Ecosystem metrics

New Repos
22
New
Commits
810
up 21.4%
Releases
5
up 66.7%
Contributors
51
up 10.9%
Merges
29
up 11.5%

Repository Explorer

8308 commits in all time Jul 09, 2026 13:29 – Oct 07, 2026 13:29 UTC
scholtz-aures wallet
Deploying to gh-pages from @ scholtz/wallet@1add2170066329d1fbc6c62332fe7c266fc9b1d1 🚀
Git Commit 6c66b102 Branch gh-pages Document 9/16 ++ 16 --
scholtz-aures wallet
Add security audit report for AWallet (commit 381ae2b) - October 2026
- Executive summary of findings including 1 High, 4 Medium, 3 Low, and 1 Informational issues.
- Detailed descriptions and recommendations for each finding, including critical issues related to multi-tab wallet persistence, password management, and WalletConnect vulnerabilities.
- Re-verification of prior findings with updated statuses and evidence.
- Dependency review highlighting new advisories and potential security impacts.
- Appendix listing files reviewed during the audit process.
Git Commit 1add2170 Branch master Document 2/210 ++ 34 --
scholtz wallet
Deploying to gh-pages from @ scholtz/wallet@b1540ea755fbdb4634de1ebf10e898af7629c803 🚀
Git Commit 71197c12 Branch gh-pages Document 15/6,762 ++ 6,761 --
scholtz wallet
Biatec Direct: relay-free popup + postMessage dApp transport (#193)
* Add Biatec Direct: relay-free popup + postMessage dApp transport (#192)

A third dApp transport next to WalletConnect and Liquid Auth. The dApp opens
/direct in a popup and exchanges ARC-0027 messages over window.postMessage;
nothing passes through a relay or the internet, so it works for localhost dApps
and offline installs.

Security: the dApp identity is the browser-verified event.origin (https or
loopback only), every message must come from both the hinted origin and
window.opener, replies use that origin as targetOrigin (never "*"), exactly one
request per popup within 30 s of ready, refuses to run framed or without an
opener, network-binds every request and transaction to the active genesis hash,
and reuses the shared sender/signer admission guards. Site grants live in the
encrypted wallet blob and are written with a read-modify-write against the
persisted record so a stale tab cannot overwrite another tab's data.

Also: Connect page "Direct" tab (list/revoke sites), frame-ancestors CSP in the
nginx config, connect.direct.* strings in all 10 locales, docs/DIRECT.md,
changelog, unit tests and a Playwright E2E spec using a cross-origin fixture dApp.

Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com>

* Address review findings on Biatec Direct (wallet side)

- Stale tab: saveWallet now takes the persisted value of shared wc items
  (direct:sessions) and wallet-record writes are serialized across tabs with a
  Web Lock, so a stale main tab can neither restore a revoked grant nor drop a
  new one.
- Single-use channel: a reload or lock/unlock cycle never announces ready again.
- handleRequest answers 4000 and ends the request on unexpected failure; the
  popup shows a "refused" state; approve/send/cancel responses are idempotent.
- The built-in table of well-known networks wins over the remote genesis list;
  grants are bound to the network they were made on; sign_data validates an
  optional genesisHash.
- Reject trailing-dot origins; /payWC inside a popup uses the minimal layout.
- Document the wire contract (wallet providerId, normalized genesisHash).
- Tests: wire-shape contract, stale-tab regression, disable, reload replay,
  ARC-60 unapproved signer / domain mismatch / approved signer, poisoned list.

Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com>

* Address second-round review findings on Biatec Direct (wallet side)

- approveEnable restores the pending request when persisting the grant fails,
  so the popup can retry or reject instead of going blank.
- Connect page: a Direct-tab load failure no longer aborts the page init.
- startPopup load failure shows the "start over" state rather than "refused".
- changePassword takes the cross-tab wallet write lock and keeps shared items
  persisted by other tabs (shared serializer with saveWallet).
- Document the dApp-implementer rules (unique window name, accepted origins).

Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com>

* Address third-round review findings on Biatec Direct (wallet side)

- Grant updates are now one atomic critical section: wallet/wcUpdateItemFresh
  runs read, update and write inside the cross-tab Web Lock, so concurrent
  updates (popup approve vs main-tab revoke) can neither restore a revoked
  grant nor drop a new one. The shared-item merge is a pure, unit-tested module.
- direct/reset runs first and in its own try/catch on logout and wallet
  destruction, so a pending request is always answered 4001 even if another
  transport's teardown throws.
- Only the four known peer fields are persisted (no dApp-controlled extra keys).
- A refused second channel start no longer tears down the live channel.
- Tests: merge unit spec, concurrent-update atomicity and lock-mid-request E2E.

Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com>

* Address fourth-round review findings on Biatec Direct (wallet side)

- Never wait on the remote genesis list for well-known networks or custom nodes
  (a stalled connection to the list host could leave the popup waiting).
- Docs name the right shared-item action (wcUpdateItemFresh).

Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com>

* Cap account names sent in the Direct enable response

The dApp library rejects names longer than 128 characters, which would make a
valid grant fail on the dApp side while the wallet kept it. Bound the name at
the source and omit it when empty.

Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com>

* Accept the verified origin's host (with port) as the ARC-0060 domain

use-wallet sends location.host as the ARC-0060 domain, which includes a
non-default port ("localhost:5173"); the wallet compared only the hostname, so
sign_data was refused for any dApp on a non-default port, including the
documented localhost development case. Accept the origin's host or hostname
(another host or port is still refused). The check moves to an import-free
module with a unit spec; an E2E test signs a port-bearing domain.

Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com>

* Direct popup: privacy and UX pass

Security/privacy: the enable response carries addresses only. Account names
are the user's private labels and were sent to the site without saying so.

UX: the popup now leads with a request headline and a prominent, scheme-aware
origin card; the network is shown by its friendly name; the locked screen
already names the site asking for access (from the URL hint); the window title
names the site; the signing view is compact (no bookkeeping columns or paging,
transactions expanded) and the result returns to the site automatically once
everything in the request is signed, so a second click in a small window is
not needed; clearer waiting/empty states and button hierarchy.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>

* Direct popup: fit the signing view into the popup

The shared request table was designed for desktop and overflowed the 480px
window, clipping the primary button and the transaction columns. In the popup
it now hides the bookkeeping columns, the header rows and the developer copy
button, keeps the type and rekey/close-to warnings, labels the fee, shows
"Send back" only for a partially signed request, and wraps values without
breaking the detail labels.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>

* Direct popup: review fixes for sign-data review, origin wording, fee detail

- Sign-data in the popup: items are expanded and reviewed individually; the
  one-click "Sign all" is not offered there (a result now returns on its own
  once every item is signed, so nothing may be signed unseen).
- The site address is labelled "claimed, not confirmed" until a message from
  it has been accepted; the pre-unlock banner says "a page claiming to be ...".
- The per-transaction fee is a row in the detail view (all transports), so it
  is never hidden behind the request total.
- E2E: sign-data review/auto-return, rekey and fee visible in the compact view,
  a partly signed request is not returned automatically.

Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com>

* Direct popup: show clawback source and OnComplete; polish states and a11y

Security/trust: the request detail now lists the account an asset clawback
really takes funds from and an app call's OnComplete (destructive ones are
highlighted), for every transport, since the compact popup is the only review
surface. The pre-unlock banner and window title only use the unverified origin
hint in a genuine popup (opener present, not framed). A custom node shows that
the site chooses the network, with the start of the genesis hash.

UX: rejecting shows a neutral "Request declined" state instead of a green
"Done"; single-transaction requests show one Sign button; the hidden expander
column no longer wastes popup width; state changes move focus to the headline
and are announced; the kicker names the wallet brand; the sign hint is accurate
for multi-step requests; Hungarian copy grammar fixed.

Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com>

* Direct: sign only what the popup can show completely; verified-state fixes

Security: the compact popup is the user's only review surface, so Direct now
signs only payments, asset transfers and calls to existing apps. Asset
configuration, freeze, key registration, state proofs, heartbeats and app
creation/update (whose security-relevant fields it does not show) are refused
with 4200; dApps needing them use WalletConnect.

