Ecosystem metrics
- New Repos
- 8
- New
- Commits
- 602
- down 4.6%
- Releases
- 3
- up 50.0%
- Contributors
- 45
- down 15.1%
- Merges
- 26
- up 160.0%
Activity Overview
Commits and releases over time
- Commits
- Releases
- Authors
Repository Explorer
No repositories match that filter.
7631 commits in all time
Jul 02, 2026 13:35 – Sep 30, 2026 13:35 UTC
Enlarge ARC-56 risk icon to match adjacent buttons
Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com>
12e8bb28
fix/arc56-risk-icon-size
1/8 ++ 2 --
Enlarge ARC-56 risk icon to match adjacent buttons
Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com>
23b7a05f
fix/arc56-risk-icon-size
13/1,039 ++ 458 --
Merge 376ab6a935e4a10a7a2dde390987505a6caa3800 into 26f622c0a1cd570138af4dd139c5943b8f5c3d58
34b2c1a6
pull/668/merge
2/49 ++ 9 --
docs(accounts): add Intermezzo and HD wallet sections. Replace two 'coming soon' placeholders with verified content.
376ab6a9
chore/update-placeholder-sections-hdacc-vault-wallet
2/42 ++ 8 --
Merge d92c73827258571cf30d0fa3e237eb4397d32fef into f83e46c9513beeb52415168fc9ea344dea8a089d
e88be749
pull/479/merge
1/28 ++ 8 --
chore(deps-dev): bump markdown-it in /assets/arc-0087
Bumps [markdown-it](https://github.com/markdown-it/markdown-it) from 14.1.0 to 14.3.2. - [Changelog](https://github.com/markdown-it/markdown-it/blob/14.3.2/CHANGELOG.md) - [Commits](https://github.com/markdown-it/markdown-it/compare/14.1.0...14.3.2) --- updated-dependencies: - dependency-name: markdown-it dependency-version: 14.3.2 dependency-type: indirect ... Signed-off-by: dependabot[bot] <support@github.com>
d92c7382
dependabot/npm_and_yarn/assets/arc-0087/markdown-it-14.3.2
1/28 ++ 8 --
Merge b66a0ff64bf25f30a4287211205b2172a6225d3c into 0b28409172f1221e1b9531cd21f793094ea9f658
c00105d5
pull/6750/merge
4/159 ++ 5 --
network: do not register ws peers after innerStop
WebsocketNetwork.Stop has the same gap. innerStop sweeps wn.peers before the HTTP server shuts down, so a handshake that completes in between is registered. Nothing closes that peer. Shutdown ignores hijacked connections and the wsPeer loops don't watch wn.ctx, so the peer outlives Stop. innerStop now sets peersClosed under peersLock, and addPeer rejects late peers. addPeer reports whether the peer is registered. ServeHTTP and tryConnect close a rejected peer and skip the connected logs and telemetry, which also applies to the existing didSignalClose rejection.
b66a0ff6
pull/6750/head
2/91 ++ 5 --
p2p: do not register wsPeers after innerStop
P2PNetwork.Stop sweeps wsPeers in innerStop before it closes the host. A stream handler that completes in between registers a wsPeer that nothing closes. Once host.Close resets its stream, the peer's read loop logs and emits telemetry, possibly after Stop returns. innerStop now sets wsPeersClosed under wsPeersLock, and baseWsStreamHandler checks it in the same critical section as the insert. A rejected peer releases its identity and throttle slot and is closed. Found while reviewing #6744.
53571611
pull/6750/head
2/68 ++ 0 --
ARC-56 risk icon next to Sign all, with registry owner reputation (#173)
* Show ARC-56 signing risk icon next to Sign all, using registry owner reputation Adds an at-a-glance icon (trusted / warning / danger / not-ABI) beside the "Sign all" button in WalletConnect/Liquid requests and on /signAll, driven by the registry trust level plus the new per-owner reputationScore/riskLevel/banned fields from the ARC56Registry owners files. Publishers now show their rating. Decode logic is extracted into a shared composable; risk evaluation is a pure, unit-tested module. Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com> * Address review: harden risk verdict, dedupe decode, accessible popover - Non-ABI verdict no longer neutral (warning colour, 'not verifiable') - App create/update/delete and close-out/rekey in the request block a trusted verdict - Share in-flight decode between summary and icon; registry fetch timeout - Click/keyboard popover instead of hover-only tooltip - Reword trusted text (acceptable reputation), fix doc comment placement Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com> * Address second review: registry timeout, no caching of transient failures, stricter trust - Actually apply registry fetch timeout; do not cache network-failure misses - Only low-risk publishers are trusted; ClearState counts as sensitive - Risky fields (close-out/rekey) raise a caution even without app calls - Every app call gets a risk input (keeps sensitive flag when decode fails) - Safe in-flight dedupe key, owner badge computed once, aria-haspopup/expanded Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com> * Address third review: non-ABI ban check, more risky txn types, verdict deadline - Hash non-ABI calls so a banned publisher is still caught - Clawback/freeze/keyreg/rekey-away/close-out raise a caution; ignore self/zero rekey - Only network failures (not non-JSON mirrors) skip negative caching; 5s fetch timeout - 20s overall verdict deadline (fail-closed), short-lived shared decode results - Clear stale summaries on new decode, close popover on reload, tidy owner links - Fix changelog wording Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com> * Address fourth review: lookup-failed reason, single decode map, tested txn rules - Failed/timed-out lookups get their own reason and are never cached - Non-ABI with no lookup fails closed; banned non-ABI is danger - Pure, unit-tested