Ecosystem metrics
- New Repos
- 10
- New
- Commits
- 654
- up 36.8%
- Releases
- 2
- down 66.7%
- Contributors
- 57
- up 21.3%
- Merges
- 11
- down 31.3%
Activity Overview
Commits and releases over time
- Commits
- Releases
- Authors
Repository Explorer
No repositories match that filter.
7295 commits in all time
Jun 23, 2026 22:24 – Sep 21, 2026 22:24 UTC
Use permanent published release URLs for asset restoration
e0d2cf45
backup/website-and-playground-2026-09-21
3/41 ++ 37 --
Complete verified 3D asset recovery archive and restoration tools
6b602354
backup/website-and-playground-2026-09-21
10/149,350 ++ 126 --
Preserve source filename case for recovery on Linux
42d896f8
backup/website-and-playground-2026-09-21
3/0 ++ 0 --
Preserve exact recovery snapshot bytes and record file checksums
5ca216cd
backup/website-and-playground-2026-09-21
162/90,384 ++ 90,375 --
Back up current website and playground runtime assets with recovery instructions
89d66109
backup/website-and-playground-2026-09-21
300/75,726 ++ 29,003 --
Merge 56825aa12062cb7ced7956bfd1a60b9d6ef75e85 into 3840d6f5e8c73e27141c5752d311c54c2efcf892
312da7a0
pull/36/merge
7/324 ++ 13 --
Merge 21f4a1e2040623f131e5df3f3c73ddfce04faa98 into 3840d6f5e8c73e27141c5752d311c54c2efcf892
4b9bd45f
pull/35/merge
2/31 ++ 3 --
Merge 93793e0099ee0902f652528cbad91f0ff5933084 into 3840d6f5e8c73e27141c5752d311c54c2efcf892
84206180
pull/34/merge
3/152 ++ 10 --
fix: wipe byte material when sealing rejects
put() zeroed the caller's buffer only on the success path, so a host Subtle that rejects the encrypt left the plaintext behind in the array it was handed. Wipe it in a finally, matching the guarantee use() already makes for decrypted material.
21f4a1e2
pull/35/head
2/31 ++ 3 --
feat: allow an externally supplied vault master key
The vault mints its AES-GCM master key itself and stores it beside the material it seals, so a copy of the profile directory opens that material with no secret. Add a `masterKey` provider to the IndexedDB driver, to createWebKeyStore and to the WithKeyStore extension, for callers that want the key bound to something the browser cannot produce alone — derived from a user password, or held by another context. The provider is resolved per sealing or opening operation rather than captured in `ready`, so it may reject while a vault is locked and resolve once it is open. With one set the vault mints no key of its own, `clear()` stops preserving a record that seals nothing this driver writes, and the driver reports nativeCryptoKey: false so that keys which would otherwise persist as non-extractable CryptoKeys are sealed with the supplied key too. Adopting it is a migration, not a flag, and the docs say so: material the default vault already sealed stops opening, since `use()` asks the provider for a key that did not seal it. Sealing standard keys also means their bytes are decrypted into JS memory for each use. Both limits are pinned by tests.
56825aa1
pull/36/head
6/296 ++ 13 --
Merge c49bc0d9370106e981546d139509d8b390d63af4 into b0a3e71a91adfd1dfb97b5060d054618c2a147aa
6751a9a9
pull/66/merge
10/1,214 ++ 1,283 --
chore(deps): Update all non-major dependencies
c49bc0d9
renovate/all-non-major-dependencies
10/1,214 ++ 1,283 --
Notes added by 'git notes add'
a1320659
notes/semantic-release
1/1 ++ 0 --
chore: v2026.37.0 (release)
## [2026.37.0](https://github.com/michaeltchuang/a-day-in-my-bobalife/compare/v2026.36.0...v2026.37.0) (2026-09-21) ### Updates & Maintenance * log greeting (2026-09-15) ([5587dee](https://github.com/michaeltchuang/a-day-in-my-bobalife/commit/5587deeeebce00e038e465be6b76c91f818d551e)) * log greeting (2026-09-16) ([bec2a77](https://github.com/michaeltchuang/a-day-in-my-bobalife/commit/bec2a7756bd074e105daa2501c0bef1e277780e6)) * log greeting (2026-09-17) ([bd03815](https://github.com/michaeltchuang/a-day-in-my-bobalife/commit/bd038156bc8c7948258e1df9de00449b226cc34a)) * log greeting (2026-09-18) ([775c817](https://github.com/michaeltchuang/a-day-in-my-bobalife/commit/775c8171c55b1223e06181cea44413781f95252d)) * log greeting (2026-09-19) ([b31bd4a](https://github.com/michaeltchuang/a-day-in-my-bobalife/commit/b31bd4a6b28ed7d1aa7140ec384d10b43fd05134)) * log greeting (2026-09-20) ([eb3c3e0](https://github.com/michaeltchuang/a-day-in-my-bobalife/commit/eb3c3e04a5fa2dad1f6bd1f37087e9dc756fedb1)) * log greeting (2026-09-21) ([f1db816](https://github.com/michaeltchuang/a-day-in-my-bobalife/commit/f1db81688487e1e6e8f850f7ee2ed70e701f89f7))
dccf7c34
main
1/13 ++ 0 --
fix: serialise vault master-key creation across contexts
Every same-origin context that builds an IndexedDB driver reaches getMasterKey concurrently on first use. All of them missed the read, all generated a key, the last put won, and each context kept using the key it had generated itself, so material sealed by one could not be opened by another — surfacing as a bare AES-GCM OperationError. Mint the key under a Web Lock and re-read once the lock is held, so the first caller creates and the rest reuse what it wrote.
93793e00
pull/34/head
3/152 ++ 10 --
Merge fe10b9fe883bd2e98bb6dc7896c05142b0e691cc into 27751c364229ae3cd0334fe4071e61690b6879e4
56f96169
pull/751/merge
300/209,555 ++ 10,346 --
Merge c0cf39bd6fb4b4c4e361901bfdb3fac5f0250ad4 into 13a5e07cca4517890dbedc99da961e21271778b1
e9b4887b
pull/414/merge
99/13,577 ++ 2,089 --
refactor: STREAM_TIMEOUT increase to 8 sec
c0cf39bd
pull/414/head
1/2 ++ 2 --
Merge 37b61201e3fcb31dd62e3b77f492d9f8c7f4f3d3 into 1f4ad10fd780a66a043e15b2e692079aede69b6a
74dd1d2d
pull/6737/merge
36/502 ++ 11 --
Disallow logicsig args that are not read
LogicSig args are not signed so any relay can append args to a transaction in flight. The program cannot detect it: it can prove that at least N args exist, never that at most N do. That is harmless while args are free. Once they are priced, and combined with a refundable fee, padding would start consuming the sender's extra fees. Under the new RequireLogicSigArgAccess consensus parameter, a LogicSig may carry no argument it did not read: none above the highest index it read, and none below that index unless the argument is empty. Empty holes remain legal, so goal tealsign's padding keeps working. opArgN records reads in a bitmask on EvalContext, and logicSigVerify checks it -- this is a rule about a transaction, not about what a program means, so it sits beside the other transaction-level LogicSig rules.
37b61201
pull/6737/head
36/502 ++ 11 --