Trust display: a popup-level "verified" flag (set once a message from the hinted
origin passed the gate) drives the "verified/claimed" label, so it no longer
reverts to "claimed" after a declined or refused request, and the window title
names the site only once it is verified. Removed the noisy aria-live region;
focus moves to the headline on each state change.

Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com>

---------

Co-authored-by: Ludovit Scholtz <ludovit.scholtz@aaaauto.cz>
Co-authored-by: Claude Sonnet 5.5 <noreply@anthropic.com>
Git Commit b1540ea7 Branch master Document 37/4,357 ++ 89 --
ipaleka frontend
Filter hides the load-more controls and clears inline display on reset
Git Commit 60237318 Branch main Document 10/312 ++ 11 --
emg110 ARCs
Merge 8f056958b107eea9cf7c80665a2424aafd33a4a8 into 750f8a3065a96f9a6e27711d72c92c59255dda7f
Git Commit 9d27a639 Branch pull/265/merge Document 4/1,022 ++ 0 --
whawk46 ARCs
Merge b56cc5532185a5363a2fce328e75b7a4d5caf774 into 750f8a3065a96f9a6e27711d72c92c59255dda7f
Git Commit 6f86e867 Branch pull/489/merge Document 2/249 ++ 0 --
whawk46 ARCs
feat(arc-0402): add HTTP 402 Machine Payment & Execution Evidence Standard
Git Commit b56cc553 Branch pull/489/head Document 2/249 ++ 0 --
nullun go-algorand
Merge 86c77aa96b2e4f00c0fa86c637cf2206f55b55d0 into a57ad64788568d1f76f63f52af499e3e30fa9149
Git Commit dcf4f26c Branch pull/6750/merge Document 5/389 ++ 41 --
Merge 86035fab92e9254b36c1622a18a293022df7c63a into a57ad64788568d1f76f63f52af499e3e30fa9149
Git Commit 38fdc167 Branch pull/6746/merge Document 2/23 ++ 21 --
Merge d60b10a1aa2630d0309c9535356d797339289d4b into a57ad64788568d1f76f63f52af499e3e30fa9149
Git Commit f2cab315 Branch pull/6742/merge Document 2/23 ++ 21 --
Merge 6d30c219a4ec7024d9ba9e9ed83146e4632d2dd4 into a57ad64788568d1f76f63f52af499e3e30fa9149
Git Commit 84f9f5d8 Branch pull/6567/merge Document 16/1,647 ++ 22 --
Merge 01ad2e0a03d0f6935a732397654025462e08b597 into a57ad64788568d1f76f63f52af499e3e30fa9149
Git Commit 44f9f761 Branch pull/6730/merge Document 1/3 ++ 3 --
Merge 01cfc9c72f2e2b11984e5353a08c653d79795c95 into a57ad64788568d1f76f63f52af499e3e30fa9149
Git Commit 4d5aa3ff Branch pull/6755/merge Document 2/23 ++ 21 --
Merge 4423646fd1f3b75cc3afcf476364627efcbfd5b8 into a57ad64788568d1f76f63f52af499e3e30fa9149
Git Commit 9e7302ec Branch pull/6735/merge Document 17/700 ++ 505 --
Merge 662830ac18ba6d860799dc85be7eb5d15cf500e4 into 04eea85a6c0bc52cd077fdb10927302978ca127f
Git Commit acc30949 Branch pull/319/merge Document 3/60 ++ 5 --
Merge 247cec3e327c24447adae5be70694068ea13d366 into b2e5c538092d217c11955b81bb0e4d4ce9511756
Git Commit 1fa97c5c Branch pull/427/merge Document 46/5,061 ++ 8 --
feat: add MySales component and utility files for WenPad sales management
Git Commit 15099b93 Branch main Document 3/130 ++ 16 --
LoafPickleWW wen-tools
feat: add WenPadSales components, core utils, and reveal API endpoint
Git Commit 82a8f17c Branch main Document 7/235 ++ 63 --
LoafPickleWW wen-tools
feat: add LaunchSaleWizard component and related collection sale files for WenPadSales
Git Commit fdacf667 Branch main Document 8/591 ++ 188 --
feat: add similar escrow session vault for solana devnet to show multi-chain
Git Commit 538e1d1c Branch main Document 15/5,778 ++ 8 --