isRiskyTransaction/isSensitiveAppCall (acfg reconfigure, CloseOut added) - One shared-decode map; hide 'no publisher' noise for plain non-ABI calls - Trusted text scoped to contract calls; owner badge colours match verdict Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com> * Address fifth review: distinguish registry outage from not-found - Strict registry lookups throw RegistryUnavailableError (owners, primary spec); 5xx/429 no longer cached as 404 - algod failure for an existing app surfaces as lookup_failed; creation uses the txn program - Identity-checked cache eviction, node in shared-decode key, single owners computed Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com> * Address sixth review: mirror-aware outage detection, ban check on every branch - A definitive 404 from any mirror beats another mirror's outage; truncated bodies are transient - Banned publisher is danger for unknown/selector-only/verified/non-ABI alike - Arc56CallDetails resolves programs like the shared decode (creation handled) - Locale reason texts cover every trigger; type-only Arc56TrustLevel import Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com> --------- Co-authored-by: Ludovit Scholtz <ludovit.scholtz@aaaauto.cz> Co-authored-by: Claude Sonnet 5.5 <noreply@anthropic.com>
6da2af52
master
25/1,130 ++ 161 --
Address sixth review: mirror-aware outage detection, ban check on every branch
- A definitive 404 from any mirror beats another mirror's outage; truncated bodies are transient - Banned publisher is danger for unknown/selector-only/verified/non-ABI alike - Arc56CallDetails resolves programs like the shared decode (creation handled) - Locale reason texts cover every trigger; type-only Arc56TrustLevel import Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com>
7bc6cdf8
pull/173/head
15/74 ++ 60 --
Address fifth review: distinguish registry outage from not-found
- Strict registry lookups throw RegistryUnavailableError (owners, primary spec); 5xx/429 no longer cached as 404 - algod failure for an existing app surfaces as lookup_failed; creation uses the txn program - Identity-checked cache eviction, node in shared-decode key, single owners computed Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com>
a2ec8ac5
pull/173/head
4/103 ++ 49 --
Merge c1611399070a47a92e8ef75560f811af4ddf6308 into 26f622c0a1cd570138af4dd139c5943b8f5c3d58
28fe5599
pull/672/merge
2/2 ++ 2 --
fix: resize og image to 1200x630 for X/social previews
c1611399
feat/og-image-1200x630
2/2 ++ 2 --
Address fourth review: lookup-failed reason, single decode map, tested txn rules
- Failed/timed-out lookups get their own reason and are never cached - Non-ABI with no lookup fails closed; banned non-ABI is danger - Pure, unit-tested isRiskyTransaction/isSensitiveAppCall (acfg reconfigure, CloseOut added) - One shared-decode map; hide 'no publisher' noise for plain non-ABI calls - Trusted text scoped to contract calls; owner badge colours match verdict Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com>
a8e0211b
pull/173/head
20/229 ++ 81 --
Address third review: non-ABI ban check, more risky txn types, verdict deadline
- Hash non-ABI calls so a banned publisher is still caught - Clawback/freeze/keyreg/rekey-away/close-out raise a caution; ignore self/zero rekey - Only network failures (not non-JSON mirrors) skip negative caching; 5s fetch timeout - 20s overall verdict deadline (fail-closed), short-lived shared decode results - Clear stale summaries on new decode, close popover on reload, tidy owner links - Fix changelog wording Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com>
6f906a0f
pull/173/head
8/99 ++ 24 --
Address second review: registry timeout, no caching of transient failures, stricter trust
- Actually apply registry fetch timeout; do not cache network-failure misses - Only low-risk publishers are trusted; ClearState counts as sensitive - Risky fields (close-out/rekey) raise a caution even without app calls - Every app call gets a risk input (keeps sensitive flag when decode fails) - Safe in-flight dedupe key, owner badge computed once, aria-haspopup/expanded Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com>
a9a9a90a
pull/173/head
17/99 ++ 65 --
Address review: harden risk verdict, dedupe decode, accessible popover
- Non-ABI verdict no longer neutral (warning colour, 'not verifiable') - App create/update/delete and close-out/rekey in the request block a trusted verdict - Share in-flight decode between summary and icon; registry fetch timeout - Click/keyboard popover instead of hover-only tooltip - Reword trusted text (acceptable reputation), fix doc comment placement Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com>
1f834852
feat/arc56-risk-icon
17/262 ++ 102 --
Show ARC-56 signing risk icon next to Sign all, using registry owner reputation
Adds an at-a-glance icon (trusted / warning / danger / not-ABI) beside the "Sign all" button in WalletConnect/Liquid requests and on /signAll, driven by the registry trust level plus the new per-owner reputationScore/riskLevel/banned fields from the ARC56Registry owners files. Publishers now show their rating. Decode logic is extracted into a shared composable; risk evaluation is a pure, unit-tested module. Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com>
94589ad0
feat/arc56-risk-icon
20/612 ++ 128 --
Merge 0318429fd70fb211f6ae16aaa133c6f481e28403 into 26f622c0a1cd570138af4dd139c5943b8f5c3d58
61825bdd
pull/671/merge
3/443 ++ 0 --