ktx-2.10.0
1/1 ++ 1 --
Merge 7cb16ae5beb3c67aba85023cc89327d71e8b97a5 into 83819dabb14d03bd1c17dba053153b5276eec43b
6d7d0dc3
pull/366/merge
1/1 ++ 1 --
Merge 136a9b9f23b36a0b0c27a8336e47f77a3afe9061 into 83819dabb14d03bd1c17dba053153b5276eec43b
47773396
pull/365/merge
4/239 ++ 165 --
chore: bump androidx.navigation:navigation-ui-ktx in /DisneyScenicRides
Bumps androidx.navigation:navigation-ui-ktx from 2.9.6 to 2.10.0. --- updated-dependencies: - dependency-name: androidx.navigation:navigation-ui-ktx dependency-version: 2.10.0 dependency-type: direct:production update-type: version-update:semver-minor ... Signed-off-by: dependabot[bot] <support@github.com>
7cb16ae5
dependabot/gradle/DisneyScenicRides/androidx.navigation-navigation-ui-ktx-2.10.0
1/1 ++ 1 --
chore: bump gradle-wrapper from 8.13 to 9.7.1 in /DisneyScenicRides
Bumps [gradle-wrapper](https://github.com/gradle/gradle) from 8.13 to 9.7.1. - [Release notes](https://github.com/gradle/gradle/releases) - [Commits](https://github.com/gradle/gradle/compare/v8.13.0...v9.7.1) --- updated-dependencies: - dependency-name: gradle-wrapper dependency-version: 9.7.1 dependency-type: direct:production update-type: version-update:semver-major ... Signed-off-by: dependabot[bot] <support@github.com>
136a9b9f
dependabot/gradle/DisneyScenicRides/gradle-wrapper-9.7.1
4/239 ++ 165 --
Merge 7ee03d29fb797282f462e9935abe14d63e7a3c26 into 83819dabb14d03bd1c17dba053153b5276eec43b
44be5f9a
pull/364/merge
1/1 ++ 1 --
Merge 9d2a42cf690023c9ddbffe52a316c1df2508d14c into 83819dabb14d03bd1c17dba053153b5276eec43b
0bc57791
pull/363/merge
1/1 ++ 1 --
chore: bump androidx.appcompat:appcompat in /DisneyScenicRides
Bumps androidx.appcompat:appcompat from 1.7.1 to 1.8.0. --- updated-dependencies: - dependency-name: androidx.appcompat:appcompat dependency-version: 1.8.0 dependency-type: direct:production update-type: version-update:semver-minor ... Signed-off-by: dependabot[bot] <support@github.com>
7ee03d29
dependabot/gradle/DisneyScenicRides/androidx.appcompat-appcompat-1.8.0
1/1 ++ 1 --
chore: bump androidx.constraintlayout:constraintlayout
Bumps androidx.constraintlayout:constraintlayout from 2.2.1 to 2.2.2. --- updated-dependencies: - dependency-name: androidx.constraintlayout:constraintlayout dependency-version: 2.2.2 dependency-type: direct:production update-type: version-update:semver-patch ... Signed-off-by: dependabot[bot] <support@github.com>
9d2a42cf
dependabot/gradle/DisneyScenicRides/androidx.constraintlayout-constraintlayout-2.2.2
1/1 ++ 1 --
Merge b141c6941c10c6ba7afe41d9106d3fa83db0883f into 42f70fe22bf79c104ddc289fd1a33168009803cf
fb311333
pull/6718/merge
3/256 ++ 16 --
Merge ffdc4ff53d4a83af310cafe14645ef006e433ff8 into 42f70fe22bf79c104ddc289fd1a33168009803cf
d0e3e491
pull/6703/merge
49/2,826 ++ 950 --
add Go Benchmark (go) benchmark result for 42f70fe22bf79c104ddc289fd1a33168009803cf
c7c60425
gh-pages
1/445 ++ 1 --
Merge 2bff9950387a770366f886517340e2d8fa1c5335 into 42f70fe22bf79c104ddc289fd1a33168009803cf
5aeabbbc
pull/6707/merge
14/1,414 ++ 51 --
Merge pull request #6721 from onetechnical/relstable5.0.1-remerge
42f70fe2
master
14/459 ++ 13 --
Merge c75a9ca8cd2c3e892b3d0f4ce25937e4a7949464 into 65896fdbf1e91d62413a51f403fa2454a87a67a2
4c298f43
pull/330/merge
4/12 ++ 17 --
docs: fix links to archived pre-reorg pages
c75a9ca8
fix/docs-staging-links
4/12 ++ 17 --
Merge babad5faa8ea8f36f3258f92c763e7f929c02c03 into a9753af2536081b26c8549679a0c9fff406fbb00
0e53dea5
pull/6722/merge
7/42 ++ 11 --
Update catchup/universalFetcher_test.go
Co-authored-by: nullun <git@nullun.com>
babad5fa
pull/6722/head
1/1 ++ 0 --
Apply suggestions from code review
Co-authored-by: nullun <git@nullun.com>
351cb6c2
pull/6722/head
2/3 ++ 2 --
Require the router to be in the group, and show where a forfeit goes (S7, S2)
**S7.** The S6 fix mirrored `_assert_group_is_clean` into the browser, and the mirror was faithful and insufficient. That guard checks hygiene - rekey, close, group fee - and hygiene is not what a hostile conversion violates. A plain asset transfer of the whole balance to a stranger carries no close, no rekey and an ordinary fee, and passed the mirror completely. The contract does not check `aamt` or `arcv` either, and does not need to: on a routed group the rest of it checks - the input proven spent, the co-signed floor, the pinned pools - and none of that runs unless the router is called. So the mirror had copied the cheap outer shell and left out the part doing the work. The two exempt entry points say the same thing from the other side: `pool_budget` and `verify_discount` skip the hygiene guard precisely because they ride alongside a route, so hygiene alone was never the safety argument. `routedGroupProblems` now also requires a call to the router whose ARC-4 selector is not one of those two - "calls the router" would have passed `[pool_budget, transfer-to-attacker]`, which calls the router and is checked by nothing. The app id comes from `data-router-app`, handed down by the view and overridable by a setting, with the same number in the widget as a fallback so a missing attribute cannot switch the rule off. Not from the plan response: an id the engine supplied would make the check agree with whatever the engine wanted, which is S2 for the third time. The two excluded selectors are recomputed from the method signatures by verify-sweep.sh rather than trusted as constants. All four router groups in the audit's evidence carry non-exempt selectors, so the rule accepts every conversion that has actually executed. It also caught a test that had gone quiet. "Accepting implies no transaction closes or rekeys" became vacuous the moment this landed - no corpus transaction is an application call, so every generated group was refused for that reason and the implication was never exercised. It now prefixes a real route call and asserts that something really was accepted. **S2 recommendation 2.** The row showed unit, id, badge, value and reason and never the address the tokens went to, so on the one disposition that gives something away the destination was the single fact the reader was not shown. `destinationLabel` is the pure half, tested; `renderLine` only appends it. A close says plainly that nothing leaves, because a blank cell there reads as a missing fact rather than as reassurance. The audit is explicit that this complements the chain lookup rather than replacing it. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01XqeQenXa9oWnLCWEvuiy8B
4fe081b9
review/S2-hardening
6/331 ++ 5 --